Is Your Organisation In Scope for NIS2?
NIS2 applies to medium and large organisations (50+ employees or \u20ac10M+ turnover) operating in 18 critical sectors. But the details matter \u2014 especially for healthcare, care services, and HSE-funded organisations.
Find your organisation type below to understand whether NIS2 applies to you.
The NIS2 Scope Test
An organisation is in scope for NIS2 if it meets both conditions:
1. Sector
Operates in one of the 18 critical sectors defined by the directive (healthcare, energy, transport, digital infrastructure, etc.)
2. Size
Meets the medium-enterprise threshold: 50+ employees or \u20ac10M+ annual turnover or \u20ac10M+ balance sheet
Some entities are in scope regardless of size (DNS providers, TLD registries, qualified trust service providers).
Organisation Types & NIS2 Scope
HSE-Funded Healthcare Providers
Healthcare is explicitly listed as an essential sector under NIS2.
Likely In Scope
HSE-Funded Healthcare Providers
Healthcare is explicitly listed as an essential sector under NIS2.
If your organisation provides healthcare services, manages patient data systems, or operates clinical IT infrastructure funded or contracted by the HSE, you are very likely in scope as an essential entity. This includes hospitals, primary care centres, and diagnostic services.
Disability Services (Section 38/39)
HSE-funded disability services are increasingly classified as healthcare providers under NIS2.
Likely In Scope
Disability Services (Section 38/39)
HSE-funded disability services are increasingly classified as healthcare providers under NIS2.
Organisations providing residential or day services under HSE Section 38 or 39 arrangements manage sensitive health data and critical care systems. Where these organisations meet medium-enterprise thresholds (50+ employees or €10M+ turnover), they will likely fall within NIS2 scope.
Brain Injury Services
Specialist rehabilitation services managing clinical systems and patient records are in scope.
Likely In Scope
Brain Injury Services
Specialist rehabilitation services managing clinical systems and patient records are in scope.
Organisations like Acquired Brain Injury Ireland and similar providers operate clinical IT systems, manage patient records, and coordinate care pathways. These functions place them firmly within the healthcare sector definition under NIS2.
Hospices & Palliative Care
Hospices managing electronic health records and clinical systems are healthcare entities.
Likely In Scope
Hospices & Palliative Care
Hospices managing electronic health records and clinical systems are healthcare entities.
Hospice and palliative care providers operate medication management systems, electronic patient records, and connected medical devices. A breach could directly affect continuity of care for vulnerable patients, making these organisations essential under NIS2.
Nursing Homes & Residential Care
Depends on size, HSE funding, and digital infrastructure.
Possibly In Scope
Nursing Homes & Residential Care
Depends on size, HSE funding, and digital infrastructure.
Nursing homes managing electronic care records, connected medication dispensing, or HSE-contracted services may be in scope. Smaller private nursing homes below the medium-enterprise threshold may be excluded, but those in HSE-funded groups or using connected health platforms should assess carefully.
Home Care Providers
HSE-funded home care packages with digital scheduling and care records may trigger scope.
Possibly In Scope
Home Care Providers
HSE-funded home care packages with digital scheduling and care records may trigger scope.
Large home care providers managing digital rostering, electronic care plans, and mobile health applications may meet NIS2 thresholds. If you hold HSE home care contracts and operate digital care management platforms, you should assess your scope status.
Intellectual Disability Organisations
Major Section 38/39 bodies providing residential care with health IT systems are in scope.
Likely In Scope
Intellectual Disability Organisations
Major Section 38/39 bodies providing residential care with health IT systems are in scope.
Organisations providing intellectual disability services often manage medication systems, incident reporting platforms, and personal data for vulnerable individuals. Those meeting size thresholds and operating digital health infrastructure will be classified under NIS2.
Charities & Voluntary Organisations
Depends on whether the charity operates in a NIS2 sector and meets size thresholds.
Possibly In Scope
Charities & Voluntary Organisations
Depends on whether the charity operates in a NIS2 sector and meets size thresholds.
Charities are not automatically excluded from NIS2. If a charity operates in healthcare, social care, education, or digital infrastructure and meets medium-enterprise thresholds, it falls within scope. Many large Irish charities providing HSE-funded services will need to assess their position.
Schools & Educational Institutions
Primary and secondary schools are generally not in scope. Universities may be.
Unlikely In Scope
Schools & Educational Institutions
Primary and secondary schools are generally not in scope. Universities may be.
Individual schools are typically too small to meet NIS2 thresholds. However, university groups, institutes of technology, and large education bodies managing research data or critical digital infrastructure may fall within scope, particularly under the research sector classification.
Local Authorities
Member States may include local authorities under public administration scope.
Possibly In Scope
Local Authorities
Member States may include local authorities under public administration scope.
NIS2 covers public administration entities, but Member States can exclude local government bodies. Ireland’s transposition will determine whether county councils, city councils, and municipal bodies are explicitly included. Those managing critical water, waste, or digital services should prepare regardless.
Energy & Utilities
Energy is an essential sector explicitly listed under NIS2.
Likely In Scope
Energy & Utilities
Energy is an essential sector explicitly listed under NIS2.
Electricity generators, gas distributors, district heating operators, and fuel suppliers meeting size thresholds are essential entities. This includes ESB subsidiaries, Bord Gáis, wind farm operators, and energy trading platforms operating in Ireland.
Transport & Logistics
Transport is an essential sector under NIS2.
Likely In Scope
Transport & Logistics
Transport is an essential sector under NIS2.
Air, rail, water, and road transport operators meeting size thresholds are in scope. This includes airport operators, port authorities, public transport bodies, and logistics companies managing critical supply chains.
Manufacturing
Manufacturing of certain products (medical devices, chemicals, food) is in scope.
Possibly In Scope
Manufacturing
Manufacturing of certain products (medical devices, chemicals, food) is in scope.
NIS2 covers manufacturers of medical devices, in-vitro diagnostics, chemicals, food products, and other critical goods. Irish pharmaceutical and medtech manufacturers should assess their NIS2 obligations carefully.
MSPs & IT Service Providers
ICT service management is explicitly in scope under NIS2.
Likely In Scope
MSPs & IT Service Providers
ICT service management is explicitly in scope under NIS2.
Managed service providers, managed security service providers, cloud service providers, and data centre operators are important entities under NIS2. If your clients are in scope, your obligations extend to securing the services you provide to them.
Not Sure If You're In Scope?
Book a 30-minute executive briefing and we'll assess your organisation's NIS2 classification, obligations, and recommended next steps — free of charge.
Frequently Asked Questions
Are charities covered by NIS2?
Charities are not automatically exempt. If a charity operates in a NIS2 sector (e.g., healthcare) and meets the medium-enterprise threshold (50+ staff or €10M+ turnover), it falls within scope. Many large HSE-funded charities in Ireland will need to assess their status.
Are schools covered by NIS2?
Individual primary and secondary schools are generally too small to meet NIS2 thresholds. However, university groups, institutes of technology, and education bodies managing research infrastructure or large digital platforms may be in scope.
Are hospices covered by NIS2?
Hospices managing electronic health records, medication systems, and connected medical devices are likely in scope as healthcare providers. The key factors are size threshold and the nature of digital systems in use.
Are nursing homes covered by NIS2?
It depends on size and HSE funding. Nursing home groups meeting the medium-enterprise threshold that manage electronic care records and connected health systems may fall within scope. Single-site private nursing homes below the threshold are less likely to be covered.
Are disability services covered by NIS2?
HSE Section 38/39 disability service providers managing health IT systems, patient records, and care management platforms are increasingly likely to be classified as healthcare entities under NIS2 — particularly those meeting size thresholds.
Are local authorities covered by NIS2?
NIS2 covers public administration, but Member States can exclude local government. Ireland’s transposition will determine whether county and city councils are included. Those managing critical digital infrastructure (water, waste, transport) should prepare.
What are the penalties for non-compliance?
Essential entities face fines up to €10 million or 2% of global turnover. Important entities face up to €7 million or 1.4% of global turnover. Directors face personal liability for failures in cybersecurity governance.