NIS2 sorts in-scope organisations into essential and important entities. The classification is decided by two things only: which annex your sector is in, and how big you are.
The short answer
NIS2 sorts in-scope organisations into **essential** and **important** entities. The classification is decided by two things only: **which annex your sector is in**, and **how big you are**.
``` essential large entities in an Annex I sector important medium-sized entities in an Annex I sector large and medium-sized entities in an Annex II sector ```
**The security obligations are the same for both.** Article 21's ten measures and Article 23's reporting deadlines apply identically. What differs is **how you are supervised** and **how much you can be fined**.
Most published summaries present this as a severity ranking. It is more useful to read it as **a difference in when the regulator arrives**: for essential entities, without being invited.
The size rule, precisely
NIS2 uses the EU definition of enterprise size categories.
``` large 250 or more staff OR turnover above EUR 50 m AND balance sheet above EUR 43 m medium 50 or more staff OR turnover and balance sheet above EUR 10 m below that generally out of scope ```
**Two traps sit in this rule.**
**First, the criteria are not all cumulative.** Reading only the headcount is the most common way an organisation concludes it is out of scope when it is not.
**Second, size is assessed for the enterprise, not the site.** Linked and partner enterprises are taken into account under the standard EU methodology, which means a subsidiary of a large group is rarely "small" in the sense the rule intends.
**Who is in scope regardless of size**
Certain entities are covered whatever their size — among them DNS service providers, top-level domain name registries, trust service providers, and providers of public electronic communications networks or publicly available electronic communications services.
Member States may also designate additional entities regardless of size — for example where an entity is the sole provider of a service that is critical for societal or economic activity, or where disruption could have a significant impact on public safety, security or health. **This designation power sits in national law**, which is one more reason the transposition is the text that matters.
What actually differs: supervision
This is the substantive distinction, and it is set out in Articles 32 and 33.
**Essential entities — supervised *ex ante***
Authorities may act **without any indication of non-compliance**. The toolkit includes on-site inspections, off-site supervision, regular and targeted audits, security scans, requests for information, and requests for access to data, documents and evidence of implementation of cybersecurity policies.
**In practice: an audit can arrive because you are an essential entity, not because something happened.**
**Important entities — supervised *ex post***
Authorities act **when there is evidence, indication or information** suggesting non-compliance — typically following an incident, a complaint, or a report.
**In practice: nothing arrives unless something prompts it.**
**The gap between the two regimes is a readiness gap, not a rulebook gap.** An important entity can operate a programme that would pass an inspection it will probably never receive. An essential entity has to be able to evidence the same programme **on request, on a date it does not choose** — which changes how documentation must be kept, not what it must contain.
What differs: penalties
Article 34 sets minimum ceilings for national law, expressed as the **higher** of the two figures:
``` essential entities at least EUR 10 000 000 or 2 % of total worldwide annual turnover important entities at least EUR 7 000 000 or 1.4 % ```
**These are floors for Member States, not caps.** A national transposition may set higher ceilings, which is why the applicable figure is the national one.
Authorities also have non-financial powers over essential entities that they do not have in the same form elsewhere — including temporarily suspending a certification or authorisation, and temporarily prohibiting an individual from exercising managerial functions.
How to determine your class without guessing
1. **Locate your activity in Annex I or Annex II**, using what the organisation actually does. Annex I covers energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (B2B), public administration and space. Annex II covers postal and courier services, waste management, chemicals, food, several manufacturing categories, digital providers and research. 2. **Apply the size rule to the enterprise**, including linked and partner enterprises. 3. **Check the size-independent categories** before concluding you are out. 4. **Read the national transposition** for additional designations and for the actual penalty ceiling. 5. **Where you operate in several Member States, do this once per State.** The Directive is the floor; the national act is the rule, and the classifications can differ.
**If the answer is genuinely borderline, prepare as an essential entity.** The obligations are identical; only the readiness posture differs. Being ready for an inspection that never comes costs documentation discipline. Not being ready for one that does costs the finding.
Tools available on NexCyber
- Free applicability assessment — confirm NIS2 scope and entity classification
- Compliance responsibility mapper — RACI by role
- Penalty calculator — exposure by regulation
Further reading
→ What is NIS2 → NIS2 incident reporting timelines → NIS2 implementation guide — eight steps → DORA × NIS2 — which instrument governs when both apply → NIS2 regulation overview
*This is regulatory information, not legal advice, and nothing here constitutes a compliance guarantee. NIS2 is a Directive: scope, additional designations and penalty ceilings are set by the national transposition in each Member State where you operate, and those texts differ. Verify against the applicable national law and consult your competent authority or a qualified adviser.*
This is an educational explainer. For the canonical regulation reference, see the dedicated NIS2 page — or run an assessment to see how it applies to your product.