Articles
Article 2Scope
Article 3(4) of the Annex to that Recommendation shall not apply for the purposes of this Directive.
- (a)services are provided by:
- (i)providers of public electronic communications networks or of publicly available electronic communications services;
- (ii)trust service providers;
- (iii)top-level domain name registries and domain name system service providers;
- (i)
- (b)the entity is the sole provider in a Member State of a service which is essential for the maintenance of critical societal or economic activities;
- (c)disruption of the service provided by the entity could have a significant impact on public safety, public security or public health;
- (d)disruption of the service provided by the entity could induce a significant systemic risk, in particular for sectors where such disruption could have a cross-border impact;
- (e)the entity is critical because of its specific importance at national or regional level for the particular sector or type of service, or for other interdependent sectors in the Member State;
- (f)the entity is a public administration entity:
- (i)of central government as defined by a Member State in accordance with national law; or
- (ii)at regional level as defined by a Member State in accordance with national law that, following a risk-based assessment, provides services the disruption of which could have a significant impact on critical societal or economic activities.
- (i)
- (a)public administration entities at local level;
- (b)education institutions, in particular where they carry out critical research activities.
The processing of personal data pursuant to this Directive by providers of public electronic communications networks or providers of publicly available electronic communications services shall be carried out in accordance with Union data protection law and Union privacy law, in particular Directive 2002/58/EC.
Footnotes
- (27) Directive 2011/93/EU of the European Parliament and of the Council of 13 December 2011 on combating the sexual abuse and sexual exploitation of children and child pornography, and replacing Council Framework Decision 2004/68/JHA (OJ L 335, 17.12.2011, p. 1).
- (28) Directive 2013/40/EU of the European Parliament and of the Council of 12 August 2013 on attacks against information systems and replacing Council Framework Decision 2005/222/JHA (OJ L 218, 14.8.2013, p. 8).
https://nis2.digiphile.law/article/article-2.html
Text as at 19 September 2026.
This is an unofficial convenience version of the EU NIS2 Directive (Directive (EU) 2022/2555). It is presented “as is” without guarantee of accuracy, completeness or reliability. See the source text for the official version. This site was last updated in September 2026.