Skip to content
CyberNIS2

Glossary

Important Entity

A category of entities subject to NIS 2 with obligations comparable to essential entities, but ex-post supervision and lower penalties.

An Important Entity is an organisation subject to the NIS 2 directive that does not meet the criteria for an essential entity. It must comply with substantially the same cybersecurity obligations, but is subject to a different supervision regime.

Identification criteria

An entity is considered important if it:

  • Belongs to one of the 7 other critical sectors (postal services, waste management, chemicals, food, manufacturing, digital providers, research)
  • OR belongs to a highly critical sector but is a medium-sized enterprise (between 50 and 250 employees, or between €10M and €50M turnover)

Differences from essential entities

CriterionEssential entityImportant entity
SupervisionProactiveEx-post (triggered by a report or incident)
Maximum penalty€10M or 2% of turnover€7M or 1.4% of turnover
ObligationsIdenticalIdentical

Both categories share the same core requirements on risk management, incident notification and supply chain security.