Glossary
Important Entity
A category of entities subject to NIS 2 with obligations comparable to essential entities, but ex-post supervision and lower penalties.
An Important Entity is an organisation subject to the NIS 2 directive that does not meet the criteria for an essential entity. It must comply with substantially the same cybersecurity obligations, but is subject to a different supervision regime.
Identification criteria
An entity is considered important if it:
- Belongs to one of the 7 other critical sectors (postal services, waste management, chemicals, food, manufacturing, digital providers, research)
- OR belongs to a highly critical sector but is a medium-sized enterprise (between 50 and 250 employees, or between €10M and €50M turnover)
Differences from essential entities
| Criterion | Essential entity | Important entity |
|---|---|---|
| Supervision | Proactive | Ex-post (triggered by a report or incident) |
| Maximum penalty | €10M or 2% of turnover | €7M or 1.4% of turnover |
| Obligations | Identical | Identical |
Both categories share the same core requirements on risk management, incident notification and supply chain security.