NIS2 covers a healthcare provider if it is at least a medium-sized enterprise. Annex I of Directive (EU) 2022/2555, sector 5, lists healthcare providers as defined in Article 3(g) of Directive 2011/24/EU: any natural or legal person or any other entity legally providing healthcare on the territory of a Member State. Healthcare there includes the prescription, dispensation and provision of medicinal products and medical devices, so the entry reaches hospitals and clinics and can reach pharmacies too. Because health is an Annex I sector, a large provider is an essential entity and a medium-sized one is an important entity. Ownership does not change the size test: NIS2 switches off the rule that would otherwise treat any organisation 25% or more controlled by public bodies as large.
Both tiers owe the same Article 21 cybersecurity risk management measures, the same Article 23 reporting clocks and the same Article 20 management body duties. The tier changes supervision and the fine ceiling. The directive had to be transposed by 17 October 2024 and applied from 18 October 2024, so the obligations reach you through your national law. The general scope rules are in our guide to what NIS2 is and who must comply.
| Who | Where NIS2 lists it | Tier if large | Tier if medium |
|---|---|---|---|
| Healthcare providers, including hospitals, clinics and dispensing pharmacies | Annex I, sector 5 | Essential | Important |
| EU reference laboratories under Regulation (EU) 2022/2371 | Annex I, sector 5 | Essential | Important |
| Research and development of medicinal products | Annex I, sector 5 | Essential | Important |
| Manufacture of basic pharmaceutical products and preparations (C21) | Annex I, sector 5 | Essential | Important |
| Manufacture of devices on the public health emergency critical devices list | Annex I, sector 5 | Essential | Important |
| Manufacture of other medical devices and in vitro diagnostics | Annex II, sector 5 | Important | Important |
Which healthcare providers are in scope of NIS2?
Start with the definition. NIS2 does not define healthcare provider itself; it borrows Article 3(g) of the Cross-Border Healthcare Directive, which turns on whether you legally provide healthcare. Article 3(a) of that directive defines healthcare as health services provided by health professionals to patients to assess, maintain or restore their state of health, including the prescription, dispensation and provision of medicinal products and medical devices. Article 3(f) counts pharmacists among the health professionals. A hospital, a clinic chain, a diagnostic imaging group and a pharmacy chain can all meet the definition. Whether they are in scope then depends on size.
The other Annex I health entries are narrower: EU reference laboratories referred to in Article 15 of Regulation (EU) 2022/2371, entities carrying out research and development of medicinal products as defined in Article 1(2) of Directive 2001/83/EC, manufacturers of basic pharmaceutical products and preparations in NACE division 21, and manufacturers of devices on the public health emergency critical devices list under Article 22 of Regulation (EU) 2022/123. Every other medical device and in vitro diagnostic manufacturer sits in Annex II, as our guide to NIS2 for manufacturers explains.
Small providers are generally outside. Article 2(2) applies the directive regardless of size in listed cases, including where the entity is the sole provider in a Member State of a service essential for critical societal or economic activities, or where disruption of its service could have a significant impact on public safety, public security or public health. Those cases work through national identification, so whether a small provider is caught is decided by your Member State.
Is a public hospital automatically large?
No, and this is the point most often missed. Article 2(1) measures size by Article 2 of the Annex to Commission Recommendation 2003/361/EC. That Recommendation treats any entity engaged in an economic activity as an enterprise, irrespective of its legal form. A small enterprise employs fewer than 50 persons and has an annual turnover and/or balance sheet total not above EUR 10 million; the SME category ends at fewer than 250 persons with turnover not above EUR 50 million and/or a balance sheet not above EUR 43 million. In practice you are at least medium-sized with 50 or more staff, or with both turnover and balance sheet above EUR 10 million, and large once you pass 250 staff or both financial ceilings.
Article 3(4) of the same Annex says an enterprise cannot be considered an SME if 25% or more of its capital or voting rights are controlled by one or more public bodies. Read alone, that would make almost every public hospital large and therefore essential. The second subparagraph of NIS2 Article 2(1) says Article 3(4) of the Annex does not apply for the purposes of the directive. A public hospital is sized on its staff and its financial figures, like a private one. For private hospital groups, the Recommendation's partner and linked enterprise rules still count group data, and recital 16 lets Member States take into account how independent the entity's network and information systems are from the rest of the group.
Essential or important, and why it matters
Article 3(1)(a) makes Annex I entities that exceed the medium-sized ceilings essential; Article 3(2) makes every other in-scope entity important. A large hospital is essential; a medium-sized clinic or pharmacy chain is important, unless the Member State identifies it as essential under Article 3(1)(e).
Recital 122 describes the difference in supervision: essential entities are subject to a comprehensive ex ante and ex post regime, important entities to a light, ex post only one, and Article 33 has authorities act on important entities when provided with evidence, indication or information of non-compliance. For infringing Article 21 or 23, Article 34(4) sets a fine maximum of at least EUR 10 million or 2% of total worldwide annual turnover for essential entities, whichever is higher, and Article 34(5) at least EUR 7 million or 1.4% for important ones. These are floors for the national maximum. Article 34(7) lets each Member State decide whether and to what extent fines can be imposed on public administration entities; whether a public hospital is one is a question of national law. Our guide to NIS2 fines and penalties has the detail.
What do the Article 21 measures mean in a hospital?
Article 21(2) sets ten measures on an all-hazards basis. In a hospital they read like this. Risk analysis and asset management have to cover clinical systems and networked medical devices, not only the office estate. Incident handling and business continuity have to include downtime procedures that keep patient care going while systems are down, and backups you have actually restored. Supply chain security under 21(2)(d) and 21(3) takes in the electronic health record vendor, laboratory and imaging system suppliers, and device manufacturers with remote maintenance access. Security in acquisition, development and maintenance includes vulnerability handling for the equipment you buy. Access control, cryptography, cyber hygiene and training, and multi-factor authentication close the list. Each measure is taken point by point in our guide to NIS2 Article 21 requirements.
Article 20(1) requires the management body to approve the measures, oversee their implementation and be capable of being held liable for infringements, and Article 20(2) requires its members to follow training. In a hospital that is the board or executive team, not the IT department.

What must a hospital report, and to whom?
Article 23 applies to significant incidents: those that have caused or are capable of causing severe operational disruption of the services or financial loss for the entity, or that have affected or are capable of affecting other persons by causing considerable material or non-material damage. A ransomware attack that forces a hospital onto paper will usually qualify. The entity submits an early warning within 24 hours of becoming aware, an incident notification within 72 hours of becoming aware, an intermediate report on request, and a final report no later than one month after the incident notification.
How does NIS2 interact with GDPR for patient data?
Most hospital incidents touch personal data, so two regimes run at once. Under GDPR Article 33, a personal data breach goes to the data protection authority without undue delay and, where feasible, within 72 hours. NIS2 Article 35(1) requires the NIS2 authority, where an infringement of Article 21 or 23 can entail a personal data breach, to inform the data protection authority without undue delay. Article 35(2) stops a double fine for the same conduct: where the data protection authority imposes a GDPR fine, the NIS2 authority may not impose a fine under Article 34 for an infringement arising from that conduct, although it can still use its other enforcement measures. The clocks are set side by side in our comparison of incident reporting deadlines by regulation, and diagnostic AI adds a third regime, covered in our guide to the EU AI Act for healthcare.

What the other results get wrong
The page one results are good on ransomware and legacy devices, and three points are easy to get wrong. The first is the tier. Several guides say healthcare is an essential sector, or that hospitals are essential entities, and quote only the EUR 10 million or 2% ceiling. A medium-sized provider is an important entity under Article 3(2), with ex post supervision and the Article 34(5) ceiling of at least EUR 7 million or 1.4%.
The second is medical devices. Several guides put every medical device and in vitro diagnostic manufacturer in the Annex I health sector. Annex I lists only manufacturers of devices on the public health emergency critical devices list; the rest are in Annex II, sector 5(a), and are important entities at any size unless designated otherwise. One guide also lists medical insurance providers in the health sector. They are not in Annex I.
The third is the size test. One guide sorts providers by headcount alone, 50 to 249 employees as medium and 250 or more as large, ignoring the financial figures. The public-body rule matters too: because Article 2(1) disapplies it, a public hospital with 50 to 249 staff and a turnover or balance sheet within the medium ceilings is an important entity, not an essential one.
Where does your organisation stand?
Fill this in per legal entity. A blank cell is the next piece of work.
| Question | Your answer | Why it matters |
|---|---|---|
| Does each entity legally provide healthcare, including dispensing? | Annex I and Directive 2011/24/EU, Art. 3(a) and (g). | |
| What are its headcount, turnover and balance sheet, ignoring public ownership? | Art. 2(1) and Recommendation 2003/361. | |
| Has the Member State identified it as essential, or caught a small entity under Art. 2(2)? | Art. 2(2) and Art. 3(1)(e). | |
| Have you registered with the national authority, and who updates the details? | Art. 3(4): changes within two weeks. | |
| Are networked medical devices and clinical systems in the asset inventory? | Art. 21(2)(i). | |
| Which suppliers have remote access to clinical systems or devices? | Art. 21(2)(d) and 21(3). | |
| Who sends the early warning within 24 hours, and who tells the data protection officer? | Art. 23(4)(a) and GDPR Art. 33. | |
| When did the board approve the measures and last train? | Art. 20(1) and (2). |
If most of the column is empty, start with scope and then the asset inventory. Our guide to what to expect from an NIS2 audit covers the supervisory side, the free compliance check gives you a baseline, and the NIS2 framework page shows how the Article 21 measures, registration and the 24 hour clock are tracked as controls with owners and evidence.
Frequently asked questions
Does NIS2 apply to hospitals?
Yes, if the hospital is at least medium-sized. Healthcare providers are listed in Annex I, sector 5. A large hospital is an essential entity and a medium-sized one an important entity.
Are public hospitals treated differently?
Not on size. NIS2 Article 2(1) disapplies the rule in Recommendation 2003/361 that would treat an organisation 25% or more controlled by public bodies as large. Whether fines can be imposed on public administration entities is left to each Member State by Article 34(7).
Does NIS2 apply to pharmacies?
It can. The healthcare provider definition in Directive 2011/24/EU includes the dispensation of medicinal products, so a pharmacy business that is at least medium-sized falls within Annex I.
Do small clinics have to comply?
Generally not, unless the Member State identifies them under Article 2(2), for example as the sole provider of an essential service or because disruption could have a significant impact on public health.
What are the reporting deadlines for a hospital?
Under Article 23(4), an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month of the notification. A personal data breach also goes to the data protection authority under GDPR Article 33.
Primary sources
Scope, tiers and duties are taken from Articles 2, 3, 20, 21, 23, 33 to 35 and 41, recitals 16 and 122 and Annexes I and II of Directive (EU) 2022/2555; the healthcare definitions from Article 3 of Directive 2011/24/EU; the size categories from Articles 1 to 3 of the Annex to Commission Recommendation 2003/361/EC; and the breach notification duty from Article 33 of Regulation (EU) 2016/679. NIS2 is a directive, so the obligations reach you through national transposing law, which can add registration details and set higher fines. Confirm the current text and your national law before relying on a specific provision.





