NIS2 scoping memo: Tinklas IT UAB (illustrative)
Directive (EU) 2022/2555 (NIS2), CELEX 32022L2555. Text as held on data_as_of 2026-09-02 (EUR-Lex). This memo sets out sources, not advice. The final classification belongs to the company and its competent authority. It cross-reads DORA (32022R2554) and GDPR (32016R0679).
Checkpoint (recorded mid-run): I assumed the sector is Annex I point 9, "ICT service management (business-to-business)", as a managed service provider. I applied 85 staff and EUR 14m turnover, with no balance-sheet figure and no group or partner companies. That makes the company medium-sized, not above the medium-sized ceilings, and not designated. The resulting class is important.
1. The entity
Tinklas IT UAB is a private company in Kaunas, Lithuania, with 85 staff and EUR 14m turnover. It installs, runs and maintains networks, servers and helpdesks for other businesses under contract. Its customers are two hospitals, two banks and about 40 SMEs. It is not a public body and no authority has designated it.
2. Sector test (Annex I or II)
- Annex I, point 9: "ICT service management (business-to-business)."
- Art 6(39) defines a managed service provider as an entity providing "services related to the installation, management, operation or maintenance of ICT products, networks, infrastructure, applications or any other network and information systems, via assistance or active administration carried out either on customers' premises or remotely". Running networks, servers and helpdesks for other businesses fits that wording.
- Managed service providers are named directly in Art 21(5), Art 23(11), Art 26(1)(b) and Art 27(1).
- Limitation: Rekvira's copy of Annex I holds only the sector headings, not the "type of entity" column. The link between point 9 and managed service providers rests on Art 6(39) and the articles above. Check it against the Official Journal table.
3. Size test
- Art 2(1): NIS2 applies to Annex I or II entities that qualify as medium-sized under Article 2 of the Annex to Recommendation 2003/361/EC, or that exceed those ceilings. Art 2(1) also says that "Article 3(4) of the Annex to that Recommendation shall not apply."
- The Recommendation is not held in Rekvira. From its published text: a medium-sized enterprise has fewer than 250 staff and either turnover of EUR 50m or less or a balance sheet of EUR 43m or less. Enterprises with fewer than 50 staff and EUR 10m or less fall below medium (small).
- With 85 staff and EUR 14m turnover, Tinklas is medium-sized. It is at or above the entry threshold in Art 2(1) and does not exceed the medium-sized ceilings.
- The size-independent routes in Art 2(2)(a)–(f), 2(3) and 2(4) do not apply on these facts. Tinklas is not a telecoms provider, trust service provider, domain name registry or DNS provider, domain name registrar, public administration or critical entity. Points (b)–(e) cover being the sole provider, or having a significant impact or national importance. They apply only if the Member State identifies the entity, and no such identification has been made.
Result: NIS2 applies.
4. Essential or important
- Art 3(1)(a): an Annex I entity is essential only if it exceeds the medium-sized ceilings. Tinklas does not.
- Art 3(1)(b)–(g) do not apply on the facts: no qualified trust or DNS services, no telecoms, not public administration, not identified under Art 2(2)(b)–(e), not a critical entity, and not a former operator of essential services.
- Art 3(2): "entities of a type referred to in Annex I or II which do not qualify as essential entities pursuant to paragraph 1 of this Article shall be considered to be important entities."
Result: an important entity by operation of the text, unless Lithuania identifies it as essential under Art 2(2)(b)–(e) and Art 3(1)(e). Having hospitals and banks as customers does not change this test. It could only matter if the authority relied on it for an Art 2(2)(c)–(e) identification.
5. Duties that follow
lookup_obligations returned zero headings for both roles. Its also_named list pointed to Art 3, 33 and 34 for important entities and Art 32 for essential entities. The duties below come from reading the text.
| Duty | Pinpoint |
|---|---|
| Registration details for the national list: name, contacts, IP ranges, sector. Changes must be notified within 2 weeks. | Art 3(4) |
| Managed-service-provider registry details (feeds the ENISA registry): sector and type, establishments, Member States served, IP ranges. Changes must be notified within 3 months. | Art 27(2), 27(3) |
| Jurisdiction: the Member State of the main establishment in the Union (Lithuania on these facts) | Art 26(1)(b) |
| The management body approves the risk-management measures, oversees them and can be held liable. Its members must take training. | Art 20(1), 20(2) |
| Appropriate and proportionate risk-management measures, all-hazards, covering at least points (a)–(j): risk analysis, incident handling, business continuity, supply chain, secure development and maintenance, effectiveness review, cyber hygiene and training, cryptography, HR and access control and asset management, multi-factor authentication | Art 21(1), 21(2) |
| Corrective measures without undue delay where it finds it does not comply | Art 21(4) |
| The Commission's implementing act on technical and methodological requirements specifically covers managed service providers | Art 21(5) |
| Significant-incident reporting: early warning within 24h, notification within 72h, final report within 1 month. Notify affected service recipients where appropriate. | Art 23(1), 23(3), 23(4) |
| Tell affected recipients about significant cyber threats and the measures they can take | Art 23(2) |
| The Commission's implementing act on which incidents count as significant covers managed service providers | Art 23(11) |
| Supervision is ex post, triggered by evidence or indications of non-compliance | Art 33(1) |
| Fines for breaching Art 21 or 23: maximum of at least EUR 7m or 1.4% of worldwide turnover, whichever is higher | Art 34(5) |
The implementing act under Art 21(5) and Art 23(11) is not held in Rekvira. The company should read it directly, because it is where the managed-service-provider requirements are set out in detail.
6. Where other EU acts take over (each act kept separate)
NIS2 Art 4. Where a sector-specific Union act imposes risk-management or reporting duties at least equivalent to NIS2 (Art 4(2)), those NIS2 provisions do not apply to the entities covered by that act (Art 4(1)).
DORA. Art 1(2) makes DORA the sector-specific act under NIS2 Art 4 only "in relation to financial entities". That takes over NIS2 duties for the two banks, not for Tinklas. On the board's bank question:
- Nothing in DORA removes or replaces Tinklas's NIS2 duties.
- Tinklas is an "ICT third-party service provider" ("an undertaking providing ICT services", Art 3(19)). The banks stay fully responsible for their own ICT third-party risk (Art 28(1)).
- The bank contracts must contain the terms in Art 30(2). These include service locations, data protection, assistance during incidents, and full cooperation with the banks' competent and resolution authorities.
- If a service supports critical or important functions, the contracts must also contain the terms in Art 30(3). These include business-continuity testing, taking part in the bank's threat-led penetration testing (TLPT), unrestricted access, inspection and audit rights, and exit transition periods. These duties reach Tinklas through contract.
- Direct oversight under DORA applies only if the European Supervisory Authorities (ESAs) designate Tinklas a critical ICT third-party provider (Art 31(1)). Nothing suggests that on these facts.
GDPR. Where Tinklas processes personal data for customers (for example hospital patient data on the systems it runs), it acts as a processor under Art 28. It must notify the controller of a personal data breach "without undue delay" (Art 33(2)). This runs alongside NIS2 Art 23. The two do not replace each other.
Hospitals. Health is an Annex I sector, so the hospitals are likely NIS2 entities themselves. Their supply-chain duties under Art 21(2)(d) will be passed down to Tinklas through contract. That does not change Tinklas's class.
7. Citations checked
Every pinpoint above was checked with verify_citation and returned exists=held:
- NIS2: Art 2(1)\, 2(2), 3(1), 3(2)\, 3(4), 4(1), 4(2), 6(39)\, 20(1), 20(2), 21(1), 21(2)\, 21(4), 21(5), 23(1), 23(2), 23(3), 23(4)\, 23(11), 26(1), 27(2), 27(3), 33(1), 34(5)\, Annex I(9)\*
- DORA: Art 1(2)\, 3(19), 28(1), 30(2)\, 30(3)\*, 31(1)
- GDPR: Art 28, 33(2)\*
\* the quoted wording was also checked and found.
Art 26(1)(b) and Art 27(1) were read in full with read_unit. They were verified at paragraph level (Art 26(1)) or read only (Art 27(1)). Recommendation 2003/361/EC is not held, so the size ceilings in section 3 are not verified here.
8. Open points for your decision
- Lithuanian transposition. The national cybersecurity law implementing NIS2, including its registration mechanism, deadlines, competent authority and CSIRT, was not read. It is not held in Rekvira.
- Designation and the national list. Rekvira cannot see whether the Lithuanian authority has listed or identified Tinklas under Art 3(3) or Art 2(2)(b)–(e), including any identification as essential.
- Group structure. Are there partner or linked companies whose staff or financial figures would count towards size under the Recommendation? Also confirm the balance sheet total.
- Annex I "type of entity" column. Confirm the managed-service-provider entry against the Official Journal table.
- Implementing act for managed service providers (Art 21(5) and 23(11)). Read it directly, because it is not held here.
- DORA contract review. Do the services to the two banks support critical or important functions? That decides whether the full Art 30(3) terms apply.
- I recorded no applicability verdicts in Rekvira. Once you confirm the class, you can have them recorded against Art 3(2), 21 and 23.