Which sectors are covered by NIS2 and the Cybersecurity Act?

The law covers 18 sectors, split into 11 sectors of high criticality and 7 other critical sectors. Here's the full list, with concrete examples.

The sector alone doesn't decide whether you're essential or important - your size does too. See the classification section further down. First, the 18 sectors.

11 sectors of high criticality

7 other critical sectors

Essential or important - what decides it?

Size decides it, not just the sector. Large organisations (generally 250+ employees or over €50M in revenue) in the 11 sectors of high criticality are classed as essential - they get planned, more active supervision and a higher sanctions cap. Medium-sized organisations (50-249 employees or €10-50M in revenue) in the same 11 sectors, plus all organisations above the threshold in the 7 other critical sectors, are classed as important - supervision there is reactive, triggered when the authority has reason to suspect non-compliance. Smaller organisations below the thresholds generally aren't covered directly, but can be covered indirectly as a supplier to one that is.

This page is a general summary, not legal advice. Edge cases and exemptions exist - contact us or a lawyer for an assessment of your specific situation.

Not sure if you're in scope? Take the self-testRead more about NIS2 and the Cybersecurity Act