NIS2 Affected Sectors: The 18 Industries and Who Counts as Essential vs Important
The EU's NIS2 Directive dramatically widens cybersecurity regulation: instead of a short list of critical operators, it covers organizations in 18 sectors. Eleven are 'sectors of high criticality' — energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, and space. Seven more are 'other critical sectors' — postal and courier services, waste management, chemicals, food, manufacturing (including medical devices, electronics, machinery and vehicles), digital providers such as online marketplaces and search engines, and research.
Within these sectors, NIS2 distinguishes 'essential' and 'important' entities. Essential entities are, broadly, large organizations (250+ employees or over €50 million turnover) in the high-criticality sectors, plus certain operators regardless of size — such as qualified trust service providers or sole national providers of an essential service. Important entities are mid-sized organizations (50+ employees or over €10 million turnover) in any of the 18 sectors, and larger ones in the 'other critical' group. The substantive security duties are nearly identical; what differs is supervision — proactive oversight for essential entities, reactive for important ones — and the fine ceilings.
For international groups the sector list deserves a careful read, because manufacturing and food land far more companies in scope than the word 'critical infrastructure' suggests. Germany implements NIS2 through the BSIG, its national cybersecurity act, supervised by the BSI, Germany's Federal Office for Information Security — and a German production subsidiary of a foreign group can be in scope even when the parent faces no comparable rule at home. Check your exposure with our NIS2 scope assessment, and see the NIS2 fines overview for what non-compliance costs.
Your checklist
- 1List all group entities with EU operations and map each one's actual activities — not its marketing description — against the 18 NIS2 sector definitions in the directive's annexes.
- 2Check size per entity: apply the thresholds (50+ employees or €10M+ turnover for important; 250+ employees or €50M+ turnover for essential-tier size) using EU SME rules, which can pull in group headcount.
- 3Screen for size-independent triggers: certain providers — such as DNS services, TLD registries and qualified trust services — are covered regardless of size.
- 4Classify each in-scope entity as essential or important, and document the reasoning — the classification drives registration details, supervision intensity and fine exposure.
- 5Register in-scope entities with the national authority: in Germany, that is the BSI under the BSIG, within the statutory deadline after determining you are covered.
- 6Verify manufacturing scope carefully: production of medical devices, electronics, machinery, vehicles and chemicals is covered — the sectors where international industrial groups most often miss their exposure.
- 7Assess supply-chain pull-in: even out-of-scope entities face NIS2-derived security requirements contractually when they supply regulated customers.
- 8Start the compliance program for covered entities: risk management, incident reporting within 24 hours, and management accountability — our NIS2 compliance checklist walks through the steps.
Frequently asked questions
Which sectors are covered by NIS2?
Eighteen in total. Eleven high-criticality sectors: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. Seven other critical sectors: postal and courier services, waste management, chemicals, food production and distribution, manufacturing (including medical devices, electronics, machinery and vehicles), digital providers, and research.
What is the difference between essential and important entities?
Both must implement essentially the same cybersecurity risk-management measures and report significant incidents. The differences are supervision and sanctions: essential entities face proactive oversight including regular audits and higher maximum fines (up to €10 million or 2% of worldwide turnover), while important entities are supervised reactively — typically after indications of a violation — with maximums of €7 million or 1.4%.
Is a company automatically in scope just because it operates in a listed sector?
No. As a rule, an entity must also meet the size threshold — at least 50 employees or more than €10 million in annual turnover — to be covered. Exceptions exist for specific operators covered regardless of size, such as certain digital-infrastructure and trust-service providers, and member states can designate additional entities individually.
Does NIS2 cover manufacturing companies?
Yes — this surprises many. Manufacturing of medical devices and in-vitro diagnostics, computers and electronics, electrical equipment, machinery, motor vehicles and other transport equipment is listed among the covered sectors. A mid-sized production plant in Germany belonging to a foreign industrial group can therefore be an 'important entity' with full NIS2 obligations under the German BSIG.