Practical guide ·

Does NIS2 apply to our company — and where should we start?

Start with the legal entity, its actual activity and its enterprise data. Then check the exceptions and national law. A customer asking about NIS2 creates a reason to investigate, but does not establish direct legal scope. The useful result is a documented decision and a list of unresolved facts.

What question are we answering?

A manager receives a security questionnaire and asks whether the company is now “under NIS2”. Three questions sit inside that sentence: whether the company has direct statutory duties, what the contract requires and whether existing safeguards are adequate. Answering only one leaves the others unattended.

Keep a separate conclusion for each legal entity. A group name, trading brand or customer’s status is not enough to determine the supplier’s position.

Which facts come first?

Describe the service operationally. “We work in technology” is too broad; hosting applications, selling licences and managing infrastructure can raise different questions. Match the actual activity to the relevant sector and entity type.

Collect headcount and financial information with the ownership context needed to apply enterprise-size rules. A headcount threshold is not the whole test. NIS2 and Bulgarian law also cover specific categories and circumstances regardless of the ordinary size rule.

Working file for an applicability review
EvidenceQuestionOwner
Service and licence descriptionWhich entity type and sector?Management / legal
Enterprise and ownership dataHow do size rules apply?Finance
Customer contractsWhich duties are contractual?Commercial / legal
National rules and authority correspondenceAre exceptions or national steps relevant?Compliance

What if we are small or only supply a regulated customer?

Small size is a fact to analyse, not an automatic exemption. Serving a bank does not automatically place a supplier under every DORA obligation either. The customer may need contractual commitments, evidence and incident assistance. Record these separately from direct legal duties.

Our DORA and NIS2 comparison explains the wider distinction. This first check assembles the information needed for a defensible company-specific conclusion.

What should the conclusion contain?

Use a dated note stating the entity, activities, information relied on, applicable provisions, conclusion and limitations. Name every missing fact and the person responsible for obtaining it. “Probably in scope” without a next step is difficult to use.

Revisit the note after an acquisition, a new service, material size changes or relevant legal changes. An initial scope review does not replace a full assessment of the measures the organisation must implement. If a customer deadline arrives first, answer the contractual request honestly while the legal assessment proceeds.

A small Bulgarian company in an international group

Local headcount is not enough to decide the size test. Collect the ownership and control relationships and the financial and employment data needed under the applicable enterprise rules. Partner and linked enterprises can affect the calculation. NIS2's sector and entity-type conditions must still be checked; group membership by itself does not place every subsidiary in scope.

Consider a fictional Bulgarian company with 18 employees and a controlling foreign parent. “Fewer than 50 employees here” is not a defensible conclusion. First identify the actual activity of the Bulgarian legal entity. Then establish which enterprise data must be combined, whether a category or exception applies regardless of size and which national provisions govern the case. Do not infer the parent's figures or the final status from the group website.

Shared systems create a second, operational question. Even where legal conclusions differ between entities, a shared identity platform or service provider can create common dependencies. Record who owns the controls and which entity can obtain evidence. This does not collapse separate legal responsibilities into one group label.

Use the group applicability evidence sheet to collect ownership, activity, entity data, shared-service dependencies and unresolved questions. The output should state the reviewed legal entity, basis, missing facts and review trigger. Customer requirements remain a separate conclusion, as explained in supplying a bank or regulated entity.

Explore in detail: NIS2 in Bulgaria: who is covered, by when, and what happens next.

How Dyasol can help

Dyasol can prepare an initial applicability note with the basis of the conclusion and the facts still needed. The starting scope is one legal entity; this is not a legal opinion or a full readiness assessment.

Review NIS2 applicability

Sources and context

Examples are illustrative. Practical recommendations should be adapted to the organisation.

General information as of 13 September 2026. Specific obligations depend on the entity, activity and applicable law.