Who may need to comply?
Use sector and entity categories as a starting point, then check size rules, exceptions, place of establishment and the relevant national implementing law.
Energy
Electricity, district heating and cooling, oil, gas and hydrogen activities appear in the Directive’s high criticality sector annex. Exact entity categories and national rules need checking.
02 / Annex IHealth
The health sector includes categories such as healthcare providers and certain research and pharmaceutical activities. Scope depends on the entity and applicable national law.
03 / Annex IDigital infrastructure
The Directive identifies a number of digital infrastructure services, including DNS, cloud and data centre categories. Some categories have specific implementing rules.
04 / Annex IIManufacturing
Selected manufacturing categories are included in the Directive’s other critical sectors annex. Product and entity classifications need a careful scope review.
05 / Annex ITransport
Air, rail, water and road transport categories appear in the high criticality sector annex. The role an organisation performs matters for scope.
06 / Annex IBanking
Credit institutions appear in the banking category. Sector-specific EU acts, including DORA, can affect the applicable cybersecurity framework.
A practical scope review
- List each legal entity and its services.
- Map services to the Directive’s annex categories.
- Review size rules and entity-specific exceptions.
- Check establishment, jurisdiction and the implementing national law.
- Record the basis and obtain specialist advice where classification is uncertain.
Official sources and context
Use these alongside the applicable national legislation and authority guidance. This page is general information and may not reflect every national measure or later amendment.