NIS2 Essential vs Important Entities Explained

Last updated: 16 July 2026

Under NIS2, every in-scope company is either an essential entity or an important entity. The category does not change what security measures you have to put in place, because Article 21 of the directive sets the same requirements for both. It changes how regulators supervise you and how much you can be fined when something goes wrong. In the high-criticality sectors of Annex I the line usually turns on whether you count as a large enterprise, and that is measured across your corporate group, not on your own headcount alone.

The directive covers 18 critical sectors, and classification depends on sector, size, activity type and specific exemptions. Most teams reach the essential-versus-important question second. First they have to answer whether they are in scope at all, which is where our companion piece on whether NIS2 applies to your company starts. This piece takes over once you know you are in.

Same Obligations, Very Different Consequences

The most common misconception about NIS2 is that essential entities face stricter security requirements than important ones. They do not. Article 21 lists ten minimum measures that apply equally to both: risk analysis, incident handling, business continuity, supply chain security, security in acquisition and development, access control, cryptography, HR security, multi-factor authentication, and secured communications. The Commission’s own materials describe a different supervisory regime, not different security obligations.

Supervision is where the categories split. Essential entities face proactive, systematic oversight under Article 32, meaning scheduled audits, on-site inspections and off-site monitoring that need no triggering incident. You are auditable by default. Important entities fall under Article 33, where oversight is reactive, prompted only by evidence or indication of non-compliance, so they are not expected to document compliance on a continuous basis.

Maximum fines under Article 34 follow the same split. Essential entities face up to €10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities face up to €7 million or 1.4% of global turnover, whichever is higher. The part that rarely reaches a compliance summary is Article 32(5), which lets a national authority temporarily suspend an essential entity’s certification, or bar its chief executive or legal representative from management functions until the gaps are fixed. That sanction does not exist for important entities. The gap between a €7 million and a €10 million ceiling matters. The prospect of a personal management ban operates in a different register entirely.

Size Sets the Essential or Important Line in Annex I

Annex I covers eleven high-criticality sectors: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. For companies in these sectors the classification follows the size definition in Commission Recommendation 2003/361/EC. A large enterprise is essential, a medium enterprise is important, and micro and small companies fall outside scope unless a size-blind rule catches them.

Large means 250 or more employees, or annual turnover above €50 million together with a balance sheet total above €43 million. Medium is everything below that but above the small-enterprise ceiling. The trap is the word “your”. Size is measured across the group, not on your own books alone. Under the Annex to Recommendation 2003/361/EC a linked enterprise, where one company holds a majority of another, is consolidated in full, and a partner enterprise, a holding between 25% and 50%, is added pro rata. So a subsidiary that looks small on its own headcount and revenue can be an important or even essential entity once the group’s figures are counted. NIS2 leaves that consolidation in place. What it adds, in Recital 16, is a discretion for member states to consider how independent an entity genuinely is from its partner or linked enterprises when they apply Article 6(2) of the Annex, which can pull a truly independent subsidiary back out. The default is consolidation, and “we are only thirty people” is the most common way a company talks itself out of a scope it is actually in.

Annex II covers seven sectors: postal and courier services, waste management, chemicals, food production and distribution, manufacturing (medical devices, computers and electronics, electrical equipment, machinery, motor vehicles and other transport equipment), digital providers (online marketplaces, search engines, social networking platforms), and research organisations. For these the default is always important. Size does not move an Annex II company up to essential. A member state can reclassify a specific Annex II entity as essential under Article 2(2), points (b) to (e), but that takes a deliberate regulatory decision on grounds such as sole-provider status or systemic risk. It is not an automatic outcome of growth.

On paper the criteria are clear. In practice, companies near the large-enterprise line, subsidiaries, and groups with multiple legal entities hit complications quickly. In our assessment a competent authority that ran a clear register or a confirmation process would spare companies from interpreting their own status alone, and most national implementations have not gone that far.

Check where you land with the NIS2 Applicability Checker.

Some Entities Are Essential Whatever Their Size

A group of entities are essential no matter how small they are, because Article 3(1) fixes their category by the nature of the service rather than by headcount or turnover. Qualified trust service providers, top-level domain name registries and DNS providers, other than root name servers, are essential regardless of size under Article 3(1)(b). Central government public administration entities are essential under Article 3(1)(d). Any entity designated a critical entity under the CER Directive (EU) 2022/2557 is essential under Article 3(1)(f). For these, size is irrelevant and the service is the only criterion.

One error worth heading off, because it appears in third-party analyses, is a reference to Directive 2008/114/EC as the source for critical infrastructure entities. That directive was repealed. NIS2 Article 3(1)(f) points to CER 2022/2557 alone.

National transposition can move the line further still. Article 2(2) lets member states pull additional companies into scope or lift important entities to essential, and several have used it broadly. Poland’s amended national cybersecurity law, in force from 3 April 2026, expanded coverage far beyond the directive baseline, from roughly 400 entities to an estimated 42,000, adding sectors such as food production, waste management and manufacturing. Italy’s authority, ACN, does not leave classification to self-assessment at all, notifying entities directly of whether they are essential or important. A company that reads only the directive text does not have its answer.

How to Check Your NIS2 Category Before Your National Authority Does

Member states had to compile their lists of essential and important entities by 17 April 2025 under Article 3(3), and national authorities have moved from list-building to enforcement. There are four things to check before your authority checks them for you, and the order matters.

Start with your primary sector against the Annex I and Annex II lists. Where a company spans several sectors, the classification that produces essential status takes precedence.

Apply the size test from Recommendation 2003/361/EC across the group, not to your own legal entity alone. Linked enterprises are consolidated in full and partner enterprises pro rata, so a subsidiary that looks small on its own figures may be in scope on the group’s.

Read your national transposition law, not just the directive. Timelines and thresholds vary. Germany’s amended BSIG took effect on 6 December 2025 with no transition period, and the registration deadline for essential entities passed on 6 March 2026. Austria’s NISG 2026 enters into force on 1 October 2026, with registration due within three months, by 1 January 2027. Ireland, Spain, France and the Netherlands were still completing transposition when the Commission referred them to the Court of Justice on 8 July 2026, which we cover in our note on the NIS2 court referral.

If you operate across several member states, run the check for each one. The classification that produces essential status in any single country is the one to prepare for.

NIS2 is a directive, so the obligations, registration requirements and scope extensions are shaped by each member state’s transposition. Check sector and size first, then confirm for each country how NIS2 has been transposed locally. The directive is the floor. Your national law is the ceiling. They are not always the same height.

Once you know your category, our breakdown of NIS2 obligations covers the ten Article 21 measures in detail. If closing the gaps calls for outside help, the specialist NIS2 consultancies in our provider directory are filterable by member state and service.

RegDossier

Making EU compliance almost enjoyable. Almost.

EU regulatory updates in your inbox every two weeks. Free.

Get the next briefing

Similar Posts