How does the NIS2 Directive define “essential” and “important” entities, and how does this affect their reporting obligations?

Direttiva NIS2 Frequently Asked Questions

The NIS2 Directive establishes a two-tier system for classifying entities falling within its scope: essential entities and important entities. This classification, based on the entity’s perceived importance and potential impact on essential services and society, directly influences their cybersecurity obligations, including incident reporting. For an in-depth look at the reference regulatory framework, the official document of the NIS2 Directive is available.

🔴 NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

Essential Entities

  • Definition: The NIS2 Directive provides a multifaceted definition of “essential entities,” which includes several categories:
  • Entities listed in Annex I that exceed the size threshold for medium-sized enterprises as defined in Recommendation 2003/361/EC. Annex I includes sectors considered “highly critical,” such as energy, transport, banking, health, and digital infrastructure.
  • Specific entities regardless of size, including qualified trust service providers, top-level domain name registries, DNS service providers, and providers of public electronic communications networks or publicly available electronic communications services.
  • Central government public administration entities as defined by the national law of each Member State.
  • Any other entity listed in Annexes I or II (which include “other critical sectors”) that a Member State identifies as essential based on criteria outlined in Article 2(2)(b-e). These criteria consider whether an interruption of the entity’s services could:
    • Significantly affect public safety, national security, or public health.
    • Lead to a significant systemic risk, particularly in sectors with potential cross-border impact.
    • Have a significant impact on critical social or economic activities at a national or regional level due to the entity’s particular importance in that sector or service area.
  • Entities designated as “critical” under Directive (EU) 2022/2557.
  • Entities identified as operators of essential services by a Member State before January 16, 2023, under Directive (EU) 2016/1148 or national law.
  • Reporting Obligations: Essential entities are subject to a more rigorous supervisory regime and are required to meet all incident reporting requirements outlined in the NIS2 Directive. This includes:
  • Early Warning: Provide an alert to the CSIRT or competent authority within 24 hours of becoming aware of a significant incident.
  • Incident Notification: Submit a more detailed notification within 72 hours.
  • Final Report: Provide a comprehensive report within one month of the incident notification.

Important Entities

  • Definition: The NIS2 Directive defines “important entities” as those belonging to the sectors listed in Annexes I or II that are not classified as essential entities. This category includes entities identified by Member States as important based on the criteria of Article 2(2)(b-e) mentioned above.
  • Reporting Obligations: Although important entities are subject to the NIS2 Directive’s incident reporting requirements, they are subject to a less stringent supervisory regime than essential entities. Furthermore, the level of administrative fines for violations of reporting obligations is lower than that provided for essential entities.

Impact of Classification

The classification of an entity as “essential” or “important” has significant implications for its cybersecurity obligations under the NIS2 Directive:

  • Supervisory Measures: Essential entities are subject to more rigorous and proactive supervisory measures by competent authorities compared to important entities. This includes regular audits, on-site inspections, and requests for information.
  • Enforcement of Sanctions: The NIS2 Directive establishes a framework for sanctions in case of non-compliance. While both categories can be penalized for violations, essential entities face higher administrative fines, reflecting their greater potential impact on society and the economy.
  • Accountability: The directive emphasizes individual accountability in high-level management positions in both essential and important entities, ensuring that there is organizational-level responsibility for the cybersecurity measures adopted.

In essence, the NIS2 Directive’s two-tier system recognizes the different levels of risk and potential impact associated with various entities operating in critical sectors. By classifying entities as “essential” or “important,” the directive applies a proportionate approach to cybersecurity obligations: understanding which category your organization falls into is the first concrete step toward setting up a structured NIS2 compliance path.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In