The question “does NIS2 apply to my organisation?” cannot be answered by a sector list or headcount alone. In Portugal, the answer requires the organisation’s activity, size, importance of the service and a set of special rules to be assessed together.
The short answer: sector and size are only the start
As a starting rule, Decree-Law 125/2025 applies to private entities of the types listed in Annexes I and II that qualify as medium-sized enterprises or exceed the medium-sized thresholds and provide services or carry out activities in the European Union.
- Does the entity’s actual activity match a type listed in Annex I or II?
- Does its size, calculated under the applicable SME rules, place it in the medium-sized or large category?
- Is there a special rule that brings it into scope regardless of size?
An activity code can guide the assessment, but it does not replace analysis of the activity actually performed and the entity type defined by law.
— Practical scoping principle
The 17 sectors in the Portuguese framework
The framework divides covered private activities between sectors of high criticality in Annex I and other critical sectors in Annex II. Each sector contains specific entity types; simply belonging to an industry is not enough.
Annex I — sectors of high criticality
- Energy
- Transport
- Banking
- Financial market infrastructures
- Health
- Drinking water
- Waste water
- Digital infrastructure
- B2B ICT service management, including managed and managed security services
- Space
Annex II — other critical sectors
- Postal and courier services
- Waste management
- Manufacture, production and distribution of chemicals
- Production, processing and distribution of food
- Certain manufacturing activities
- Digital providers: online marketplaces, search engines and social networking platforms
- Research
Public administration and higher-education institutions are also covered through specific rules that are not limited to the list of 17 private sectors.
The size criterion: why a simple headcount fails
The general rule reaches medium-sized and large enterprises. Annex III treats as SMEs enterprises with fewer than 250 employees and annual turnover not exceeding €50 million or an annual balance-sheet total not exceeding €43 million; within that category, a small enterprise has fewer than 50 employees and turnover or balance-sheet total not exceeding €10 million.
- Employee count expressed as annual work units
- Annual turnover and balance-sheet total
- Relationships with partner or linked enterprises where relevant to the calculation
- The activity and type of service actually provided
A company with fewer than 50 employees should not automatically conclude that it is excluded. Group structure and financial data can change the classification, and the framework’s exceptions may make size irrelevant.
When size is no longer decisive
Article 3 provides for situations in which an entity may be covered regardless of its nature or size. Cases requiring particular attention include:
- Providers of public electronic communications networks or publicly available electronic communications services
- Trust service providers, top-level domain registries, domain name registration service providers and DNS service providers
- The sole provider of a service essential to critical societal or economic activities
- Entities whose disruption could significantly affect public security, public safety or public health
- Entities whose disruption could create significant systemic risks or cross-border impact
- Entities critical because of their national or regional importance and entities identified under the critical-entities resilience framework
The law also applies to higher-education institutions. Public entities are classified under specific rules as essential, important or relevant public entities in groups A and B.
Essential, important or relevant public entity?
Essential entities
They include, among the situations set out in Article 6, large entities of the types in Annex I, certain digital and communications providers, specified public entities and critical entities. Classification affects the supervision model and applicable level of scrutiny.
Important entities
Broadly, these are covered entities of the types in Annexes I and II that are not classified as essential. The word “important” does not mean optional: these entities remain subject to risk management, incident, governance and evidence obligations.
Relevant public entities
Public entities not classified as essential or important may fall into group A or B, principally according to their nature and size. Regulation 756/2026 specifies measures applying to those groups.
Five premature conclusions to avoid
- “We have fewer than 50 people, so we are out.” Size is not limited to payroll and some inclusions apply regardless of size.
- “Our activity code is not listed.” What matters is the match between the activity performed and the entity type described in the annexes.
- “We supply an in-scope entity, so the law automatically applies to us.” Supply-chain risk matters, but being a supplier does not by itself determine legal classification.
- “We are subject to DORA, so NIS2 is irrelevant.” Special regimes and coordination mechanisms must be assessed in the specific case.
- “We have not been notified, so we do not need to act.” The law provides for self-identification and update duties; lack of notification does not replace a scope assessment.
How to build a defensible scope assessment
A professional conclusion should be reviewable and explainable. The result is not simply “yes” or “no”: it should record the factual basis, assumptions, likely classification and points requiring confirmation.
- Inventory the group’s legal entities, establishments, services, activities and geographies.
- Map each activity to the entity types in Annexes I and II, documenting matches and exclusions.
- Calculate size using workforce, turnover, balance-sheet and relevant ownership relationship data.
- Test size-independent inclusions and special sectoral regimes.
- Record the conclusion, validation owner, evidence used and next review date.
Covered entities identify themselves through the CNCS electronic platform. For entities already operating, the law sets 60 days after the platform becomes available; for new entities, 30 days after starting activity. Self-identification creates a provisional record supporting the classification process.
Review scope whenever group structure, size, service portfolio, operating territory or applicable regulation changes.
— Recommended governance practice
Sources and limits of this analysis
This article was reviewed on 10 August 2026 against Decree-Law 125/2025, Regulation 756/2026, the CNCS classification matrix and Directive (EU) 2022/2555. Links to the official versions appear immediately below the article.
Informational content. It is not legal advice and does not replace validation of the specific situation by qualified professionals.
— Editorial note


