# What are Essential and Important Entities under NIS2?

> Essential entities and important entities are the two principal supervisory categories used by the NIS2 Directive.

- Canonical URL: https://yellowcube.eu/glossary/essential-and-important-entities-under-nis2/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Both categories are generally subject to the cybersecurity risk-management measures in Article 21 and significant-incident reporting requirements in Article 23. An exception applies where an at-least-equivalent sector-specific Union legal act displaces the relevant NIS2 provisions under Article 4, as DORA does for covered financial entities. The distinction between essential and important primarily affects how authorities supervise and enforce the duties that apply; it is not a division between organizations that must and need not comply.

Classification begins with the type of entity or service listed in Annex I or II, the applicable enterprise-size calculation, and the special scope and classification rules in Articles 2 and 3. Which Member State has jurisdiction is a related but separate question governed principally by Article 26 and national implementing law. As a general pattern, medium-sized entities in Annex I sectors are important, while entities in Annex I that exceed the medium-sized thresholds are essential. Annex II entities covered by the size-cap rule are generally important. Article 3 also makes specified entity types essential regardless of size or when particular national or EU criteria apply. Member States can identify additional entities under the directive’s rules.

### Key points

- **Essential entities:** Include many larger entities in Annex I’s highly critical sectors and particular categories named in Article 3, such as qualified trust service providers, top-level domain name registries, DNS service providers, and covered medium-sized public electronic-communications providers, as well as entities identified on criticality grounds.
- **Important entities:** Include covered entities that are not classified as essential, including many medium-sized Annex I entities and medium or larger Annex II entities.
- **Supervision:** Essential entities can be subject to proactive, or **ex ante**, supervision such as inspections, audits, scans, information requests, and evidence requests. Important entities are generally subject to **ex post** supervision when authorities receive evidence or indications of non-compliance.
- **Enforcement:** For infringements of Articles 21 or 23, Member States must provide maximum administrative fines of at least the higher of €10 million or 2% of the preceding financial year’s total worldwide turnover of the undertaking to which an essential entity belongs. For important entities, the corresponding required national maximum is at least the higher of €7 million or 1.4%. National law may provide higher maxima and determines the applicable procedure and other sanctions.
- **National implementation matters:** Registration, competent authorities, identification procedures, public-sector treatment, sanctions, and procedural details must be checked in each Member State’s transposing law.

### Related terms

[NIS2 Directive](<https://yellowcube.eu/glossary/nis2-directive/>) · [Digital Operational Resilience Act (DORA)](<https://yellowcube.eu/glossary/digital-operational-resilience-act/>)

### Sources

[EUR-Lex: Directive (EU) 2022/2555, Articles 2–4, 26, and 34](https://eur-lex.europa.eu/eli/dir/2022/2555/oj) · [European Commission: Guidelines on NIS2 Article 4](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX%3A52023XC0918%2801%29) · [ENISA: NIS Directive 2](https://www.enisa.europa.eu/topics/state-of-cybersecurity-in-the-eu/cybersecurity-policies/nis-directive-2)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

