Which sectors are covered by NIS2 and the Cybersecurity Act?
The law covers 18 sectors, split into 11 sectors of high criticality and 7 other critical sectors. Here's the full list, with concrete examples.
The sector alone doesn't decide whether you're essential or important - your size does too. See the classification section further down. First, the 18 sectors.
11 sectors of high criticality
Energy
Electricity grid operators, power generation, district heating, oil and gas, hydrogen
Transport
Air, rail, water, and road transport
Banking
Banks and credit institutions
Financial market infrastructure
Trading venues and central counterparties
Health
Hospitals, healthcare providers, laboratories, pharmaceutical manufacturers
Drinking water
Public water utilities
Waste water
Public wastewater and treatment utilities
Digital infrastructure
Data centres, cloud services, DNS providers, internet exchange points, telecom operators
ICT service management (B2B)
Managed service and security service providers running IT for other companies
Public administration
Central government bodies, in some cases local and regional government
Space
Satellite operators and space infrastructure
7 other critical sectors
Postal and courier services
Postal operators, courier and parcel delivery companies
Waste management
Waste management and recycling companies
Manufacture, production and distribution of chemicals
Chemical manufacturers and distributors
Production, processing and distribution of food
Food producers, wholesalers, large-scale distributors
Manufacturing
Medical devices, electronics, machinery, motor vehicles, other transport equipment
Digital providers
Online marketplaces, search engines, social networking platforms
Research
Research organisations
Essential or important - what decides it?
Size decides it, not just the sector. Large organisations (generally 250+ employees or over €50M in revenue) in the 11 sectors of high criticality are classed as essential - they get planned, more active supervision and a higher sanctions cap. Medium-sized organisations (50-249 employees or €10-50M in revenue) in the same 11 sectors, plus all organisations above the threshold in the 7 other critical sectors, are classed as important - supervision there is reactive, triggered when the authority has reason to suspect non-compliance. Smaller organisations below the thresholds generally aren't covered directly, but can be covered indirectly as a supplier to one that is.
This page is a general summary, not legal advice. Edge cases and exemptions exist - contact us or a lawyer for an assessment of your specific situation.