Who falls under NIS2 is largely a question of size. The directive relies on the EU definition of small and medium-sized enterprises — Recommendation 2003/361/EC — and that definition is shorter than most people expect. It is also being read in three different ways in Sweden right now.
What the Recommendation says.
A small enterprise has fewer than 50 employees and an annual turnover and/or balance sheet total not exceeding EUR 10 million (Annex Article 2(2) in the English version; the Swedish version reads or). An enterprise that no longer meets that is medium-sized — and medium-sized enterprises in NIS2 sectors are in scope.
Annex Article 4(2) adds a time rule: an enterprise changes category only when it exceeds or falls below the thresholds over two consecutive accounting periods. One strong year is not enough.
What the Swedish Agency for Civil Defence says.
MCF's guidance on registration and identification of entities under the Cybersecurity Act (MCF0027, February 2026) states the test as follows (our translation):
A medium-sized enterprise shall therefore employ at least 50 persons or have an annual turnover or balance sheet total exceeding EUR 10 million per year.
The guidance applies the two-year rule with an express reference to Annex Article 4 and gives worked examples: 49 employees and EUR 11 million in turnover is medium-sized; 50 employees and EUR 9 million in turnover is medium-sized.
What the Swedish Food Agency says.
Livsmedelsverket's guidance on entities under the Cybersecurity Act (ref. 2026/00688) states (our translation):
an entity with a balance sheet total or turnover of at least EUR 10 million is covered. An entity may also be covered if turnover or balance sheet total is below EUR 10 million but more than 50 annual employees are engaged in the business.
The assessment, the guidance says, "shall be based on the company's most recently approved annual accounts and cover the average of the two most recent financial years". The guidance also restates the Recommendation two-year rule: the category changes only when the thresholds are exceeded or fallen below over two consecutive financial years.
Where they differ.
Two points. First, the financial limb: Regweaver reads the Recommendation so that an enterprise stays small as long as one of the two financial ceilings is not exceeded (the English version and/or; the Swedish version reads or). Both agencies word it so that one exceeded ceiling suffices to become medium-sized. That is a wider reading — more companies are in scope under it. Second, time: the Recommendation and MCF count two consecutive years. Livsmedelsverket restates the same two-year rule but adds that the assessment shall cover the average of the two most recent financial years. For a fast-growing company, the two methods can give different answers in the same year.
The difference is not academic. A company with 42 employees, EUR 11 million in turnover and EUR 8 million in balance sheet total is small under the Recommendation's wording — and medium-sized under MCF's formulation.
What to do.
Calculate on two financial years, not one. Test both financial limbs separately. And if the outcome differs between the Recommendation's wording and your supervisory authority's guidance: ask the authority, not the adviser. The registration duty under the Swedish Cybersecurity Act (2025:1506) has applied since 15 January 2026, when the act entered into force, and it is the supervisory authority that settles the interpretation in the individual case.
Regweaver's assessments apply the Recommendation's wording, run the two-year rule explicitly, and flag when the authorities' reading may give a different outcome — so the difference is shown rather than hidden in a yes or no.
Want to know where you stand? The NIS2 quick check now asks for both this year's and last year's figures and shows whether the two-year rule is met, on the edge, or not applicable. And because the guidance is new and will be revised: want to monitor NIS2? RegWatch tells you when the directive, the Swedish act or the authorities' guidance changes — every change reviewed by a person before it reaches you.
Sources.
Recommendation 2003/361/EC, Annex Article 2(2) and Annex Article 4(2) — eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32003H0361
MCF, Vägledning för anmälan och identifiering av verksamhetsutövare som omfattas av cybersäkerhetslagen, MCF0027, February 2026 — www.ncsc.se/siteassets/radgivning-och-stod/ovriga-publikationer/vagledning-for-anmalan-och-identifiering-av-verksamhetsutovare-som-omfattas-av-cybersakerhetslagen.pdf
Livsmedelsverket, Vägledning om verksamhetsutövare enligt cybersäkerhetslagen, ref. 2026/00688, 2026 — www.livsmedelsverket.se/om-oss/publikationer/vagledningar/vagledning-om-verksamhetsutovare-enligt-cybersakerhetslagen/
Key takeaway
Calculate on two financial years, test both financial limbs separately — and ask the supervisory authority when the wording and the guidance point in different directions.
Take the NIS2 quick check
Read moreMonitor NIS2
We watch for changes and send a reviewed notice when something actually changes.
See the monitoring optionThis article is for informational purposes only and does not constitute legal advice.
Related reading
- NIS2
NIS2 Value Chain Obligations: What Suppliers Actually Need to Provide
Essential and important entities are pushing security requirements downstream. Here is what evidence suppliers should be ready to provide.
Read article - AI Act
One act changed three regulations. Most teams saw one
The Digital Omnibus on AI quietly amended the Machinery Regulation and aviation rules. Why per-regulation monitoring misses cross-regulation change.
Read article - PPWR
PPWR applies from today. It will not arrive alone.
The Packaging and Packaging Waste Regulation becomes generally applicable on 12 August. Most companies will read that as a deadline passed. It is the opposite — and it is not even the main event. The main event is what it lands on top of.
Read article