Skip to content
Cybersecurity

Essential Entity

An essential entity under NIS2 is a large organization operating in a sector of high criticality (energy, transport, banking, healthcare, digital infrastructure), subject to the highest cybersecurity requirements and proactive supervision by competent authorities.

What is an Essential Entity?

Essential Entity Definition

Essential entity is a term introduced by the NIS2 Directive, referring to an organization operating in a sector of high criticality that, due to its size and importance for the functioning of the state or society, is subject to the most stringent cybersecurity requirements.

Criteria for Essential Entity Classification

An organization is an essential entity if it meets both conditions:

CriterionRequirement
SectorOperates in a sector of high criticality (Annex I NIS2)
SizeLarge enterprise (>250 employees OR >€50M turnover)

Sectors of High Criticality (Annex I NIS2)

  1. Energy - electricity, district heating/cooling, oil, gas, hydrogen
  2. Transport - air, rail, water, road
  3. Banking - credit institutions
  4. Financial market infrastructure - trading venues, CCPs
  5. Healthcare - hospitals, laboratories, pharmaceutical manufacturers
  6. Drinking water - drinking water suppliers
  7. Wastewater - wastewater enterprises
  8. Digital infrastructure - IXP, DNS, TLD, cloud, data centers, CDN
  9. ICT service management (B2B) - MSP, MSSP
  10. Public administration - central and regional government entities
  11. Space - ground-based infrastructure operators

Essential Entity vs Important Entity

AspectEssential EntityImportant Entity
SectorsHigh criticality (Annex I)Other critical (Annex II)
SizeLarge enterpriseMedium enterprise
SupervisionProactive (audits without incident)Reactive (after incident)
Maximum penalties€10M or 2% of turnover€7M or 1.4% of turnover
InspectionsRegular inspectionsOn-demand

Essential Entity Obligations

Risk Management (Article 21 NIS2)

  • Risk analysis and information system security policies
  • Incident handling (prevention, detection, response)
  • Business continuity and crisis management
  • Supply chain security
  • Security in network and system acquisition, development, and maintenance
  • Policies for assessing effectiveness of risk management measures
  • Basic cyber hygiene practices and training
  • Cryptography and encryption policies
  • Human resources security and access control
  • Multi-factor authentication (MFA)

Incident Reporting (Article 23 NIS2)

  • Early warning: 24 hours
  • Incident notification: 72 hours
  • Final report: 1 month

Management Accountability (Article 20 NIS2)

  • Approve risk management measures
  • Oversee implementation of measures
  • Undergo cybersecurity training
  • Personal liability for infringements

Consequences of Non-Compliance

InfringementMaximum Penalty
Failure to implement risk management measures€10M or 2% of annual turnover
Failure to report incidents€10M or 2% of annual turnover
Failure to cooperate with supervisory authorityAdministrative fines, prohibition from holding management positions

How to Determine if You’re an Essential Entity

  1. Identify your sector - do you operate in a sector listed in Annex I NIS2?
  2. Check your size - do you have >250 employees or >€50M turnover?
  3. Assess your services - do you provide services covered by NIS2?
  4. Consult legal counsel - seek advice if in doubt

Essential entity status carries the highest cybersecurity requirements in the EU. Organizations classified as essential entities must implement comprehensive risk management measures and prepare for regular inspections by supervisory authorities.

Learn more

Explore our services

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist