Back to News
    NIS2RegCheck

    The NIS2 size test — three readings of the same line.

    Recommendation 2003/361/EC, MCF guidance MCF0027 and Livsmedelsverket guidance ref. 2026/00688 state the NIS2 size threshold in three different ways — and/or on the financial limb, two consecutive years, or an average of two years. The quotes, the differences and what they mean in practice.

    Who falls under NIS2 is largely a question of size. The directive relies on the EU definition of small and medium-sized enterprises — Recommendation 2003/361/EC — and that definition is shorter than most people expect. It is also being read in three different ways in Sweden right now.

    What the Recommendation says.

    A small enterprise has fewer than 50 employees and an annual turnover and/or balance sheet total not exceeding EUR 10 million (Annex Article 2(2) in the English version; the Swedish version reads or). An enterprise that no longer meets that is medium-sized — and medium-sized enterprises in NIS2 sectors are in scope.

    Annex Article 4(2) adds a time rule: an enterprise changes category only when it exceeds or falls below the thresholds over two consecutive accounting periods. One strong year is not enough.

    What the Swedish Agency for Civil Defence says.

    MCF's guidance on registration and identification of entities under the Cybersecurity Act (MCF0027, February 2026) states the test as follows (our translation):

    A medium-sized enterprise shall therefore employ at least 50 persons or have an annual turnover or balance sheet total exceeding EUR 10 million per year.

    The guidance applies the two-year rule with an express reference to Annex Article 4 and gives worked examples: 49 employees and EUR 11 million in turnover is medium-sized; 50 employees and EUR 9 million in turnover is medium-sized.

    What the Swedish Food Agency says.

    Livsmedelsverket's guidance on entities under the Cybersecurity Act (ref. 2026/00688) states (our translation):

    an entity with a balance sheet total or turnover of at least EUR 10 million is covered. An entity may also be covered if turnover or balance sheet total is below EUR 10 million but more than 50 annual employees are engaged in the business.

    The assessment, the guidance says, "shall be based on the company's most recently approved annual accounts and cover the average of the two most recent financial years". The guidance also restates the Recommendation two-year rule: the category changes only when the thresholds are exceeded or fallen below over two consecutive financial years.

    Where they differ.

    Two points. First, the financial limb: Regweaver reads the Recommendation so that an enterprise stays small as long as one of the two financial ceilings is not exceeded (the English version and/or; the Swedish version reads or). Both agencies word it so that one exceeded ceiling suffices to become medium-sized. That is a wider reading — more companies are in scope under it. Second, time: the Recommendation and MCF count two consecutive years. Livsmedelsverket restates the same two-year rule but adds that the assessment shall cover the average of the two most recent financial years. For a fast-growing company, the two methods can give different answers in the same year.

    The difference is not academic. A company with 42 employees, EUR 11 million in turnover and EUR 8 million in balance sheet total is small under the Recommendation's wording — and medium-sized under MCF's formulation.

    What to do.

    Calculate on two financial years, not one. Test both financial limbs separately. And if the outcome differs between the Recommendation's wording and your supervisory authority's guidance: ask the authority, not the adviser. The registration duty under the Swedish Cybersecurity Act (2025:1506) has applied since 15 January 2026, when the act entered into force, and it is the supervisory authority that settles the interpretation in the individual case.

    Regweaver's assessments apply the Recommendation's wording, run the two-year rule explicitly, and flag when the authorities' reading may give a different outcome — so the difference is shown rather than hidden in a yes or no.

    Want to know where you stand? The NIS2 quick check now asks for both this year's and last year's figures and shows whether the two-year rule is met, on the edge, or not applicable. And because the guidance is new and will be revised: want to monitor NIS2? RegWatch tells you when the directive, the Swedish act or the authorities' guidance changes — every change reviewed by a person before it reaches you.

    Take the NIS2 quick check

    Sources.

    Recommendation 2003/361/EC, Annex Article 2(2) and Annex Article 4(2) — eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32003H0361

    MCF, Vägledning för anmälan och identifiering av verksamhetsutövare som omfattas av cybersäkerhetslagen, MCF0027, February 2026 — www.ncsc.se/siteassets/radgivning-och-stod/ovriga-publikationer/vagledning-for-anmalan-och-identifiering-av-verksamhetsutovare-som-omfattas-av-cybersakerhetslagen.pdf

    Livsmedelsverket, Vägledning om verksamhetsutövare enligt cybersäkerhetslagen, ref. 2026/00688, 2026 — www.livsmedelsverket.se/om-oss/publikationer/vagledningar/vagledning-om-verksamhetsutovare-enligt-cybersakerhetslagen/

    Key takeaway

    Calculate on two financial years, test both financial limbs separately — and ask the supervisory authority when the wording and the guidance point in different directions.

    Take the NIS2 quick check

    Read more

    Monitor NIS2

    We watch for changes and send a reviewed notice when something actually changes.

    See the monitoring option

    This article is for informational purposes only and does not constitute legal advice.

    Related reading