INDEPENDENT NIS2 RESOURCEGovernance · Resilience · ImplementationEU framework / national application
HomeSectorsHealth
Annex I / Sector guidance

Health and NIS2

The health sector includes categories such as healthcare providers and certain research and pharmaceutical activities. Scope depends on the entity and applicable national law.

Applicability starts with the service

Compare the precise entity and service category in Annex I with the organisation’s actual activity. Review size-related rules, exceptions and the law of the relevant Member State before concluding that an entity is in or out of scope.

Implementation considerations

  • Identify patient-facing critical systems
  • Assess supplier and clinical system continuity
  • Coordinate incident escalation roles

Obligations to review

For in-scope entities, examine cybersecurity risk-management measures, management oversight and the reporting of significant incidents, including the national rules and any sector-specific EU measures.

A sector listing is not a determination of legal status or an exhaustive description of covered entities.

Official sources and context

Use these alongside the applicable national legislation and authority guidance. This page is general information and may not reflect every national measure or later amendment.