NIS2 Essential Entities vs Important Entities: What Your Organisation Needs to Know (2026)
The NIS2 Directive (EU 2022/2555, transposed in Spain by RDL 3/2025 and in force from October 2024) creates two tiers of regulated entities: Essential Entities (EEs) and Important Entities (IEs). The distinction matters because EEs face stricter obligations, proactive supervision, and fines up to €10 million or 2% of global turnover. This guide explains which tier applies to your organisation and what you must implement now.
€10M or 2%
"Maximum fine for Essential Entities under NIS2 for failure to implement required cybersecurity risk management measures — whichever is higher."
— NIS2 Directive Art. 34(4), EU 2022/2555
What is NIS2 and when did it come into force?
Directive EU 2022/2555 (NIS2) was adopted on 14 December 2022, replacing the original NIS1 Directive (2016/1148). NIS2 substantially expanded the scope of regulated sectors, introduced stricter obligations, and created clearer liability for senior management. Member states were required to transpose NIS2 into national law by 17 October 2024.
In Spain, the transposition was achieved through Real Decreto-Ley 3/2025, entering into force in March 2025. The national competent authorities are CCN-CERT (for public sector and critical infrastructure) and INCIBE-CERT (for private sector). In the UK, post-Brexit, NIS2 does not apply directly; instead, the NIS Regulations 2018 (as amended by the Network and Information Systems (Amendment) Regulations 2022) form a separate but broadly comparable regime overseen by the NCSC and ICO.
Essential Entities vs Important Entities — the key distinction
NIS2 divides regulated organisations into two categories. Essential Entities (EEs) are generally large organisations operating in the most critical sectors (Annex I). Important Entities (IEs) are medium-sized organisations in Annex I sectors, or organisations of any size in high-criticality sectors listed in Annex II. The practical consequences of this classification are significant.
| Criterion | Essential Entity (EE) | Important Entity (IE) |
|---|---|---|
| Supervision model | Proactive — ex ante audits and inspections | Reactive — supervisory action triggered by evidence of breach |
| Maximum fine | €10M or 2% global turnover | €7M or 1.4% global turnover |
| Incident reporting timeline | 24h early warning → 72h notification → 1 month final report | Same timeline applies |
| Auditing | Mandatory periodic audits by national authority | Audits only on request or upon suspicion of breach |
| Management liability | Personal liability; mandatory cybersecurity training | Personal liability; training recommended |
| Risk measures (Art. 21) | All 10 mandatory measures — full scope | All 10 mandatory measures — proportionate implementation |
| Supply chain requirements | Must assess and contractually bind direct suppliers | Must assess direct suppliers; contractual binding encouraged |
| Cross-border coordination | Must designate point of contact; proactive engagement with EU-CyCLONe | Point of contact recommended; reactive engagement |
Which sectors are covered?
NIS2 uses two annexes to define scope. Annex I covers sectors of high criticality, where large operators are classified as Essential Entities: Energy (electricity, district heating, oil, gas, hydrogen), Transport (air, rail, water, road), Banking, Financial market infrastructure, Health, Drinking water, Wastewater, Digital infrastructure (IXPs, DNS, TLD registries, cloud computing, data centres, CDNs, trust services, electronic communications), ICT service management (managed services, managed security services), Space, and Public administration.
Annex II covers other critical sectors where organisations are generally classified as Important Entities regardless of size: Postal and courier services, Waste management, Manufacture, production and distribution of chemicals, Production, processing and distribution of food, Manufacturing (medical devices, computers, electrical equipment, machinery, motor vehicles, transport equipment), Digital providers (online marketplaces, online search engines, social networking platforms), and Research organisations.
The size threshold rule — and critical exceptions
The general size rule under NIS2 is straightforward. In Annex I sectors: organisations that are large enterprises (250 or more employees, or annual turnover exceeding €50M and annual balance sheet exceeding €43M) are classified as Essential Entities. Organisations that are medium enterprises (50–249 employees) in the same sectors are classified as Important Entities.
In Annex II sectors: medium and large enterprises are classified as Important Entities regardless of which Annex they fall under.
CRITICAL EXCEPTION — always Essential regardless of size: Certain entities are automatically classified as Essential Entities regardless of their headcount or turnover. These include: providers of public electronic communications networks or publicly available electronic communications services; qualified trust service providers; TLD name registries and DNS service providers; providers of cloud computing services, data centre services, content delivery networks, managed services and managed security services (where designated by Member State); operators of essential services (OES) already designated under NIS1; entities identified as critical by a Member State under other legislation (e.g. DORA, CER Directive); sole providers of a critical service in a Member State; public administration entities at central government level.
What must Essential Entities implement? Art. 21 NIS2
Article 21 of NIS2 mandates ten categories of cybersecurity risk management measures. Both Essential and Important Entities must implement all ten, but EEs are expected to implement them to a higher standard and will be audited proactively to verify compliance.
Management liability under Art. 20 NIS2
Article 20 of NIS2 introduces a significant shift from NIS1: senior management is personally liable for NIS2 compliance failures. The governing bodies of both Essential and Important Entities must approve the cybersecurity risk management measures, oversee their implementation, and can be held personally liable if the entity fails to comply.
Tracking NIS2 obligations across multiple entities and jurisdictions?
IgeraRegTech tracks your NIS2 obligations, incident reporting deadlines and evidence requirements — updated automatically when regulation changes
See IgeraRegTechLast updated: July 2026 | Reviewed by: IgeraSolutions Legal & RegTech Team | Sources: EU Directive 2022/2555 (NIS2); RDL 3/2025 Spain; ENISA NIS2 Implementation Guide 2024; CCN-CERT | IgeraRegTech — automated NIS2 compliance tracking.