- Meaning
- A company or organisation in scope of NIS2
- Categories
- Essential and important entities
- Criteria
- Sector + size (employees/turnover)
- Relevance to NIS2
- A core term of the directive
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is an entity in the NIS2 context?
NIS2 deliberately avoids the word “companies” and speaks instead of entities and means more than private firms: public authorities, associations and other organisations can be covered too. An entity is therefore any legal person or organisational unit that falls within the scope of the directive. The term is the central anchor of the whole framework: only once it is settled that an organisation is an entity within the meaning of NIS2 do the duties on risk management, reporting and governance apply.
When are you an entity?
Two factors decide it: belonging to a regulated sector (energy, health, transport, digital infrastructure or waste management, for example) and your size. As a rule the threshold starts at 50 employees or an annual turnover and balance sheet total above EUR 10 million. In some areas – DNS services, qualified trust services or public administration, for instance – the duty applies regardless of size.
Essential or important?
NIS2 splits the organisations it covers into two classes: essential entities (supervised more strictly and proactively) and important entities (checked mainly when there is a reason to). The classification determines above all how close the supervision is and how high the fines can go – Article 34 sets minimum ceilings of EUR 10 million or 2 % of turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts. The substantive security duties, by contrast, are largely the same.
First step: check whether you are in scope
Whether you are an entity within the meaning of NIS2 is settled by a structured scope assessment: sector allocation, size threshold and special cases are documented. In concrete terms: A mid-sized food manufacturer with 120 staff and EUR 30 million in turnover checks whether it falls within the annexes, classifies itself as an important entity and then attends to its registration duty without delay, using the portal and the deadline that apply in its own Member State. Only after this classification can duties and deadlines be implemented with any certainty. The self-assessment rests with the entity itself.
Further reading: European Commission – NIS2 Directive
Frequently asked questions
What is an entity under NIS2?
Entity is the umbrella term NIS2 uses for every organisation that falls under the directive – so not only private companies, but also public authorities, associations and other public bodies in a regulated sector. Only once it is settled that an organisation is an entity within the meaning of NIS2 do the duties on risk management, reporting and governance apply. The directive has applied since 18 October 2024, and what makes it binding on you is the transposing act of your own Member State.
When do you fall under NIS2 as an entity?
You fall under NIS2 as an entity when you belong to a regulated sector and reach the size thresholds – as a rule from 50 employees, or an annual turnover and balance sheet total above EUR 10 million. In some areas, such as DNS services, qualified trust services or public administration, the duty applies regardless of size. The assessment rests with the entity itself. Registration is then handled nationally: the body you sign up with and the deadline that binds you are set by your Member State.
What types of entity are there?
NIS2 distinguishes two classes: essential entities, which are supervised proactively, and important entities, which are checked mainly when there is a reason to. The classification determines above all how close the supervision is and how high the fines can go – Article 34 sets minimum ceilings of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts. The substantive security duties, by contrast, are largely identical.