P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Free tool

Am I in scope for NIS2, DORA or the UK Cyber Bill?

Answer nine questions and see which cyber regimes reach your organisation, with the reasoning behind every verdict and the primary sources.

Scope is the first question anyone asks about a new cyber regime and the hardest to get a straight answer to, because the summaries in circulation are frequently wrong about the thresholds that decide it. This walks the actual tests in NIS2, DORA and the UK Cyber Security and Resilience Bill, shows the chain of reasoning that produced each verdict, and links the primary text so you can check the work rather than take it on faith.

Nothing leaves your browser: Your answers describe your organisation's size, sector and dependencies, so none of them leave your browser. There is no submission and no account, and the page is served with a Content Security Policy whose connect-src 'none' rule blocks fetch, XHR, WebSocket, EventSource and sendBeacon. Open your developer tools and watch the network tab while you answer. A policy inside the page cannot stop you copying the result somewhere else, so what you do with it afterwards is yours to protect. Refreshing the page loses your work.

Last reviewed:
Open data: download the full dataset as JSON

About your organisation

0 of 6 answered

  1. 01

    Where is your organisation established?

    Establishment is what anchors jurisdiction under NIS2 and DORA, so this determines most of what follows.

  2. 02

    Which of these describes what your organisation does?

    Select every one that applies. Leave blank if none do.

  3. 03

    Do you provide any of these specific services?

    These carry rules of their own, several of which apply regardless of how small you are.

  4. 04

    How many people does the organisation employ?

    Count the whole enterprise, including linked and partner enterprises where a group relationship exists.

    employees
  5. 05

    What is annual turnover?

  6. 06

    Are you an authorised financial entity?

    DORA binds entities authorised in the EU, such as credit institutions, investment firms, insurers, payment and e-money institutions, crypto-asset service providers and pension institutions.

Answer the remaining 6 questions to continue.

The three regimes, and where each stands

NIS2

Directive (EU) 2022/2555

The EU's baseline cybersecurity regime for essential and important entities.

Status: In force since 16 January 2023 and applicable from 18 October 2024. It is a Directive, so the obligations that bind you come from your Member State's transposing law, which varies in thresholds, sector scoping and penalties.

DORA

Regulation (EU) 2022/2554

Digital operational resilience for the EU financial sector, including direct oversight of critical IT providers.

Status: In force since 16 January 2023 and applicable since 17 January 2025. Being a Regulation it is directly applicable, with no transposition step.

UK Cyber Security and Resilience Bill

Bill 4035, HL Bill 32

The UK's update to the NIS Regulations 2018, adding data centres, managed service providers and designated critical suppliers.

Status: NOT YET LAW. The Bill is in the House of Lords and has not received Royal Assent. Lords committee stage begins 1 September 2026, and the scope below may change there. The Bill contains no commencement date for its substantive provisions: they come into force on a day the Secretary of State appoints by regulations.

Three things published tools get wrong

Each of these changes a verdict, and each was verified against the primary text rather than a summary.

  1. Size cannot make an Annex II entity essential

    Article 3(1)(a) elevates Annex I entities only. A manufacturer with ten thousand employees is an important entity, and the difference decides both the supervisory regime and the penalty ceiling.

  2. The financial ceilings are cumulative going up

    An entity exceeds the medium-sized ceilings only when turnover is above EUR 50 million and balance sheet total is above EUR 43 million. Headcount of 250 or more suffices on its own. Treating the financial tests as alternatives over-classifies organisations.

  3. NIS2 is not generally extraterritorial

    A UK organisation with no EU establishment is reached directly only in the nine digital categories in Article 26(1)(b). For everyone else the pressure is contractual, arriving through the supply-chain duties Article 21 places on their EU customers, which is a different thing and worth saying precisely.

Verified against primary sources on 2026-08-03. NIS2 is a Directive, so your Member State’s transposing law governs; the UK Bill is not law and has no commencement date. Both are re-checked on a schedule, and the UK position will be reviewed after Lords committee stage.

Common questions

Does NIS2 apply to UK companies?

Only in narrow circumstances, and this is the point most summaries get wrong. NIS2 anchors jurisdiction to establishment. A UK organisation with no EU establishment is reached directly only if it falls in one of the nine digital categories in Article 26(1)(b), which include cloud, data centre, CDN, managed service, managed security, DNS, TLD registry, domain registration and online platform providers. Those must appoint an EU representative. For everyone else the exposure is contractual: your EU customers must manage supply-chain security under Article 21, and they push that down in contracts.

What is the difference between an essential and an important entity?

Supervision and penalties. Essential entities face comprehensive supervision both before and after the fact, including random checks, regular audits and powers to suspend authorisation or ban a chief executive from management functions, with a penalty ceiling of at least EUR 10 million or 2% of worldwide turnover, whichever is higher. Important entities face lighter, after-the-fact supervision triggered by evidence of non-compliance, and a ceiling of at least EUR 7 million or 1.4%. Incident reporting deadlines are identical for both.

Can size alone make my organisation an essential entity?

Only if you are in an Annex I sector of high criticality. Size cannot elevate an Annex II entity: a manufacturer with ten thousand employees is an important entity, not an essential one. Getting this backwards is the single most common error in published scope tools. Separately, qualified trust service providers, TLD name registries and DNS service providers are essential irrespective of size.

Has the UK Cyber Security and Resilience Bill become law?

No. As at 3 August 2026 it is in the House of Lords and has not received Royal Assent, with Lords committee stage due to begin on 1 September 2026. Its scope can still change. The Bill also contains no commencement date for its substantive provisions: they come into force on a day the Secretary of State appoints by regulations, and the government has said only that it intends to consult on implementation during 2026. Any specific date quoted elsewhere is commentary rather than law.

How does the UK Bill differ from NIS2 on incident reporting?

The UK Bill runs a two-stage clock: an initial notification within 24 hours and a full notification within 72 hours, with an express duty to notify affected customers. NIS2 adds stages after that: an intermediate report if the authority requests one, and a final report within one month of the 72-hour notification, plus a progress report where the incident is still running. The UK therefore front-loads more substance into 72 hours and requires nothing afterwards.

Is this legal advice?

No. It is an indicative assessment from the answers you give, and scope decisions turn on facts this tool does not ask about. NIS2 in particular is a Directive, so what binds you is your Member State's transposing law, which varies in thresholds and sector scoping. Every regime links its primary source so you can check the position, and anything consequential warrants proper advice.

When you need more than a tool

vCISO Advisory

Embedded security leadership one to three days a week: board reporting, programme direction, and decisions taken with accountability, without a full-time hire.

Discuss vCISO support

Share this tool

Free, no sign-up, and nothing you type leaves your browser.

Related analysis

← All free tools