Skip to main content
Back to overview

NIS2 for Public Administration: Why Your Government Client's Scope Depends on Their Postcode

By NIS2Certify
nis2public-administrationgovernmentcompliance-scopemsp
NIS2 for Public Administration: Why Your Government Client's Scope Depends on Their Postcode

A Dutch municipality with 180 staff and a German Landkreis with the same headcount can land on opposite sides of NIS2. Same sector, same citizen data, same suppliers - different obligations, because the Directive left regional and local government as a member state option.

That single design decision makes public administration the hardest sector in NIS2 to scope. Every other Annex I sector runs on the same size-cap logic across all 27 member states. This one does not.

It also matters more this year than last. ENISA's NIS360 2026 report placed public administration in the risk zone: one of eight sectors whose cybersecurity maturity sits below what their criticality demands, alongside health, rail, maritime, space, drinking water and wastewater. Supervisory authorities read that report, and it shapes where attention goes first. We covered that dynamic in how regulators decide which clients get audited first.

If you advise government bodies - or supply them - here is what actually determines the obligation.

Central government is in scope everywhere, and headcount is irrelevant

Annex I lists public administration entities of central government as a sector of high criticality. Unlike a logistics operator or a food producer, these entities do not get to argue their way out on size.

The size-cap rule - 50 staff or EUR 10 million turnover for medium, 250 or EUR 50 million for large - is the general filter for NIS2 scope. Public administration entities of central government are pulled in irrespective of that filter. A ministry directorate with 30 people carries the same Article 21 obligations as an agency with 3,000.

Practical consequence: stop opening a government scoping conversation with headcount. Ask two questions instead. Which legal instrument established this body, and which level of government does it sit at? Those answers decide the outcome.

Note also the definition NIS2 uses. A public administration entity is a body established to meet needs in the general interest, without industrial or commercial character, with legal personality, and financed or supervised by the state. That captures a lot of arm's-length organisations that do not think of themselves as "government" - public registries, social insurance funds, national statistical offices, licensing bodies.

Regional and local government is a national choice, not an EU rule

The Directive reaches public administration entities at NUTS level 1 and 2 - broadly, national and major regional administrations. Below that, Article 2 gives member states the option to extend scope to local authorities. Many did. Several did not.

The result is a scope map that matches no other NIS2 sector. A city IT department in one member state is a regulated essential entity with registration duties, incident reporting deadlines and management liability. The equivalent city across the border is out of scope entirely and buys security on a purely voluntary basis.

This is also why national transposition status matters more here than anywhere else. With 22 of 27 member states transposed as of mid-2026, and the Commission having referred Ireland, Spain, France and the Netherlands to the CJEU, the local-government question is still legally open in some markets. Our country-by-country implementation tracker has the current position.

NIS2 Implementation Status by Country (2025–2026)

Fully in force

Belgium
Croatia
Hungary
Lithuania
Latvia
Italy
6 countries

Adopted — late 2025

Germany
Czech Republic
Finland
3 countries

In progress — expected 2026

Netherlands
France
Spain
Poland
Austria
Sweden
Ireland
7 countries

Never assume a group-wide answer for a client operating across borders. A shared-services organisation serving municipalities in three member states can be regulated in one and not the others, with a single IT estate underneath.

Four exclusions that consultants routinely misread

NIS2 does not apply to everything with a government letterhead. Four carve-outs matter, and all four are narrower than people assume.

National security, public security, defence and law enforcement. The exclusion attaches to the activity, not the organisation. A ministry of the interior is not wholesale exempt because part of it handles policing. The parts carrying out other functions can still be in scope.

The judiciary. Courts are excluded. Court administration services constituted as separate legal entities are not automatically excluded with them.

Parliaments. Legislatures are excluded. Parliamentary IT service organisations that are separate bodies may not be.

Central banks. Excluded under NIS2 - but many of the same institutions are captured by DORA instead. If you have argued a client out of NIS2 on this basis, check what replaced it in NIS2 vs DORA.

Two points worth stating plainly. First, an exclusion is not a step you can skip documenting: if the entity is later asked why it is not registered, someone has to show the reasoning. Second, member states may apply NIS2 requirements to excluded entities anyway, and several have done exactly that for parts of the public sector.


In-scope public bodies are essential entities, which changes the supervision model

When a public administration entity is in scope, it is treated as an essential entity. That is not a labelling detail. It determines how the regulator behaves.

Essential entities face ex ante supervision. The authority does not need an incident or a complaint to act - it can run inspections, demand evidence and order security audits at the entity's expense as a matter of routine. Important entities face ex post supervision, meaning the regulator generally moves once something has gone wrong.

For a government client, the audit is therefore a scheduled event, not a contingency. The evidence has to exist continuously, not be assembled after a phone call. We set out what supervisors actually ask for in the NIS2 supervisory audit evidence checklist.

The management liability provisions apply here too. Directors, secretaries-general and municipal executives must approve the risk management measures and oversee their implementation, and can be held personally accountable. In several transpositions the accountable person is named in law rather than left to internal delegation.

The sector data says public administration is the least prepared high-criticality sector

ENISA's NIS360 2026 assessment is the most useful external benchmark you have when a public sector client pushes back on urgency.

Public administration sits in the risk zone: high criticality, maturity that has not caught up. ENISA's framing is specifically about sectors new to regulation and whether they can build capacity faster than their criticality rises. Public administration is the clearest case of that gap.

The reasons are familiar to anyone who has worked a government account. Procurement cycles measured in quarters. Legacy estates nobody owns end to end. Security budgets competing directly with statutory service delivery. Responsibility fragmented between a central IT department and dozens of semi-autonomous departments running their own applications.

None of that is an excuse a supervisor accepts. It is, however, a strong argument for starting the gap analysis now rather than after the first inspection letter. Our step-by-step gap analysis guide works the same way for a municipality as for a manufacturer.

Supplying government makes you part of a regulated supply chain

Here is the part most IT consultants and MSPs miss. You do not need to be in scope yourself for NIS2 to reach you. You need your client to be.

Article 21(2)(d) requires in-scope entities to manage the security of their direct suppliers and service providers, taking into account each supplier's specific vulnerabilities and overall security practices. When a ministry or a regional authority applies that to its supplier base, the obligation lands on you contractually - in tender requirements, in framework agreements, in security annexes that outlive the contract.

Public sector procurement makes this sharper than the private market. Requirements get written into standardised tender documents and reused across hundreds of contracts. Once a national procurement body adds NIS2 supplier clauses to its template, every bidder inherits them at once.

NIS2 Penalty Escalation — Beyond the Fine

!

Trigger event

Non-Compliance Detected or Incident Occurs

A supervisory authority identifies a compliance gap or an organisation fails to meet NIS2 requirements

Authorities can impose
Non-Monetary Penalties
1

Compliance orders with binding deadlines

2

Mandatory security audits at your expense

3

Public disclosure of violations

4

Binding instructions on specific security measures

Escalates to
Operational & Personal Consequences
1

Suspension of certifications or operating licences

2

Temporary ban on management functions for individuals

3

Public naming of responsible natural persons

Trigger
Non-monetary
Operational / personal

If you already hold public sector contracts, read the supplier contract obligations under Article 21 before your next renewal. Those clauses are going in whether or not you negotiate them.

What a readiness assessment for a public body should establish first

Before any control work, settle four questions in writing:

  1. Level and legal basis. Central, regional (NUTS 1 or 2), or local - and which instrument established the entity. This decides scope, not headcount.
  2. National extension. Has the member state extended NIS2 to local authorities, and under what conditions? This is national law, not the Directive.
  3. Exclusion analysis. Which activities, if any, fall under the national security, judiciary, parliament or central bank carve-outs - and which parts of the entity remain in scope regardless.
  4. Competent authority. Which regulator supervises this entity, and does it publish sector-specific guidance? Public administration is often supervised by a different authority than commercial sectors in the same country. See which regulator actually supervises your client.

Only then does gap work against Article 21 make sense. Scoping errors in this sector are expensive in both directions: you either build a compliance programme for an entity that never needed one, or you leave an essential entity unregistered and unprepared for ex ante inspection.

If you want a fast, structured starting point for a government client - or for your own position as a supplier to one - run the NIS2 quick scan. It takes minutes and gives you a defensible readiness baseline to build the assessment on.

The short version

Central government is in scope in every member state, regardless of size. Regional administrations at NUTS 1 and 2 are in scope. Local government depends entirely on national law. The exclusions are activity-based and narrower than they look. In-scope public bodies are essential entities, which means ex ante supervision and named management accountability.

And if you sell to any of them, their obligations become your contract terms.

Still have a question?

Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.

    NIS2 for Public Administration: Scope, Exclusions and Supplier Impact