An Edge Built on Knowledge and Experience
NIS2 / BSIG § 30

Technical Scope of NIS2

Which IT systems, components and processes at your organisation fall under NIS2 and the BSIG — and how to define the scope precisely.

Technical & Legal Expertise Experience from Numerous NIS2 Projects Based in Sindelfingen
§ 30 BSIG

What Falls Under the Technical Scope?

The technical scope of NIS2 covers all systems, components and processes that your organisation uses to deliver its services and that process information technically. Four criteria must be met simultaneously.

The Four Criteria Under § 30 BSIG

  1. A system, a component or a process — hardware, software, logical modules or automated procedures
  2. Information is processed — the type of data is irrelevant: text data, transaction data, IoT telemetry, access credentials, etc.
  3. The processing is technical — digital, automated or semi-automated processing
  4. Used to deliver a service — a direct link to the services for which the organisation was classified under NIS2

IT Systems

A functional whole made up of technical and software-based parts

  • ERP system (inventory management, accounting)
  • Web application with server, database, UI
  • Email system including spam filter
  • Industrial / IoT systems

IT Components

Individual parts that form part of a larger system

  • Hardware: server, router, firewall, sensor
  • Software: operating system, database, application
  • Logical: authentication, encryption, API gateway
  • Communication: VPN, TLS, message queue

IT Processes

Workflows in which IT is used to handle data

  • Capture, validate, process data
  • Store, transmit, archive data
  • Collect logs → correlate → trigger an alert
  • Customer registration → email verification → account creation
Practical Question

What's In — What Stays Out?

The most common misconception in practice: organisations limit the scope to the IT department. NIS2, however, covers all systems used to deliver the regulated service — regardless of where they are operated.

Do cloud services and SaaS applications also fall within scope?
Yes. If a cloud or SaaS service is used to deliver your NIS2-regulated services, it falls within the technical scope. This has direct consequences for supply chain security: contracts with cloud providers must be reviewed for NIS2-compliant security clauses.
Do OT (Operational Technology) systems need to be taken into account?
Generally yes, if the OT environment is part of service delivery — for example in energy supply, healthcare or water supply. Industrial control systems (ICS), SCADA systems and their network connections then fall explicitly within scope.
What about systems that are only used indirectly (e.g. accounting software)?
This depends on the concrete link to service delivery. Accounting software that serves purely internal administrative purposes and has no bearing on the regulated services does not necessarily need to be included in the NIS2 scope. The boundary should be documented and justified.
Do systems operated by external service providers also count?
To the extent external service providers operate systems that directly support your service delivery, you as the affected entity are required to review the security of these systems as part of supply chain risk management and secure them contractually.
What is the best way to document the technical scope?
A proven approach is an asset inventory with classification: system/component/process → information type → link to service delivery → protection needs. This list also forms the basis for the risk analysis under § 30 BSIG and is a mandatory document for internal audits.
Recommended Approach

Defining Scope in Three Steps

A clearly defined scope boundary is the prerequisite for a robust gap analysis and efficient resource planning. Draw the scope too widely and you waste budget — draw it too narrowly and you risk compliance gaps.

1. Identify Services

Which of your organisation's services are NIS2-relevant? The starting point is classification as an important or especially important entity under the BSIG.

2. Map Systems & Processes

Record all IT systems, components and processes that contribute directly or indirectly to delivering these services — including cloud and external service providers.

3. Assess Protection Needs

For every element in scope: assess availability, integrity and confidentiality. The result feeds directly into the risk analysis under § 30 (1) BSIG.

Related Topics

Further NIS2 Topics

Scope Definition and Gap Analysis From a Single Source

We help you define the technical scope in a legally sound way and link it directly to the risk analysis.

Request Consultation Now
Tilsiter Str. 6 · D-71065 Sindelfingen, Germany · +49 (0) 7031.4181-860 · contact@consuvation.com