Glossary · NIS2
Essential Entity
An organisation classified under NIS2 Annex I sectors that faces the strictest supervisory regime and highest penalty ceiling.
Explained in depth: Who NIS2 applies to
Essential entities are, broadly, large organisations (at least 250 employees, or over EUR 50 million turnover) in Annex I sectors, plus certain entity types that qualify regardless of size, such as qualified trust service providers, TLD name registries, DNS service providers, and sole providers of a critical service in a member state. Public administration entities of central government are also classified as essential. Essential entities are subject to proactive supervision: competent authorities can carry out audits, inspections, and security scans at any time without needing prior indication of non-compliance. The maximum administrative fine is at least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher.
Why it matters
The essential/important distinction determines how intrusive supervision is and how high the fines go. It does not change the security measures themselves, which are identical under Article 21.
