Skip to content

Scope and applicability

This page focuses on how NIS2 applicability is established and maintained in Modulos at organization level.

OFF-15 requirements for scope and applicability

RequirementTopicDirective reference
ORF-284NIS2 scope and entity classificationArt. 2, 3
ORF-285Sector-specific legal act equivalence assessmentArt. 4
ORF-294Registry submission and update obligationsArt. 27(1)-(4)
ORF-295Jurisdiction and EU representative managementArt. 26
ORF-296Entity listing data submission and two-week update dutyArt. 3(4)
ORF-302Implementing-act applicability and criteria governanceArt. 21(5), 23(11)

What to evidence in practice

For defensible scope decisions, organizations typically maintain:

  • sector and service qualification rationale
  • size-threshold and classification record (essential vs important)
  • legal analysis for Art. 4 equivalence scenarios
  • registry/listing submission records and update log
  • implementing-act applicability matrix (including affected entity classes)

AI-system implications

Scope is organization-driven, but scope decisions influence which AI-system controls are activated and reviewed in MFF-15 projects.

When scope or classification changes, propagate that change into system-level projects and revalidate mapped controls.

Disclaimer

This page is for general informational purposes and does not constitute legal advice.