vCISO Cybersecurity

Blog space

NIS2 Compliance – are you an essential or important entity and what must you implement?

In this article you will learn

  • Whether NIS2 applies to your organisation
  • The 18 NIS2 sectors
  • The differences between essential and important entities
essential or important entity

Updated: 21 July 2026

What is the NIS2 Directive and who does it cover? NIS2 (Directive (EU) 2022/2555) entered into force on 16 Jan 2023 and required Member States to transpose it by 17 Oct 2024. It is the EU’s baseline cybersecurity framework for organisations operating in 18 critical sectors – far broader than the original NIS Directive. Most boards still raise the NIS2 question too late, assuming it only touches obvious critical infrastructure. In practice, food manufacturers, digital service providers, waste management operators, postal services, manufacturers and managed service providers can all fall within scope. Fines for essential entities can reach EUR 10 million or 2% of global annual turnover, whichever is higher (Article 34 NIS2).

NIS2 essential or important entity compliance – at a glance:

  1. NIS2 covers 18 critical sectors across the EU – the list extends far beyond energy, banking and healthcare into food, manufacturing, waste management, digital providers and ICT service management.
  2. The size threshold for most sectors: at least 50 employees or more than EUR 10 million annual turnover or balance sheet total brings an entity into scope.
  3. Essential entities face proactive supervision; important entities face predominantly reactive supervision. Both categories have hard obligations under Articles 20, 21 and 23.
  4. Article 20 requires management bodies to approve and oversee cybersecurity risk-management measures and to follow training – boards must demonstrate informed cyber oversight, not merely receive IT briefings.
  5. Fines: essential entities – up to EUR 10 million or 2% of global annual turnover; important entities – up to EUR 7 million or 1.4% (Article 34 NIS2).
  6. Incident reporting timelines (Article 23): early warning within 24 hours, full notification within 72 hours, final report within one month.
  7. Patronusec conducts NIS2 applicability assessments and gap analyses for organisations in essential and important sectors – helping establish classification, jurisdiction-specific requirements and implementation priorities before the regulator does.


How do you determine whether your organisation is an essential or important entity under NIS2?

Whether your organisation is an essential or important entity under NIS2 is one of the first questions to answer before planning compliance work.

Apply three filters in sequence: sector, size and special status. Getting them wrong can mean a year preparing for the wrong regulation.

Step 1 – Sector: Does your organisation operate in a sector listed in Annex I (high criticality) or Annex II (other critical sectors) of Directive (EU) 2022/2555? NIS2 covers 18 critical sectors across the EU – and the list is broader than most boards expect.

Step 2 – Size: The medium-size threshold is the practical starting point for most sectors: at least 50 employees or more than EUR 10 million annual turnover or balance sheet total. The large-entity threshold (at least 250 employees or more than EUR 50 million turnover or balance sheet total) matters for the essential/important classification. The Directive also contains special cases – certain digital service providers, trust service providers, public electronic communications providers, DNS service providers and TLD registries can be in scope regardless of size.

Step 3 – National transposition: A sector check at EU level is only the starting point. National transposition laws can widen or reshape the detail – registration routes, supervisory authority structures and the interaction with sector-specific rules differ materially by country.

Patronusec Insight: The most common error we observe is skipping Step 3. Organisations check the EU Directive scope, declare compliance and stop – failing to account for the fact that the national transposition act may change thresholds, require registration or impose obligations beyond the Directive minimum. As part of our NIS2 applicability assessments, we analyse both Directive requirements and national law in each jurisdiction where the client operates simultaneously.

What are the 18 sectors covered by NIS2 (Annexes I and II)?

AnnexSectorWhat it covers in practice
Annex IEnergyElectricity, district heating and cooling, oil, gas, hydrogen
Annex ITransportAir, rail, water and road transport operators and infrastructure
Annex IBankingCredit institutions
Annex IFinancial market infrastructuresTrading venues, CCPs and similar market infrastructure
Annex IHealthHospitals, clinics, laboratories, healthcare providers
Annex IDrinking waterSuppliers and distributors
Annex IWaste waterCollection, disposal and treatment entities
Annex IDigital infrastructureIXPs, DNS, TLD registries, data centres, cloud, trust services, public electronic communications
Annex IICT service managementManaged service providers and managed security service providers
Annex IPublic administrationCentral and, in some Member States, regional
Annex ISpaceOperators of ground-based infrastructure supporting space services
Annex IIPostal and courier servicesOperators handling postal or parcel delivery
Annex IIWaste managementCollection, transport, recovery and disposal operators
Annex IIManufacture/production/distribution of chemicalsChemical industry entities
Annex IIFoodProduction, processing and distribution
Annex IIManufacturingMedical devices, computer/electronics, machinery, motor vehicles, other transport equipment
Annex IIDigital providersOnline marketplaces, search engines, social networking platforms
Annex IIResearchResearch organisations carrying out critical or strategic work

What are the 10 security measures required by NIS2 Article 21?

Article 21 is the operational core of NIS2. Boards should treat it as a mandatory agenda, not a menu.

Article 21 measureWhat it means in practiceComplexity
1. Risk analysis and information system security policiesDocumented cyber risk-management policy and repeatable risk assessment methodologyModerate
2. Incident handlingDetection, triage, escalation, containment, eradication, recovery and lessons learnedModerate
3. Business continuity, backup, disaster recovery and crisis managementCyber scenarios built into BCM plans – not a separate binderSpecialist
4. Supply-chain securityAssessment of the cybersecurity posture of direct suppliers and ICT service providersSpecialist
5. Security in network and information systems acquisition, development and maintenanceSecure development, patching, change control and vulnerability managementSpecialist
6. Policies and procedures to assess the effectiveness of cybersecurity risk-management measuresInternal audits, metrics, assurance reviews and tabletop exercisesModerate
7. Basic cyber hygiene and cybersecurity trainingAwareness, secure configuration, patching discipline and trained staff – including management body training under Article 20Straightforward
8. Policies and procedures regarding cryptography and, where appropriate, encryptionEncryption policy, key management, approved algorithmsModerate
9. Human resources security, access control policies and asset managementJoiners/movers/leavers, least privilege, MFA, role reviews and asset inventoriesModerate
10. MFA or continuous authentication, secured voice/video/text communicationsModern identity and communications controls as a baseline, not an optional extraStraightforward

The incident reporting deadlines linked to Article 23 are equally specific: early warning within 24 hours of awareness, full incident notification within 72 hours, final report no later than one month after notification. Your incident response plan must support regulatory notification under time pressure, not only technical containment.


Unsure whether your organisation falls under NIS2 – or in which category?

In a free 30-minute session we assess NIS2 applicability: we establish the likely classification, identify the national-law checkpoints that matter for your jurisdictions and show where your evidence and governance are weakest – before the regulator does.

Book a free NIS2 consultation


How does ISO 27001 reduce the effort required for NIS2 compliance?

Companies already building or maintaining ISO 27001 are not starting from zero – they are starting from structure. ISO/IEC 27001:2022 provides an information security management system, a risk methodology, internal audit, management review, control ownership and evidence discipline. Those are exactly the foundations NIS2 entities need when regulators ask how risk is assessed, how controls are chosen and what management approved.

The operational overlap is substantial. From our project experience, a company with a live ISO 27001 programme often finds that 40-60% of the organisational effort needed for NIS2 is already in place: risk analysis, supplier management, access control, incident response, BCM structure, asset inventories, audit evidence and management review mechanics.

ISO 27001 does not replace NIS2 – it accelerates it. ISO provides the management system; NIS2 adds sector-specific legal duties, classification, supervisory expectations and incident-reporting obligations.

Learn more about ISO 27001 certification and NIS2 compliance services.

Patronusec Insight: A common trap in combined ISO 27001 + NIS2 projects is assuming all 10 Article 21 measures are automatically covered by ISO 27001. They are not – NIS2 introduces specific obligations around incident reporting, entity classification and supervisory requirements that go beyond the scope of ISO certification. In engagements delivered through our vCISO model, we build an ISO-NIS2 gap-analysis mapping that identifies precisely what is missing – rather than duplicating work the client has already done.

FAQ – Essential or Important Entity

What is the difference between essential and important entities under NIS2?

Essential entities face more proactive supervision and higher maximum fines. Important entities are still fully in scope, but supervision is more often reactive. Both must implement Article 21 measures and meet Article 23 reporting duties.

What are the penalties for NIS2 non-compliance?

Member States must provide for fines of at least up to EUR 10 million or 2% of worldwide annual turnover for essential entities, and up to EUR 7 million or 1.4% for important entities – whichever figure is higher in each case (Article 34 NIS2).

Can a CEO be personally held liable under NIS2?

NIS2 requires Member States to ensure management bodies approve and oversee cyber risk measures and can be held liable under national law. The exact personal-liability mechanism depends on national transposition, but board accountability is explicit in Article 20 – including the possibility of temporary bans from management roles for essential entities.

When did NIS2 come into force and when must organisations comply?

The Directive entered into force on 16 Jan 2023. Member States were required to transpose it by 17 Oct 2024, but national implementation varies – organisations must check both the Directive and the applicable national law in each Member State where they operate.

What security measures does NIS2 Article 21 require?

Article 21 sets out 10 minimum measures: risk analysis and security policies, incident handling, business continuity and backup, supply-chain security, secure network and information systems, control effectiveness testing, cyber hygiene and training, cryptography, human resources security and access control, and MFA or continuous authentication.

How much does a NIS2 applicability assessment and gap analysis cost with Patronusec?

The cost depends on the number of jurisdictions in which the organisation operates, sector complexity and existing documentation (e.g. ISO 27001). After a free scope-assessment call we provide a fixed-price proposal. For organisations that already hold ISO 27001, we offer a dedicated ISO-NIS2 gap-analysis mapping that significantly reduces project time and cost.

How do you start working with Patronusec on NIS2?

The best starting point is a free 30-minute call in which we establish your sector, size and jurisdictions, identify classification risks and discuss the optimal implementation path. Contact us via the contact page or directly through the NIS2 service page.


NIS2 compliance – free scope assessment consultation

Patronusec delivers NIS2 applicability assessments and gap analyses for organisations in essential and important sectors. As an adviser with experience across DORA, ISO 27001 and PCI DSS, we help boards meet Articles 20 and 21 requirements without building from scratch.

In a free 30-minute consultation we will help you:

  • Establish whether your organisation is an essential entity, important entity or out of scope
  • Identify gaps between your current security posture and Article 21 requirements
  • Clarify which national laws apply in your operational jurisdictions
  • Plan the NIS2 implementation sequence for minimum effort and maximum regulatory coverage

Book a NIS2 consultation | NIS2 services | ISO 27001 | DORA compliance | vCISO

Don't buy a pig in a poke -
request a free consultation and check how we can assist you.

Free consultation
Contact form

Use the contact form or contact us directly.

Patronusec Sp z o. o.

Head Office:
ul. Święty Marcin 29/8
61-806 Poznań, Polska

KRS: 0001039087
REGON: 525433988
NIP: 7831881739
D-U-N-S: 989454390
LEI: 259400NAR8ZOX1O66C64

To top