Essential and important entities (NIS2)
Also known as: essential entities, important entities
The two groups of organisations NIS2 covers, sorted by sector and size, with stricter oversight for the essential group.
Draft - this entry has not been reviewed yet.
Formal
The two classes of NIS2 Article 3 - as a rule, large organisations in the Annex I sectors are essential, while medium ones there and medium or large ones in Annex II are important. Duties are the same; essential entities face checks in advance and higher fines.
In plain English
Like road rules for lorries and vans - both must drive safely, but lorries are pulled over for checks more often because a crash does more harm.
In practice
A large Danish energy company sits in Annex I and is essential, so it expects planned inspections; a medium-sized food producer sits in Annex II and is important, so it is checked mainly after an incident or a tip-off.
Why it matters
Getting the class wrong means preparing for the wrong level of oversight - too little, and the first inspection or fine comes as a surprise; too much, and money goes where it is not needed.
Technical deep dive
Classification is a two-step test. Article 2 first decides whether an entity is in scope at all: it must be of a type listed in Annex I or II and at least a medium-sized enterprise under Article 2 of the Annex to Commission Recommendation 2003/361/EC, meaning 50 or more staff, or an annual turnover and balance sheet total both above EUR 10 million. Large enterprises are those with 250 or more staff, or turnover above EUR 50 million and a balance sheet above EUR 43 million. Because the Recommendation counts partner and linked enterprises, a modest subsidiary of a large group can cross the threshold on group figures, one of the most common surprises in scoping.
Article 3(1) then lists who is essential: Annex I entities that exceed the medium-sized ceilings; qualified trust service providers, TLD name registries and DNS service providers regardless of size; providers of public electronic communications networks or services that are at least medium-sized; central-government public administration entities; entities identified as critical under the CER Directive (EU) 2022/2557; and any others a member state designates, including former NIS1 operators of essential services if national law so provides. Everything else in scope under Annexes I and II is important under Article 3(2). Member states had to draw up a list of essential and important entities by 17 April 2025 and review it at least every two years, supported by self-registration.
Obligations under Articles 20, 21 and 23 are identical for both classes; supervision and sanctions are not. Essential entities are subject to Article 32: on-site inspections and off-site supervision including random checks, regular and targeted security audits by an independent body, ad hoc audits, security scans and requests for evidence, even without any incident. Important entities fall under Article 33, where a narrower set of tools, without random checks or regular audits, is used only after evidence, an indication or information suggests non-compliance. Maximum fines differ (Article 34: at least EUR 10 million or 2 % of worldwide turnover versus EUR 7 million or 1.4 %), and only essential entities can face suspension of a certification or authorisation and a temporary ban on a manager under Article 32(5).
Edge cases need care. Public administration is mandatory only at central-government level; member states may extend coverage to regional and local bodies, and may exempt bodies working mainly in national security, defence or law enforcement. Financial entities under DORA are covered by that regulation instead of Articles 21 and 23. In Denmark the NIS2 Act mirrors the classes in §§ 4-5, and entities must register their details with the authorities through Virk so that the list can be maintained.
Relationships
- Part of
- NIS2 Directive
Sources & further reading
Standards & official texts
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…