Back to knowledge base

Do I fall under NIS2? How to determine whether your organisation is an essential or important entity

Published on July 11, 2026 · Updated on August 4, 2026

This article is general information about laws and regulations, not legal advice.

On 15 August 2026 the Dutch Cybersecurity Act enters into force, the Dutch implementation of NIS2. According to a Dutch government estimate, more than 8,000 organisations fall under it, and not every organisation is aware of that yet. At the same time, there are organisations worrying unnecessarily, or that assume on a supplier's say-so that they are "NIS2-obligated", when that is not established.

For many organisations, the question "am I in scope?" can be answered in a few steps. This article walks through the criteria in the order in which you can tick them off yourself.

Step 1: do you provide a service or activity from one of the 18 sectors?

The act works with two sector lists, taken from the European NIS2 directive. The Netherlands has additionally designated publicly funded higher education; those institutions follow their own timeline (see the frequently asked questions).

Sectors of high criticality (Annex I): energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure (including telecom, data centres, cloud and DNS), ICT service management (B2B, such as managed service providers), public administration and space.

Other critical sectors (Annex II): postal and courier services, waste management, chemicals, food, manufacturing of among others medical devices, electronics, machinery and vehicles, digital providers (online marketplaces, search engines, social networks) and research.

What matters is whether you yourself provide a service or activity from Annex I or II; who you provide it to is a separate question. And it does not have to be your core business: a secondary activity can also bring you into scope. A software company that happens to have a hospital as a customer is not thereby in the health sector. But a managed service provider falls directly under Annex I as an ICT service manager, a category that is easy to overlook, because ICT management rarely feels like a "sector".

Step 2: do you meet the size threshold?

Within those sectors, the act in principle applies to medium-sized and large organisations:

SizeCriteriaPosition
Large250 or more employees, or more than 50 million euros in turnover and more than 43 million euros in balance sheet totalAnnex I: essential; Annex II: important
Medium50 to 250 employees, or more than 10 million euros in turnover and more than 10 million euros in balance sheet totalImportant (both annexes)
Small and microFewer than 50 employees and a turnover or balance sheet total of at most 10 million eurosOutside the act, barring exceptions

The count follows the European SME definition (Recommendation 2003/361/EC): employees are counted in annual work units (comparable to FTE, including working owners), and partner and linked enterprises count as well. A small company within a large group can therefore still be in scope. In cases of doubt, the official self-assessment helps you further.

Rule of thumb: large organisations in the high-criticality sectors are essential; the remaining organisations within scope are important. There are exceptions to that rule of thumb. Public administrations, DNS service providers, top-level domain name registries and qualified trust service providers are essential regardless of their size. Medium-sized and large providers of public electronic communications networks and services (telecom and internet providers) are essential as well. For that category, the table's rule that medium-sized means important does not apply. Small and micro telecom providers and non-qualified trust services do fall under the act regardless of size, but as important entities (see step 3). The core obligations (duty of care and reporting obligation) are the same; the difference is in supervision and the severity of enforcement. Essential entities receive proactive supervision and higher maximum fines, important entities are checked afterwards, for example following an incident or a signal.

Step 3: check the exceptions

For a number of categories the act applies regardless of size. The main ones: providers of public electronic communications networks and services (telecom and internet providers), DNS service providers, top-level domain registries, domain name registration service providers, providers of (qualified) trust services and parts of government, including central government, provinces, municipalities and water authorities. A small organisation that is the sole provider of a critical service in the Netherlands can also be designated.

Not all of these categories end up in the same position. Public administrations, DNS service providers, top-level domain name registries and qualified trust service providers count as essential entities regardless of size. For providers of public electronic communications networks and services, size determines the position: medium-sized and large providers are essential entities; only small and micro providers count (like non-qualified trust services) as important entities. For domain name registration service providers a more limited regime applies: they are not listed in Annex I or II and are only subject to part of the obligations. There is one more route: entities designated as critical entities under the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten, Wwke), which enters into force on the same day, count as essential entities under the Dutch Cybersecurity Act, regardless of size. And if your organisation is part of the financial sector, keep in mind that the European DORA regulation applies there as lex specialis: partly separate rules and deadlines apply to the duty of care and incident reporting.

For public-sector directors there is an extra reason to look closely: the act explicitly regulates board-level accountability. What that does and does not mean is covered in NIS2 and joint and several liability for public-sector directors, with the practical follow-up in the NIS2 roadmap for public-sector boards.

Still in doubt after these three steps? The Dutch government offers an official self-assessment (in Dutch) that gives a well-founded indication and helps you further in cases of doubt. The outcome is also a useful document for your records: "we are not in scope, and this is how we established that" is something you want to be able to show as well.

Outside the scope is not out of range

The most underestimated outcome of the self-check is this: you fall formally outside the act, but your largest customers are covered by it. Those more than 8,000 organisations are required to manage the risks in their supply chain, and for you as a supplier that can translate into questionnaires, contract requirements and audits. What that supply-chain duty of care means for you as a supplier and how to answer such a supplier questionnaire well we described earlier.

In practice, for SMEs the pressure from the chain is often felt sooner than the act itself: your largest customer will typically come knocking sooner than the regulator.

You are in scope. Now what?

Four things, in this order:

  1. Register your organisation in the entity register. This is already possible via mijn.ncsc.nl (with eHerkenning), before 15 August 2026; from that date registration is mandatory. This is the most accessible step, and immediately visible to the regulator.
  2. Map your risks. The duty of care starts with knowing what you have and where you are vulnerable, including what is visible from the outside. The self-assessment is paperwork; after that, the duty of care calls for measurement: knowing what is actually visible from the internet. Exposentry does that with OpenKAT, the open-source scanner that originated within the Dutch government and to which Edward Hasekamp himself contributes. Start with what an attacker sees of your domain.
  3. Set up your reporting process. The reporting obligation for significant incidents is staged: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. That calls for a rehearsed process and agreements with your suppliers.
  4. Make it demonstrable and board-owned. The board approves the measures and oversees them. Make sure there is dated evidence of what you do, because a measure you cannot demonstrate does not count.

Conclusion

Whether you fall under NIS2 is not a matter of gut feeling or of what a vendor claims, but of two testable criteria: sector and size, plus a short list of exceptions. Do the check, record the outcome, and remember that even a "no" does not exempt you from the practice: the supply chain asks the same questions as the law.

Exposentry helps with the steps that come next: continuous visibility of your external attack surface and forensically substantiated reports with which you demonstrate your duty of care to regulators and customers alike. The result is a demonstrable building block; the compliance judgment itself remains with your auditor and the regulator. Start with a baseline scan or see the plans and pricing.

Written by Edward Hasekamp, founder of Exposentry and collaborator on the open-source OpenKAT project. See the project on GitHub and the profile at github.com/hasecon. Exposentry provides EU-sovereign, forensically substantiated vulnerability monitoring based on OpenKAT. More articles in the Knowledge base.