Under NIS2, an organisation's sector, size and role can determine whether cybersecurity risk-management and reporting duties apply

Whether NIS2 applies to an organisation turns on what sector it is in, how big it is, and what role it plays.

It is not a general obligation and it is broader than its predecessor. The practical difficulty is that many organisations do not know whether they are in scope, and being a supplier to somebody who is can bring obligations indirectly. Note also that it does not apply in the UK, where the NCSC's Cyber Assessment Framework and separate legislation govern instead.

Checked against the primary source.

More on Regulation and law