- Meaning
- A particularly critical entity under NIS2
- Sectors
- Energy, health, banking, digital infrastructure and others
- Supervision
- Strict, and proactive
- Fines
- At least EUR 10 million or 2 % of annual turnover
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is an essential entity?
Essential entities are organisations from particularly critical sectors such as energy, health, drinking water, banking, financial market infrastructure, transport or digital infrastructure. They count as the backbone of supply: if a cyberattack knocks out an entity of this kind, whole supply chains or essential public services can be hit. That is precisely why NIS2 places the strictest requirements on essential entities and assigns them to the highest tier of supervision and sanctions.
How you are classified
Classification depends on the sector – Annex I to the directive lists the “sectors of high criticality” – and on the size of the organisation. As a rule, large enterprises with 250 or more employees or more than EUR 50 million in turnover count as essential entities in those highly critical sectors. On top of that come special cases such as qualified trust service providers or TLD registries, which count as essential regardless of size.
How this differs from an important entity
The dividing line is sharp. Where an important entity is checked reactively, an essential entity is supervised proactively – that is, even without a particular trigger, for example through on-site inspections or security audits. The level of fines is higher too: Article 34 sets a minimum ceiling of EUR 10 million or 2 % of total worldwide annual turnover instead of EUR 7 million or 1.4 % for important entities, and Member States may go higher. The Management body carries responsibility for the risk measures and can be held personally liable.
Essential vs important, side by side
| Criterion | Essential entity | Important entity |
|---|---|---|
| Size threshold | Large enterprises: 250 or more employees or > EUR 50 million turnover, in sectors of high criticality (Annex I) | Medium-sized enterprises: 50 or more employees or > EUR 10 million turnover – plus large enterprises in the other critical sectors (Annex II) |
| Supervision | Proactive – audits and inspections even without a particular trigger | Reactive – checks as a rule only where there are indications of a breach |
| Level of fines | At least EUR 10 million or 2 % of total worldwide annual turnover, whichever is higher (Article 34 minimum) | At least EUR 7 million or 1.4 % of total worldwide annual turnover, whichever is higher (Article 34 minimum) |
Note: the substantive security duties themselves – risk management, reporting channels, minimum technical measures – are almost identical for both categories. What differs is above all how hard and how early the authorities look.
Duties in practice
The substantive duties – Risk management, reporting obligations along the 24h/72h/one-month chain and Governance – resemble those of important entities, but are supervised more strictly. Picture a regional energy supplier with 400 staff that has to act after a ransomware incident: it has registered with the authority designated in its own Member State and named a contact point, reports the significant incident within 24 hours as an early warning, adds its assessment of the incident together with a first root-cause analysis after 72 hours, and files the final report within one month at the latest. Because it counts as an essential entity, it also has to reckon with unannounced evidence checks at any time.
What you actually have to do
Are you an essential entity? Then these are the steps that count:
- Document your self-classification: check your sector (Annex I) and your size class and record the result in writing – responsibility for the classification rests with you, not with the authority.
- Register with your national authority: which body you sign up with, in what form and by when is set by your Member State; where that date has already passed, the duty does not lapse and you should catch up without delay.
- Set up the reporting chain: define processes for the 24-hour early warning, the 72-hour assessment and the one-month final report, and rehearse them with your team.
- Involve the management body: senior management takes training, approves the risk measures and oversees their implementation – otherwise it is personally liable.
- Prepare for proactive audits: collect evidence without gaps, so that an unannounced inspection does not come up empty.
Further reading: European Commission – NIS2 Directive
Frequently asked questions
What is an essential entity?
An essential entity is a particularly critical organisation from a sector of high criticality under Annex I to the NIS2 Directive, such as energy, health, drinking water, banking or digital infrastructure. It typically covers large enterprises with 250 or more employees or more than EUR 50 million in turnover. Essential entities carry the strictest duties, proactive supervision and the highest level of fines. The directive has applied since 18 October 2024.
What fines apply to essential entities?
For essential entities, Article 34 of NIS2 sets a minimum ceiling of at least EUR 10 million or 2 % of total worldwide annual turnover, whichever is higher, and Member States may set higher amounts. That is above the ceiling for important entities, which is at least EUR 7 million or 1.4 % of turnover. On top of that, the management body can be held personally liable for neglected risk measures, which is why senior management has to be actively involved.
How does an essential entity differ from an important one?
Essential entities are supervised proactively and without any particular trigger, for example through on-site inspections and security audits, and face higher sanctions (at least EUR 10 million or 2 %). Important entities are supervised reactively, that is only where there are indications of a breach, and face lower sanctions (at least EUR 7 million or 1.4 %). The substantive security and reporting duties along the 24h/72h/one-month chain are largely identical for both classes.