Work out whether NIS2, DORA or the UK Bill reaches you
A method that produces an answer you can defend rather than one you can produce quickly, because published guidance on these thresholds is wrong often enough that a summary cannot be trusted.
By Parminder Kumar Sharma · · 9 min read

Why this is harder than it should be
Three regimes, overlapping sectors, and a body of published guidance that gets the thresholds wrong often enough that you cannot trust a summary. Including, on occasion, summaries published by people selling compliance services.
The method below produces an answer you can defend, which matters more than an answer you can produce quickly.
Establish these in order
- JurisdictionWhere established
- ActivityWhich sectors
- ThresholdWhat size
- With reasoningVerdict

- 1Jurisdiction Where you are established, not where the customers are
- 2Sector A specific Annex I or Annex II entry you can point at
- 3Size Size elevates to essential only within Annex I
- 4The reasoning, dated Cited to primary text, with what would change it
Step one: jurisdiction, which most people skip
Establish where you are established
This is the question that decides most cases and it is the one summaries skip. NIS2 anchors to establishment. Having EU customers is not the same as having an EU establishment, and the two lead to completely different answers.
You should see: A list of the countries where your organisation has an establishment, not just customers.
Check whether you fall in a category caught regardless
Cloud computing, data centre, content delivery network, managed service, managed security service, DNS, TLD name registry, domain registration and online platform providers are reached without an EU establishment, and must appoint an EU representative.
If you are none of those and have no EU establishment, NIS2 does not reach you directly. Your exposure is contractual instead, which is real but is a different problem with different answers.
You should see: A yes or no on each of the digital categories in NIS2 Article 26(1)(b).
Step two: sector, in the right annex
Find your activity in Annex I or Annex II
Annex I is sectors of high criticality: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space.
Annex II is other critical sectors: postal and courier, waste management, chemicals, food, manufacturing of certain products, digital providers, research.
Which annex you are in decides whether size can make you essential.
You should see: You can point at the specific annex entry, not a paraphrase of it.
Apply the size test, in the right direction
Medium and large entities in scope sectors are caught. But size only elevates within Annex I: a very large Annex II manufacturer is an important entity, not an essential one.
This is the single most common error in published scope tools, and it changes both your supervision regime and your penalty ceiling.
You should see: You have not concluded that being large makes you essential.
The three regimes side by side
Holding the differences in mind is most of the difficulty, so they are worth setting out once rather than inferring from three separate readings.
What each regime actually turns on
| NIS2 | DORA | UK Cyber Security and Resilience Bill | |
|---|---|---|---|
| Instrument | Directive, so national law binds you rather than the directive | Regulation, directly applicable, no transposition | Bill, still progressing, so scope can change |
| Who it catches | Annex I and II sectors, at medium size or above | Financial entities, and ICT third-party providers to them | Expected to widen the existing NIS Regulations, including managed service providers |
| The size test | 50 staff, or turnover and balance sheet above 10 million euros | No size test. A small firm in scope is in scope | Not settled |
| How it reaches a supplier | Article 21(2)(d), passed down as a contract term | Directly, through the third-party provider regime and the register | Expected to name managed service providers directly |
| Applies since | National law, where it exists. Four states referred to the CJEU | 17 January 2025 | Not yet in force |
The middle column is the one that catches people. DORA has no size test, so the reasoning that keeps a small organisation outside NIS2 does nothing here. And it reaches ICT providers directly rather than only through their customers, which is a different mechanism from the one NIS2 uses.
Step three: the other two regimes
DORA
- A Regulation, so it applies directly and identically across the EU. No transposition question.
- Financial entities, defined by a list of entity types rather than by size alone.
- Also reaches ICT third-party service providers to those entities, which catches suppliers who do not think of themselves as regulated.
- Where DORA and NIS2 overlap, DORA generally takes precedence as the more specific regime.
UK Cyber Security and Resilience Bill
- Still a Bill. Check its current parliamentary stage before relying on any date.
- No commencement date for the substantive provisions: they come into force on a day the Secretary of State appoints.
- Two-stage reporting: initial notification within 24 hours, full notification within 72, plus an express duty to notify affected customers.
- Any specific date quoted elsewhere is commentary rather than law.
The answer that matters most is usually about somebody else
Most organisations reading this will conclude they are not directly in scope of any of the three. That conclusion is often correct and almost always incomplete, because the question a customer asks is different from the question the law asks.
Three routes bring an out-of-scope organisation inside the requirements anyway, and none of them depends on your own classification.
Contractual pass-down. An in-scope entity cannot discharge its supply chain obligation by hoping. It imposes terms, so the requirement arrives as a clause with hours in it, audit rights and evidence requests, and it arrives without the softening a regulator would apply to an organisation your size.
Designation. Under DORA a provider can be designated critical and supervised directly. That is a decision made about you rather than by you.
Procurement, before either. Long before any of this is enforced, the questionnaire arrives. A supplier who cannot describe its incident reporting timeline loses the account, which is faster and blunter than any regulator.
The practical consequence is that "we are out of scope" is not the end of the assessment. It is the point at which you start listing which of your customers are in scope, because their obligations become your contract terms.
When to redo it
A scoping assessment is a snapshot, and four things invalidate it. Put a review date on the document and a note of what would trigger an early one.
A Member State transposes, or changes what it transposed. NIS2 binds through national law, and several states are still producing it. Four were referred to the Court of Justice in July 2026 for failing to. An assessment that concluded nothing applies in a given country can become wrong without anybody doing anything.
You win a customer in a new sector or country. The output test and the supply chain route both follow the customer rather than you.
You cross the size threshold. Fifty staff, or turnover and balance sheet above ten million euros. Organisations pass this during a hiring round and nobody re-runs the assessment, because it does not feel like a compliance event.
The UK Bill completes its passage. Its scope is not settled, and the expectation that it will name managed service providers directly would bring a population inside that is currently outside every one of the three.
Annually is a reasonable default. Sooner if any of the four happens, which is why the trigger list matters more than the date.
Step four: record the reasoning, not just the answer
This is what separates a scope assessment from a guess.
Write the chain, one line per step
Established in X. Activity falls in Annex Y entry Z. Headcount and turnover above or below the threshold. Therefore essential or important or out of scope. Each line traceable to something you can point at.
You should see: A colleague could follow the reasoning without asking you a question.
Cite the primary text, not a summary
Summaries are where the errors come from. If your reasoning cites a consultancy blog, your reasoning inherits whatever that blog got wrong.
You should see: Every conclusion links to the Directive, Regulation or Bill rather than to an article about it.
Note what would change the answer
Opening an EU establishment. Crossing a headcount threshold. Acquiring a business in a scope sector. Being named as a critical supplier by a customer. Scope is a decision with a shelf life.
You should see: A short list of facts that, if they changed, would need re-assessment.
Take this with you
A defensible scope assessment
- Jurisdiction established first, on establishment rather than on where customers are.
- The digital categories that apply without establishment checked explicitly.
- Activity matched to a specific annex entry you can point at.
- Size test applied in the correct direction: size elevates only within Annex I.
- DORA precedence considered where a financial entity is also in a NIS2 sector.
- UK Bill treated as not yet in force, with its parliamentary stage checked rather than assumed.
- Every conclusion cited to primary text rather than to a summary.
- A list of facts that would require re-assessment if they changed.
- The assessment dated, because scope decisions expire.
Verified
Written 5 August 2026. Positions taken from the primary texts: Directive (EU) 2022/2555, Regulation (EU) 2022/2554, and the UK Bill as currently before Parliament. Re-check the Bill's stage before relying on it.


