• 10/09/2026 13:57

Are You in Scope of NIS2? The Complete Entity Classification Checklist

Tiempo estimado de lectura: 2 minutos, 6 segundos

Introduction to NIS2

understanding the nature and extent of cyber threats within the framework of‍ the European‍ Union (EU) is ⁢becoming increasingly crucial. As online activities grow,so does the importance of ensuring⁣ the protection of networks and information systems. ⁤The Directive on Security of Network and Information Systems (NIS ‌Directive), now being updated (NIS2), aims to provide ⁢legal measures to boost the overall cybersecurity in the EU. The question is – ​are you in the scope of NIS2?

The ‍Evolution from NIS to ⁣NIS2

Originally coming into effect in ‌2016, the NIS Directive was the first piece of EU-wide legislation on cybersecurity. It​ provided legal measures to ⁤boost the overall level of cybersecurity in the EU. However, due to the⁣ fast-evolving nature of digital threats and the realization ⁣that some sectors crucial for the⁤ economy and society were out of scope,‌ the‌ European‍ Commission proposed a revised directive (NIS2) in December 2020.

Understanding the Scope of NIS2

The key element of understanding ‍NIS2 is identifying its scope. according to​ the 2020 proposal,NIS2 applies to a wider range of ‘entities’. while the original NIS directive focused on operators of essential⁤ services (OES) and ⁢digital⁤ service providers (DSPs), NIS2 ⁤suggests expanding this scope to include crucial entities. The ‌three classifications of entities in NIS2 are:

1. Essential and important entities: This incorporates sectors vital for the economy ⁤and society, ⁤including energy, transport, banking, financial market infrastructures, health sector, drinking water ⁣supply, digital infrastructure,‍ and ⁤providers of public ​electronic communications networks.

2. Manufacturers, developers, and providers of certain ICT‌ (information and Communications Technology) products, services, and processes: NIS2 brings under its ambit the digital ⁣supply chain facts, with a particular emphasis on​ software and hardware used⁤ in provision ‌of vital services.

3. Medium and large-sized entities:⁣ As per the proposal, irrespective of their sector​ of operation, all medium and large-sized entities are under the microscope.

Entity Classification Checklist

Are you wondering whether you are‍ within the scope of NIS2? The following questions can help you figure it out:

1. What is your business size? As per the NIS2⁤ proposal, irrespective of your sector, all medium-sized (i.e., with 50-249 employees) and large-sized (i.e., 250 employees or more) entities fall within the scope.

2. What is your sector of ​operation? Entities operating in sectors deemed ​essential for the economy and society, such as transport, banking, health sector, digital infrastructure, etc., fall under the scope.

3. Are you a service provider? if you provide ​digital services, especially those linked to the essential sectors, you are considered within the​ scope of NIS2.

4. Are you part⁤ of the ICT chain? If you manufacture,develop or provide certain ICT-related products,services or processes,you are also⁢ in scope.

Preparing for NIS2

Compliance with NIS2 will largely⁢ focus on risk management, which requires entities to take appropriate⁤ technical and organizational⁢ measures to manage the risks that could effect the security of network ⁣and information systems. Also, entities should be aware of reporting ⁢incidents significantly impacting ⁣continuity‍ of essential services​ to ‍the relevant ​national authorities.

While the language in the NIS2⁤ proposal might be ​broad, and the directive⁢ is still under discussion, one thing is certain – the EU is ‍serious about strengthening cybersecurity. This indicates that entities should foster a culture of cybersecurity risk management, ​develop robust​ protocols, and ensure full ​compliance.

Conclusion

Staying‍ updated with the evolving cybersecurity landscape and preparing for ‌the new, extended scope​ of NIS2 are basic​ steps all entities, nonetheless of size or sector, ‍should take to ensure ‍their activities are ⁤carried out within a‌ secure‌ online environment. Compliance is not only about ​meeting⁣ regulations but also about ensuring the essential continuity of⁢ services in an evermore interconnected and digital economy and society.Are you ready for NIS2?

La entrada Are You in Scope of NIS2? The Complete Entity Classification Checklist se publicó primero en Revista de Ciberseguridad y Seguridad de la Información para Empresas y Organismos Públicos..


Artículo de Ciberpyme publicado en https://www.ciberseguridadpyme.es/actualidad/are-you-in-scope-of-nis2-the-complete-entity-classification-checklist/