Is Your Organisation In Scope for NIS2?

NIS2 applies to medium and large organisations (50+ employees or \u20ac10M+ turnover) operating in 18 critical sectors. But the details matter \u2014 especially for healthcare, care services, and HSE-funded organisations.

Find your organisation type below to understand whether NIS2 applies to you.

The NIS2 Scope Test

An organisation is in scope for NIS2 if it meets both conditions:

1. Sector

Operates in one of the 18 critical sectors defined by the directive (healthcare, energy, transport, digital infrastructure, etc.)

2. Size

Meets the medium-enterprise threshold: 50+ employees or \u20ac10M+ annual turnover or \u20ac10M+ balance sheet

Some entities are in scope regardless of size (DNS providers, TLD registries, qualified trust service providers).

Organisation Types & NIS2 Scope

HSE-Funded Healthcare Providers

Healthcare is explicitly listed as an essential sector under NIS2.

Likely In Scope

If your organisation provides healthcare services, manages patient data systems, or operates clinical IT infrastructure funded or contracted by the HSE, you are very likely in scope as an essential entity. This includes hospitals, primary care centres, and diagnostic services.

Disability Services (Section 38/39)

HSE-funded disability services are increasingly classified as healthcare providers under NIS2.

Likely In Scope

Organisations providing residential or day services under HSE Section 38 or 39 arrangements manage sensitive health data and critical care systems. Where these organisations meet medium-enterprise thresholds (50+ employees or €10M+ turnover), they will likely fall within NIS2 scope.

Brain Injury Services

Specialist rehabilitation services managing clinical systems and patient records are in scope.

Likely In Scope

Organisations like Acquired Brain Injury Ireland and similar providers operate clinical IT systems, manage patient records, and coordinate care pathways. These functions place them firmly within the healthcare sector definition under NIS2.

Hospices & Palliative Care

Hospices managing electronic health records and clinical systems are healthcare entities.

Likely In Scope

Hospice and palliative care providers operate medication management systems, electronic patient records, and connected medical devices. A breach could directly affect continuity of care for vulnerable patients, making these organisations essential under NIS2.

Nursing Homes & Residential Care

Depends on size, HSE funding, and digital infrastructure.

Possibly In Scope

Nursing homes managing electronic care records, connected medication dispensing, or HSE-contracted services may be in scope. Smaller private nursing homes below the medium-enterprise threshold may be excluded, but those in HSE-funded groups or using connected health platforms should assess carefully.

Home Care Providers

HSE-funded home care packages with digital scheduling and care records may trigger scope.

Possibly In Scope

Large home care providers managing digital rostering, electronic care plans, and mobile health applications may meet NIS2 thresholds. If you hold HSE home care contracts and operate digital care management platforms, you should assess your scope status.

Intellectual Disability Organisations

Major Section 38/39 bodies providing residential care with health IT systems are in scope.

Likely In Scope

Organisations providing intellectual disability services often manage medication systems, incident reporting platforms, and personal data for vulnerable individuals. Those meeting size thresholds and operating digital health infrastructure will be classified under NIS2.

Charities & Voluntary Organisations

Depends on whether the charity operates in a NIS2 sector and meets size thresholds.

Possibly In Scope

Charities are not automatically excluded from NIS2. If a charity operates in healthcare, social care, education, or digital infrastructure and meets medium-enterprise thresholds, it falls within scope. Many large Irish charities providing HSE-funded services will need to assess their position.

Schools & Educational Institutions

Primary and secondary schools are generally not in scope. Universities may be.

Unlikely In Scope

Individual schools are typically too small to meet NIS2 thresholds. However, university groups, institutes of technology, and large education bodies managing research data or critical digital infrastructure may fall within scope, particularly under the research sector classification.

Local Authorities

Member States may include local authorities under public administration scope.

Possibly In Scope

NIS2 covers public administration entities, but Member States can exclude local government bodies. Ireland’s transposition will determine whether county councils, city councils, and municipal bodies are explicitly included. Those managing critical water, waste, or digital services should prepare regardless.

Energy & Utilities

Energy is an essential sector explicitly listed under NIS2.

Likely In Scope

Electricity generators, gas distributors, district heating operators, and fuel suppliers meeting size thresholds are essential entities. This includes ESB subsidiaries, Bord Gáis, wind farm operators, and energy trading platforms operating in Ireland.

Transport & Logistics

Transport is an essential sector under NIS2.

Likely In Scope

Air, rail, water, and road transport operators meeting size thresholds are in scope. This includes airport operators, port authorities, public transport bodies, and logistics companies managing critical supply chains.

Manufacturing

Manufacturing of certain products (medical devices, chemicals, food) is in scope.

Possibly In Scope

NIS2 covers manufacturers of medical devices, in-vitro diagnostics, chemicals, food products, and other critical goods. Irish pharmaceutical and medtech manufacturers should assess their NIS2 obligations carefully.

MSPs & IT Service Providers

ICT service management is explicitly in scope under NIS2.

Likely In Scope

Managed service providers, managed security service providers, cloud service providers, and data centre operators are important entities under NIS2. If your clients are in scope, your obligations extend to securing the services you provide to them.

Not Sure If You're In Scope?

Book a 30-minute executive briefing and we'll assess your organisation's NIS2 classification, obligations, and recommended next steps — free of charge.

Frequently Asked Questions

Are charities covered by NIS2?

Charities are not automatically exempt. If a charity operates in a NIS2 sector (e.g., healthcare) and meets the medium-enterprise threshold (50+ staff or €10M+ turnover), it falls within scope. Many large HSE-funded charities in Ireland will need to assess their status.

Are schools covered by NIS2?

Individual primary and secondary schools are generally too small to meet NIS2 thresholds. However, university groups, institutes of technology, and education bodies managing research infrastructure or large digital platforms may be in scope.

Are hospices covered by NIS2?

Hospices managing electronic health records, medication systems, and connected medical devices are likely in scope as healthcare providers. The key factors are size threshold and the nature of digital systems in use.

Are nursing homes covered by NIS2?

It depends on size and HSE funding. Nursing home groups meeting the medium-enterprise threshold that manage electronic care records and connected health systems may fall within scope. Single-site private nursing homes below the threshold are less likely to be covered.

Are disability services covered by NIS2?

HSE Section 38/39 disability service providers managing health IT systems, patient records, and care management platforms are increasingly likely to be classified as healthcare entities under NIS2 — particularly those meeting size thresholds.

Are local authorities covered by NIS2?

NIS2 covers public administration, but Member States can exclude local government. Ireland’s transposition will determine whether county and city councils are included. Those managing critical digital infrastructure (water, waste, transport) should prepare.

What are the penalties for non-compliance?

Essential entities face fines up to €10 million or 2% of global turnover. Important entities face up to €7 million or 1.4% of global turnover. Directors face personal liability for failures in cybersecurity governance.