The NIS2 directive significantly broadens cybersecurity obligations — across more sectors and far more organisations than its predecessor. Many companies simply do not know whether they are in scope. These seven questions support an honest first self-assessment. They do not replace a legal review, but they locate where you stand.
Seven questions on scope
- Which sector do you operate in? NIS2 distinguishes „essential“ and „important“ entities — from energy, transport and health to digital services, postal services, waste management and food.
- How large is your organisation? As a rough threshold, 50 employees or EUR 10 million annual turnover. Below that, NIS2 usually does not apply — with exceptions.
- Is there a special status? Some entities fall under NIS2 regardless of size, for example critical infrastructure or the sole provider of a service.
- Are you part of a supply chain? Even if you are not directly regulated, the requirements are often passed down contractually by your customers.
- Which EU countries are you active in? NIS2 is transposed nationally; thresholds and deadlines can differ in detail.
- Do you have reporting and response processes? NIS2 requires an early warning of significant incidents within 24 hours — which presupposes prepared procedures.
- Is leadership involved? The directive explicitly places responsibility on management, including a duty to undergo training.
What the answers mean
Several „yes“ answers across the first three questions is a clear signal to examine scope seriously. But even a „no“ does not fully release anyone from the topic: through the supply chain (question 4), NIS2 requirements are effectively passed on — as a contract clause, an audit question, a condition for doing business.
From assessment to readiness
A self-assessment is the start, not the goal. The next step is to lay the NIS2 measures from Article 21 — risk management, incident handling, business continuity, supply-chain security, encryption, access control — against your current state and make the gaps visible.
This is exactly where the GARION NIS2 module fits in: it structures the self-assessment, documents the rationale behind each judgement, and makes the readiness status visible per area of measures. The result is a traceable state of preparation on which a well-founded decision — ideally with professional support — can be built.
Note: GARION supports preparation for the EU AI Act and related frameworks. GARION is not a substitute for legal advice, conformity assessment or certification.