NIS2 Essential Entities Guide: What the Directive Requires in 2026
NIS2 transposition deadlines passed in October 2024. If you operate in energy, transport, banking, health, digital infrastructure or public administration, you are already subject to enforcement. Here is the complete obligation map.
Key figures: NIS2 covers ~160,000 entities across the EU. Essential entities: max fine €10M or 2% global annual turnover. Important entities: max fine €7M or 1.4% turnover. Incident notification: 24h early warning, 72h full notification, 1 month final report.
Essential vs Important entities — are you in scope?
| Criterion | Essential Entity | Important Entity |
|---|---|---|
| Size | Large (≥250 employees or ≥€50M turnover) | Medium (≥50 employees or ≥€10M turnover) |
| Sectors (Annex I) | Energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space | Postal, waste management, chemicals, food production, manufacturing, digital providers, research |
| Supervision | Ex-ante (proactive, ongoing) | Ex-post (triggered by incident or complaint) |
| Max penalty | €10M or 2% global turnover | €7M or 1.4% global turnover |
Note: certain entities are in scope regardless of size — DNS providers, TLD registries, cloud providers, data centres, CDNs, and electronic communication networks.
10 mandatory security measures (Art. 21)
NIS2 Article 21 requires a risk-based approach covering at minimum:
- Risk analysis and information system security policies
- Incident handling — detection, response, recovery procedures
- Business continuity — backup management, disaster recovery, crisis management
- Supply chain security — including relationships with direct suppliers and service providers
- Security in network and information systems acquisition, development and maintenance
- Policies and procedures to assess effectiveness of cybersecurity risk-management measures
- Basic cyber hygiene practices and cybersecurity training
- Policies on the use of cryptography and, where appropriate, encryption
- Human resources security, access control policies and asset management
- Multi-factor authentication (MFA) or continuous authentication solutions