Applicability starts with the service
Compare the precise entity and service category in Annex I with the organisation’s actual activity. Review size-related rules, exceptions and the law of the relevant Member State before concluding that an entity is in or out of scope.
Implementation considerations
- Map services and operational technology dependencies
- Review incident coordination and business continuity
- Document critical suppliers and access paths
Obligations to review
For in-scope entities, examine cybersecurity risk-management measures, management oversight and the reporting of significant incidents, including the national rules and any sector-specific EU measures.
Official sources and context
Use these alongside the applicable national legislation and authority guidance. This page is general information and may not reflect every national measure or later amendment.