NIS2 scope is difficult to reduce to a single yes or no. The answer depends on sector, company size, entity type, group structure, and a set of exceptions. This guide helps a Danish SaaS CEO or CTO organise those facts before asking for a legal conclusion.
Work through it top to bottom and record the sources behind each answer. The result is a fact and source record, not a scope determination or legal opinion. Have qualified legal counsel confirm the classification before relying on it.
Primary sources checked 1 September 2026: the Danish NIS 2 Act and the NIS2 Directive. Check the current text and the competent authority for the relevant sector before using the record.
Step 1: Record the sector facts
NIS2 applies only to entities operating in the sectors listed in its two annexes or caught by a specific designation or exception. If your business does not fit any listed sector, skip to Step 3. Customers may still ask you for security evidence through their supply-chain controls.
Annex I sectors (high criticality)
| Sector | Common for Nordic B2B SaaS? |
|---|---|
| Energy (electricity, oil, gas, district heating, hydrogen) | No, unless you operate infrastructure |
| Transport (air, rail, water, road) | No |
| Banking | No (regulated separately under DORA) |
| Financial market infrastructure | No (DORA applies) |
| Health (hospitals, labs, pharma, medical device manufacturers) | Yes, if you run clinical infrastructure or certain medtech |
| Drinking water | No |
| Waste water | No |
| Digital infrastructure (DNS, TLD, cloud providers, data centres, CDNs, trust services, electronic comms) | Yes, this captures many infrastructure-tier SaaS |
| ICT service management (managed service providers, managed security service providers) | Yes, if you operate or manage customer ICT systems rather than only license software |
| Public administration | No, unless you are a public body |
| Space (ground infrastructure operators) | No |
Annex II sectors (important entities)
| Sector | Common for Nordic B2B SaaS? |
|---|---|
| Postal and courier services | No |
| Waste management | No |
| Manufacture, production, distribution of chemicals | No |
| Production, processing, distribution of food | No (unless you are an agtech/foodtech producer) |
| Manufacturing (medical devices, computers/electronics, machinery, motor vehicles, other transport equipment) | Sometimes, for hardware-adjacent SaaS |
| Digital providers (online marketplaces, online search engines, social networking platforms) | Sometimes, but the category is narrower than ordinary B2B SaaS. It covers online marketplaces, search engines, and social networks |
| Research (research organisations) | No, unless you are a research institution |
The important nuance: the “digital providers” category under Annex II is narrower than most SaaS founders think. It means online marketplaces, search engines, and social networks. A typical B2B SaaS product sold to businesses (CRM, HR tools, compliance software, analytics) does not automatically fall here.
The category that catches most B2B SaaS and ICT companies is under Annex I: digital infrastructure (if you run DNS, TLD, cloud, data centres, CDN, trust services, or electronic communications) or ICT service management (if you are a managed service provider or managed security service provider).
If no sector applies, jump to Step 3. If one does, continue to Step 2.
Step 2: Record the size facts and possible classification
For entities covered by the Danish NIS 2-loven, the ordinary route uses the thresholds written directly into sections 4 and 5: number of people employed, annual turnover and annual balance-sheet total. Use those statutory values rather than a generic SME table.
| Possible indication before exceptions and legal confirmation | Threshold | Working classification to confirm if in Annex I | Working classification to confirm if in Annex II |
|---|---|---|---|
| Below the ordinary scope threshold | < 50 people employed AND (turnover ≤ EUR 10M OR balance sheet ≤ EUR 10M) | Ordinary threshold may not be met; check exceptions and designations | Ordinary threshold may not be met; check exceptions and designations |
| Meets the important-entity threshold | 50+ people employed OR both turnover > EUR 10M and balance sheet > EUR 10M | Possible important entity; confirm the full legal test | Possible important entity; confirm the full legal test |
| Meets the essential-entity threshold | 250+ people employed OR both turnover > EUR 50M and balance sheet > EUR 43M | Possible essential entity; confirm the full legal test | Possible important entity; confirm the full legal test |
Three working positions to test
Possible position: not directly in scope. The recorded facts indicate that the entity is below the size threshold, outside the listed sectors, or both, and that no exception or designation applies. Read Step 3 anyway because customers may still ask for security evidence and contract commitments.
Possible position: important entity. If qualified counsel confirms this classification, the entity must address the applicable risk-management, incident-reporting and registration duties. Important entities are generally supervised after the authority receives evidence of non-compliance. The NIS2 Directive requires national law to permit maximum fines of at least EUR 7 million or 1.4% of worldwide annual turnover for specified breaches. The Danish NIS 2 Act sets its own enforcement framework and does not repeat those figures as automatic fines.
Possible position: essential entity. If qualified counsel confirms this classification, the same core duties apply with a proactive supervisory regime. The NIS2 Directive requires national law to permit maximum fines of at least EUR 10 million or 2% of worldwide annual turnover for specified breaches. Under Danish law, the management body must approve the cybersecurity measures, oversee their implementation, and complete relevant training. The law does not state a blanket rule that every board member is personally liable for every breach.
Size-independent overrides
Size does not determine scope in a handful of cases. You can be in scope regardless of headcount or revenue if you are:
- A qualified trust service provider, TLD name registry, or DNS service provider
- A non-qualified trust service provider, which is ordinarily classified as important
- A central-government public administration entity or an entity identified under the Danish CER law
- An entity identified by a Member State because it is the sole provider of an essential service, disruption could materially affect public safety, public health, or create systemic cross-border risk, or it is nationally or regionally critical
Scope and classification are separate. Qualified trust service providers, TLD registries and DNS service providers are essential entities regardless of size. A non-qualified trust service provider is ordinarily important unless another essential-entity trigger applies. Domain-name registration services have specific registration and database duties under sections 10 and 11, but that activity alone does not make the provider an essential or important entity. Danish providers covered by the separate laws for energy or telecom security follow those sector laws instead of the general NIS 2-loven for the overlapping duties.
Step 3: Separate direct scope from customer requirements
This is where many Danish SaaS leaders get a false sense of security. You run through steps 1 and 2, you're below the size threshold or your sector is not listed, and you conclude: not in scope, done, filing this away.
That may be the right direct-scope conclusion. It does not settle what a customer may ask for in the contract.
NIS2 Article 21 requires an entity in scope to manage supply-chain security, including vulnerabilities specific to its direct suppliers and service providers. That duty remains with the regulated customer. It does not make an out-of-scope supplier directly subject to Article 21 or prescribe a fixed set of supplier clauses. A customer may nevertheless ask for evidence, negotiate security clauses, or seek customer-notification commitments.
Answering “we're not in scope of NIS2” does not answer a customer's supplier-risk question. The customer may still assess the service, the data involved, your access, and the controls that protect the relationship. Whether it passes requirements to you is a contractual decision, not a new statutory NIS2 status.
Practical rule: if regulated or NIS2-covered customers are commercially important, treat their security requirements as a defined customer-diligence workstream. Do not describe the company as “operationally in scope” unless it is legally in scope.
Step 4: If direct scope is legally confirmed, prepare the operating response
If qualified legal counsel has confirmed that the entity is important or essential, use the applicable law, authority instructions and confirmed deadlines to plan the operating work. The five areas below are a practical starting list, not a regulator-endorsed priority order.
Assign responsibility for the NIS2 work. Name the person with authority to coordinate the work, surface decisions and keep management informed. Do not assign it to the DPO or CTO by default. The right person depends on the organisation's actual mandates. Record who prepares the work, who approves the measures and who handles each authority contact.
Inventory your cybersecurity risk-management measures against Article 21's 10 headings. Those headings are: risk analysis and information system security policies; incident handling; business continuity and crisis management; supply chain security; security in acquisition, development, and maintenance; policies to assess effectiveness; basic cyber hygiene and training; cryptography; human resources, access control, asset management; and multi-factor authentication and secured communications. Map what you already have against each heading. Gaps become your roadmap.
Implement incident detection and a reporting process. Under the Danish law, a significant incident is reported to both the relevant competent authority and the CSIRT. The early warning is due within 24 hours of awareness and the incident notification within 72 hours. An intermediate report is required if the CSIRT asks for one. The final report is due no later than one month after the incident notification. If the incident is still ongoing, provide a progress report then and the final report within one month after it has been handled. You need detection, classification, a decision path and a documented reporting flow. Write it down, run a tabletop exercise against it, and keep the artefact.
Document supplier and vendor cybersecurity assessments. Pull together the list of your critical third parties (cloud, identity, payments, key SaaS). Document the assurance, contract clauses and incident-notification terms relevant to each relationship. Use the confirmed legal duties and authority guidance to determine what the assessment must cover.
Book the management-body cybersecurity training. Article 20 requires members of the management body to follow relevant training. The people approving the measures need enough knowledge to identify risks and assess the company's cybersecurity practices. Record the content, attendance, and date so the company can show that the requirement was met.
Step 5: If counsel confirms the entity is outside direct scope but customers require evidence
You're below the threshold or outside the listed sectors, but enterprise customers are sending NIS2-style questionnaires. Three actions can organise that customer-diligence work without misrepresenting your legal status.
Prepare a controlled response pack for recurring customer questions. Document the controls and evidence you can actually support, version the pack, and review customer-specific commitments before accepting them. This reduces repeated drafting without turning a standard response into a blanket compliance claim.
Map your existing ISO 27001 or SOC 2 work to the NIS2 Article 21 headings. An existing ISMS may cover much of the underlying control work, but the mapping and customer-specific commitments still need to be checked. Build a crosswalk and use it as evidence without claiming that certification alone proves NIS2 compliance.
Watch the upgrade path. Re-run Step 2 if you reach 50 people employed or if both turnover and the balance sheet exceed EUR 10M. Put a reminder at the start of each financial year to check again.
What this guide does not settle
This guide prepares a fact and source record. It does not determine legal scope. It covers common routes that qualified counsel may need to test, and edge cases matter:
- A national designation can bring an entity into scope regardless of the ordinary size route
- Cross-border operations complicate which Member State's competent authority has jurisdiction
- Government contracting may bring sector-specific requirements that layer on top of NIS2
- Sector-specific overlays (DORA for financial services, CER for physical resilience) can interact in non-obvious ways
- Group structures with parent entities in or out of the EU create entity-level scoping questions
If the initial answer is borderline, or your company has any of these complicating factors, do not guess. Document the open point and have a qualified legal adviser confirm the classification before you rely on it.
Where to go from here
Read the full NIS2 article on the site. It explains how NIS2 fits with DORA, what Denmark's NIS 2-loven requires, and how the supervisory model works in practice.
See the services page. A Market-access assessment can connect the requirement, your current evidence, the material gaps and the person who can approve the response. It does not replace a legal opinion on whether your company is directly in scope.
Get in touch. If the answer is still unclear, describe the requirement, the current scope position and the decision you need to make. I will tell you whether Accel Comply is relevant and which questions need a qualified legal adviser.