Which rules reach you?
NIS2, DORA, the GDPR and the UK's Network and Information Systems Regulations 2018 each define their own scope, in their own words, and the answers differ. This reads them against the figures you give us and shows you the text each answer rests on.
No account, no email address, nothing written down. The answer is not saved and neither are the figures.
The text every answer above rests on
Verbatim, with the Official Journal reference each was read from. Check the answer against the provision rather than against the summary.
This reads the statutory scope tests against the facts you give us. It is not legal advice and it is not a determination: for NIS2 in particular, whether an entity is in scope is settled by the Member State that lists it, and several limbs of the test turn on judgements only a national authority makes.
What this cannot tell you
This page cannot tell you that you are "not in scope"
Only one negative rests on the text alone: an express exclusion. Everything else this page can say is that the test it ran did not reach you — and several limbs of NIS2 Art. 2 reach an entity on a judgement no form can make. Those are listed under every answer, positive ones included.
Your Member State has the last word on NIS2
Art. 3(3) has Member States establish the list of essential and important entities. Being in scope is settled by that list, not by this test and not by us.
The size ceilings this page applies are250 annual work units, EUR 50 million turnover and EUR 43 million balance sheet total, from the Annex to Recommendation 2003/361/EC. Seewhat we do once you are in scope.