Glossary · NIS2

Essential Entity

An organisation classified under NIS2 Annex I sectors that faces the strictest supervisory regime and highest penalty ceiling.

Explained in depth: Who NIS2 applies to

Essential entities are, broadly, large organisations (at least 250 employees, or over EUR 50 million turnover) in Annex I sectors, plus certain entity types that qualify regardless of size, such as qualified trust service providers, TLD name registries, DNS service providers, and sole providers of a critical service in a member state. Public administration entities of central government are also classified as essential. Essential entities are subject to proactive supervision: competent authorities can carry out audits, inspections, and security scans at any time without needing prior indication of non-compliance. The maximum administrative fine is at least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher.

Why it matters

The essential/important distinction determines how intrusive supervision is and how high the fines go. It does not change the security measures themselves, which are identical under Article 21.

Used in

See also

← All glossary terms