CRA full compliance required 453 days left What it means for you
THZ Networks Under attack? SOS — incident response, any hour of any day

GUIDES

Are you in scope? A ten-minute self-check

Four questions that settle which of the European regimes apply to you, and one common way organisations get caught without being named anywhere.

1. What do you do, and how big are you?

NIS2 works on sector and size together. If your activity is in one of the named sectors and you have 50 or more staff or €10 M or more of turnover, you are in scope — as an essential entity in the critical sectors, as an important entity in the rest. Some entities are caught at any size, irrespective of the thresholds.

Start from the sector pages rather than the directive: they are written around the activity, not the annex number.

2. Do you handle money or financial risk?

DORA does not use size thresholds the way NIS2 does. It applies by activity: banking, insurance, investment, payments, crypto-assets, and the ICT providers serving them. It has applied since January 2025, so this is not a deadline question any more.

3. Do you put a product on the EU market?

If it has a network interface or a radio, the CRA and RED reach it regardless of your sector. That catches manufacturers who have never thought of themselves as a technology company — machinery, appliances, sensors, anything with firmware.

4. And the one people miss: your clients

You can be outside every one of these regimes and still have to answer them, because your client is inside one and their supply-chain obligation lands on you as a contract clause and a questionnaire. In practice this arrives earlier than any regulator would, and it is the commonest reason a small supplier suddenly needs evidence it has never produced.

If you are not sure which of the four applies, describe what you do and we will put the answer in writing.