The NIS2 Directive establishes two main categories of entities: essential entities and important entities. The classification is based on the entity’s sector, size, and the potential impact of the essential services provided on society.
- Essential entities: These are subject to a more rigorous supervisory regime compared to important entities. These entities face more frequent and stringent audits, potentially higher penalties for non-compliance, and a higher expectation to adopt proactive cybersecurity measures.
- Important entities: While they must still comply with the obligations set out in the NIS2, they are subject to a lighter supervisory regime compared to essential entities. They have greater flexibility in how they implement cybersecurity measures and face potentially lower penalties in case of non-compliance.
Criteria for Essential Entities:
The NIS2 Directive defines essential entities based on the following criteria:
- Sector: The entity operates in a sector considered to be of “high criticality.” Annex I of the NIS2 Directive lists these sectors, including energy, transport, banking, health, drinking water, wastewater, digital infrastructure, public administration, and space. Within each sector, the annex specifies further subsectors and types of entities.
- Size: The entity exceeds the size threshold for medium-sized enterprises, thus falling into the category of large companies.
- Specific designations: The entity falls under the following specific designations:
- Qualified trust service providers and top-level domain name registries, as well as DNS service providers, regardless of their size.
- Public administration entities as indicated in Article 2, Paragraph 2(f)(i).
- Entities identified as “critical” under Directive (EU) 2022/2557, as indicated in Article 2, Paragraph 3.
- Entities previously identified by Member States as operators of essential services under Directive (EU) 2016/1148 or national legislation, if provided for by the Member State.
- Identification by the Member State: Furthermore, Member States have the authority to designate other entities listed in Annexes I or II as essential based on the criteria indicated in Article 2, Paragraph 2(b) to (e). These criteria concern:
- The entity’s role as the sole provider of a service essential for the maintenance of critical economic or social activities in a Member State.
- The potential impact on public security, national security, or public health in the event of a service disruption.
- The ability to cause a significant systemic risk, particularly with cross-border implications, in the event of a service disruption.
Criteria for Important Entities:
Important entities are defined as follows:
- Sector and size: The entity belongs to a sector listed in Annexes I or II but does not meet the criteria to be classified as an essential entity. This typically includes medium-sized or smaller entities operating in the specified sectors.
- Identification by the Member State: Similar to essential entities, Member States may designate entities listed in Annexes I or II as important based on the criteria specified in Article 2, Paragraph 2(b) to (e).
Key Points:
- The classification of an entity as essential or important under NIS2 depends on a combination of factors, with the sector, size, and potential social impact playing crucial roles.
- Essential entities are subject to a more rigorous regulatory environment, with stricter cybersecurity obligations and potentially higher penalties in case of non-compliance. To start a structured path toward NIS2 Directive compliance, it is useful to start with an assessment of your perimeter and applicable obligations.
- Member States retain a degree of flexibility in designating specific entities as essential or important based on the national context and risk assessments. For Italian organizations, a practical reference is the procedure for registration with the ACN list and the deadlines provided for NIS2 subjects.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
