NIS2: are you in scope? Who the directive covers and what they must do
A practical overview of NIS2: who the directive applies to, what obligations it brings and how to tell whether your company is in scope. No unnecessary jargon.
Roman Olejnikov
Founder of Integrity, a certified Cloudflare partner for the Czech and Slovak market. Helps companies with security, performance and NIS2/DORA compliance.

There is a lot of noise around NIS2 and few concrete answers. Most companies ask one single question: does it apply to us or not? This article answers that first, and only then what follows from it.
NIS2 in one sentence
NIS2 is the European cybersecurity directive that significantly widens the range of companies with obligations and toughens the sanctions. In the Czech Republic it is put into practice by the new Cybersecurity Act, overseen by NÚKIB, the national cyber security agency. Put simply: more companies, more obligations, personal accountability of management.
How to tell whether you are in scope
Three questions decide it. If you answer "yes" to the first two, you are very likely in scope.
- Sector. Do you operate in energy, transport, banking, healthcare, water, digital infrastructure, public administration, manufacturing, postal services, waste, food or as a digital service provider? NIS2 divides entities into essential and important; both categories have obligations and differ mainly in the intensity of supervision.
- Size. Do you have 50 or more employees, or an annual turnover above 10 million euros? That is the basic threshold. For some types of services (for example DNS providers, TLD registries, some digital service providers) the size threshold does not apply and you are in scope regardless of headcount.
- Supply chain. Even if you are not in scope yourself, a customer who falls under NIS2 may oblige you to meet part of the requirements. Supplier security is one of the explicit obligations.
If you are still unsure after these three questions, you are not alone; the boundaries for "important" entities tend to be blurry in practice. That is exactly why a structured assessment makes more sense than a guess.
What you will actually have to meet
The obligations can be summed up in four blocks:
- Risk management. Measures that are in place and can be evidenced: access control, encryption, backups, network protection, vulnerability handling, business continuity.
- Incident reporting. A significant incident is reported to NÚKIB within clearly set deadlines (an early warning within roughly 24 hours, a more detailed report within 72 hours). You therefore have to be able to detect an incident in time; without detection there is nothing to report.
- Management accountability. The statutory body approves the measures and is accountable for them. Non-compliance carries fines that, for essential entities, are calculated as a percentage of total turnover.
- Supply chain security. You also have to address risks that come from suppliers and service providers.
The most common mistake: "we have a firewall, we are fine"
NIS2 is not about a single product. It is about evidence: not only having the measures, but being able to describe them, test them and act on them when an incident happens. A firewall is one piece of the puzzle; what is typically missing next to it is detection, access control, protection of web and API interfaces and the ability to withstand a volumetric attack that floods the network before the rules are even reached.
Where to start so it does not become a year-long project
- Establish your scope. Essential or important entity? Everything else follows from that.
- Do a gap analysis. Where are today's gaps against the risk management requirements.
- Build detection and response. Without the ability to recognise an incident you cannot meet the reporting duty.
- Secure your interfaces and availability. Web, API and DDoS resilience are what an attacker tests first.
- Involve your suppliers. Contractually and technically.
A short self-assessment to begin with
Ask yourself: Do we know which NIS2 category we belong to? Would we recognise a significant incident within 24 hours? Do we have measures we can evidence, not just tools? Do we address supplier risk? If you hesitate on any of these, you have the first item on your list.
Not sure about your scope or where to start? We will go through your specific case with you in a short consultation and show how Cloudflare covers detection, interface protection and attack resilience from a single platform. Arrange a free pilot →
Integrity is a certified Cloudflare partner focused on the Czech and Slovak market.
Integrity
news
Articles from our blog. The latest about the Cloudflare platform and everything around it.
.jpg)

.jpg)



