We use necessary cookies to run this site, and analytics cookies only if
you accept.
Change your choice anytime from the footer.Privacy Policy
Free NIS2 scope check
Answer a few questions about your sector and size and get an instant result, with the reasoning behind it and the legal articles it rests on. No email required.
This check is computed against Romania's NIS2 law
This tool's underlying decision engine applies OUG 155/2024, Romania's transposition of Directive (EU) 2022/2555 (NIS2), including its exact Annex I and Annex II sector lists and size thresholds. The Annex I/II sector categories are the same ones the directive itself defines, so the sector and size logic below is a close match for the EU-wide rules. But the article numbers this tool cites, and country-specific detail like registration deadlines, are Romania's. Other member states transposed the same directive with different national laws, different deadlines and different competent authorities, and as of 8 July 2026 France, Spain and Ireland had not transposed NIS2 into national law at all and were referred to the Court of Justice of the European Union. See the full country-by-country picture on the NIS2 transposition status page before treating a citation on this page as the law in your own country.
Before you fill in the form below, here is what this checker actually returns for two real inputs, tested directly in this tool. Both are computed against Romania's OUG 155/2024, per the caveat above.
Example 1
A large energy operator, with a clear CAEN signal
CAEN code 3513 and 1,966 employees, an electricity transmission operator. The CAEN code points at the Energy sector in Annex I, and the headcount clears the large-enterprise threshold, so the large-enterprise-in-a-critical-sector rule applies.
IN SCOPE FOR NIS2(essential entity)
Large enterprise, Annex I sector: Energy
OUG 155/2024, Annex I, point 1 | OUG 155/2024 art. 8(1)
CAEN code 6290 and 1 employee, a small IT company. This time the CAEN code does not point at a single sector: it partially matches two, ICT service management (business-to-business) and digital infrastructure. The tool does not guess between them, it asks you to confirm the role.
Enter your sector or a CAEN code, your headcount and your turnover or balance sheet total in EUR, then answer whether your company is owned by or affiliated with another company. The tool runs entirely in your browser: no data is sent anywhere, and the result appears instantly. There is no email gate.
What this does not replace
This is not a legal determination. Your result is directional, based only on what you enter, and your national competent authority makes the final call on your classification. If your company is part of a group, this tool always returns "cannot be determined automatically", because whether group affiliation changes how a subsidiary is sized is an unresolved legal question under Romanian law, not a settled fact this tool can assume either way.
Your sector (or a CAEN code, if you have a Romanian one), your average headcount for the last financial year, and your annual turnover or balance sheet total in EUR. A handful of yes/no questions about special entity types and group affiliation take it from there.
How accurate is this result?
It reflects exactly what our decision engine computes from the facts you enter, against Romania's OUG 155/2024. It is not an official determination: about 85% of NIS2 Annex I/II rows are defined by regulatory role or licence status, not by sector code or size alone, so a large share of honest answers are "cannot be determined automatically", not a guess dressed up as a yes or no.
What do essential and important entity mean?
They are the two classifications NIS2 uses for in-scope organisations. Essential entities face closer supervision; important entities have the same core Article 21 obligations but lighter-touch oversight. Large enterprises in Annex I sectors are generally essential; medium enterprises in Annex I and most Annex II entities are generally important. A few provider types, DNS operators among them, are essential regardless of size.
What do I do next if I am in scope?
Register with your national competent authority, if you have not already, implement the Article 21(2) risk-management measures proportionate to your size and exposure, be ready to report significant incidents on the 24-hour/72-hour/1-month timeline, and check whether your country adds its own statutory audit or assessment requirement on top of the directive. See the obligations panel in your result for the full breakdown.