Back to Publications
Regulatory Brief · NIS2

NIS2 Essential vs Important Entity: Classification Checklist + Penalty Cap Matrix

30 May 2026By NexCyber Editorial NIS2

NIS2 removes the old “operator of essential services” distinction and replaces it with two tiers—essential and important—based on sector, size, and systemic risk. Misclassification means either over-spending on compliance or facing enforcement that could reach 2 % of global turnover. This checklist gives CISOs, DPOs, and board members a single reference to determine their tier, understand the penalty caps, and meet the 17 October 2024 registration deadline.

NIS2 removes the old “operator of essential services” distinction and replaces it with two tiers—essential and important—based on sector, size, and systemic risk. Misclassification means either over-spending on compliance or facing enforcement that could reach 2 % of global turnover. This checklist gives CISOs, DPOs, and board members a single reference to determine their tier, understand the penalty caps, and meet the 17 October 2024 registration deadline.

---

1. Sector split: Annex I vs Annex II

NIS2 Annex I lists eleven “high-criticality” sectors; Annex II lists seven “other critical” sectors. Entities that fall under Annex I are automatically classified as essential if they meet the size threshold. Entities in Annex II are important unless they are explicitly designated as essential by the Member State.

1.1 Annex I – high-criticality sectors (essential if large)

  • Energy (electricity, district heating and cooling, oil, gas, hydrogen)
  • Transport (air, rail, water, road)
  • Banking (credit institutions)
  • Financial market infrastructures (trading venues, central counterparties)
  • Health (healthcare providers, EU reference laboratories)
  • Drinking water (suppliers and distributors)
  • Waste water (collectors, treatment plants, dischargers)
  • Digital infrastructure (IXPs, DNS providers, TLD registries, cloud computing, data centres, content-delivery networks, trust service providers, public electronic communications networks and services)
  • ICT service management (managed service providers, managed security service providers)
  • Public administration (central government, regional critical entities)
  • Space (ground-based infrastructure operated or provided by Member States or private parties that support the provision of space-based services)

1.2 Annex II – other critical sectors (important unless designated essential)

  • Postal and courier services
  • Waste management
  • Manufacture, production and distribution of chemicals
  • Production, processing and distribution of food
  • Manufacturing of medical devices, computers and electronics, machinery, motor vehicles, transport equipment
  • Digital providers (online marketplaces, online search engines, social networking platforms)

1.3 Sector-specific notes

  • Digital infrastructure: cloud computing, data centres, CDNs, and trust service providers are in Annex I; SaaS and PaaS providers that do not meet the Annex I definitions fall under the Digital Services Act, not NIS2.
  • Health: only EU reference laboratories and healthcare providers that are “critical” (typically hospitals with emergency departments) are in Annex I; smaller clinics and pharmacies are out of scope.
  • Food: the entire supply chain is in Annex II, but only entities that process or distribute food for human consumption at scale are in scope.
  • Manufacturing: only the specific sub-sectors listed in Annex II are covered; general manufacturing is out of scope.

---

2. Size thresholds: 250+ employees AND 50 M EUR turnover

NIS2 uses the EU SME definition (Commission Recommendation 2003/361/EC) but inverts it: only entities that exceed both thresholds are “large” and therefore essential if they operate in an Annex I sector.

MetricLarge (essential if Annex I)Medium (important if Annex II)Small (out of scope)
Employees≥ 25050–249< 50
Annual turnover≥ 50 M EUR10–50 M EUR< 10 M EUR
Annual balance-sheet total≥ 43 M EUR< 43 M EUR< 10 M EUR

Key points

  • The thresholds are cumulative: an entity must exceed both the employee and the turnover threshold to be large.
  • Balance-sheet total is only relevant if the entity is close to the turnover threshold; if turnover is clearly above 50 M EUR, the balance-sheet test is not needed.
  • Group consolidation: if the entity is part of a group, the thresholds are calculated at the highest level of consolidation within the EU (NIS2 Article 2(1)).
  • Micro-enterprises (< 10 employees and < 2 M EUR turnover) are always out of scope, even if they operate in an Annex I sector.

---

3. Classification flowchart (Mermaid)

graph TD
    A[Start] --> B{Operates in<br>Annex I sector?}
    B -->|Yes| C{Meets large-size<br>thresholds?}
    B -->|No| D{Operates in<br>Annex II sector?}
    C -->|Yes| E[Essential entity]
    C -->|No| F[Out of scope]
    D -->|Yes| G{Meets medium-size<br>thresholds?}
    D -->|No| H[Out of scope]
    G -->|Yes| I[Important entity]
    G -->|No| J[Out of scope]
    E --> K[Register with CSIRT &<br>competent authority by<br>17 October 2024]
    I --> K

---

4. Penalty cap matrix: 10 M EUR / 2 % vs 7 M EUR / 1.4 %

NIS2 Article 34 sets harmonised administrative fines that competent authorities must impose (minimum 50 % of the cap). The caps are per infringement, not per year.

Entity tierFixed cap (EUR)% of global turnover capExample calculation (2023 turnover = 800 M EUR)
Essential10 000 0002 %min(10 000 000, 16 000 000) = 10 000 000
Important7 000 0001.4 %min(7 000 000, 11 200 000) = 7 000 000

Additional consequences

  • Essential entities: competent authorities may impose interim measures (Article 32) and binding instructions (Article 33) before a fine is issued.
  • Important entities: interim measures are possible, but binding instructions are not explicitly listed in Article 33 for important entities.
  • Criminal liability: NIS2 does not harmonise criminal sanctions; Member States may introduce them under national law (Article 34(6)).

---

5. Supervisory regime differences: ex-ante vs ex-post

AspectEssential entityImportant entity
Supervision modelEx-ante (continuous)Ex-post (reactive)
Security auditsMandatory every 2 years (Article 21(2))Only after incident or suspicion
Incident reportingWithin 24 h (early warning), 72 h (report)Within 24 h (early warning), 72 h (report)
Vulnerability disclosureMandatory (Article 21(3))Mandatory (Article 21(3))
Supply-chain securityMandatory (Article 21(2)(d))Mandatory (Article 21(2)(d))
Board trainingMandatory (Article 20)Mandatory (Article 20)
CSIRT cooperationDirect access to CSIRT network (Article 12)Access via competent authority

Key takeaway Essential entities face proactive supervision: competent authorities can conduct on-site inspections, request documentation, and issue binding instructions without prior evidence of non-compliance. Important entities are only supervised after an incident or a justified suspicion.

---

6. Self-classification template and registration deadlines

6.1 Self-classification template (Excel / CSV)

FieldDescription
Legal nameFull registered name
LEI / VAT numberLegal Entity Identifier or VAT number
SectorAnnex I or Annex II sector (pick one)
Sub-sectorSpecific sub-sector (e.g., “electricity transmission”)
Employees (FTE)Full-time equivalent employees (group consolidated)
Annual turnover (EUR)Group consolidated turnover
Annual balance-sheet totalGroup consolidated balance-sheet total (if turnover < 55 M EUR)
Size classificationLarge / Medium / Small
NIS2 tierEssential / Important / Out of scope
Competent authorityName of the national authority (see ENISA list)
CSIRT contactName and email of the CSIRT or single point of contact
Registration deadline17 October 2024 (essential) or 17 April 2025 (important)

6.2 Registration deadlines

  • Essential entities: must register with the competent authority and the CSIRT by 17 October 2024 (NIS2 Article 27(1)).
  • Important entities: must register by 17 April 2025 (NIS2 Article 27(2)).
  • New entities: must register within