Glossary · Term

Essential entity explained

An essential entity is a particularly critical organisation under NIS2, with stricter requirements and a higher level of fines.

At a glance
Meaning
A particularly critical entity under NIS2
Sectors
Energy, health, banking, digital infrastructure and others
Supervision
Strict, and proactive
Fines
At least EUR 10 million or 2 % of annual turnover
Updated
June 2026
Editorial team
Compliance Compass

What is an essential entity?

Essential entities are organisations from particularly critical sectors such as energy, health, drinking water, banking, financial market infrastructure, transport or digital infrastructure. They count as the backbone of supply: if a cyberattack knocks out an entity of this kind, whole supply chains or essential public services can be hit. That is precisely why NIS2 places the strictest requirements on essential entities and assigns them to the highest tier of supervision and sanctions.

How you are classified

Classification depends on the sector – Annex I to the directive lists the “sectors of high criticality” – and on the size of the organisation. As a rule, large enterprises with 250 or more employees or more than EUR 50 million in turnover count as essential entities in those highly critical sectors. On top of that come special cases such as qualified trust service providers or TLD registries, which count as essential regardless of size.

How this differs from an important entity

The dividing line is sharp. Where an important entity is checked reactively, an essential entity is supervised proactively – that is, even without a particular trigger, for example through on-site inspections or security audits. The level of fines is higher too: Article 34 sets a minimum ceiling of EUR 10 million or 2 % of total worldwide annual turnover instead of EUR 7 million or 1.4 % for important entities, and Member States may go higher. The Management body carries responsibility for the risk measures and can be held personally liable.

Essential vs important, side by side

CriterionEssential entityImportant entity
Size thresholdLarge enterprises: 250 or more employees or > EUR 50 million turnover, in sectors of high criticality (Annex I)Medium-sized enterprises: 50 or more employees or > EUR 10 million turnover – plus large enterprises in the other critical sectors (Annex II)
SupervisionProactive – audits and inspections even without a particular triggerReactive – checks as a rule only where there are indications of a breach
Level of finesAt least EUR 10 million or 2 % of total worldwide annual turnover, whichever is higher (Article 34 minimum)At least EUR 7 million or 1.4 % of total worldwide annual turnover, whichever is higher (Article 34 minimum)

Note: the substantive security duties themselves – risk management, reporting channels, minimum technical measures – are almost identical for both categories. What differs is above all how hard and how early the authorities look.

Duties in practice

The substantive duties – Risk management, reporting obligations along the 24h/72h/one-month chain and Governance – resemble those of important entities, but are supervised more strictly. Picture a regional energy supplier with 400 staff that has to act after a ransomware incident: it has registered with the authority designated in its own Member State and named a contact point, reports the significant incident within 24 hours as an early warning, adds its assessment of the incident together with a first root-cause analysis after 72 hours, and files the final report within one month at the latest. Because it counts as an essential entity, it also has to reckon with unannounced evidence checks at any time.

What you actually have to do

Are you an essential entity? Then these are the steps that count:

Further reading: European Commission – NIS2 Directive

Frequently asked questions

What is an essential entity?

An essential entity is a particularly critical organisation from a sector of high criticality under Annex I to the NIS2 Directive, such as energy, health, drinking water, banking or digital infrastructure. It typically covers large enterprises with 250 or more employees or more than EUR 50 million in turnover. Essential entities carry the strictest duties, proactive supervision and the highest level of fines. The directive has applied since 18 October 2024.

What fines apply to essential entities?

For essential entities, Article 34 of NIS2 sets a minimum ceiling of at least EUR 10 million or 2 % of total worldwide annual turnover, whichever is higher, and Member States may set higher amounts. That is above the ceiling for important entities, which is at least EUR 7 million or 1.4 % of turnover. On top of that, the management body can be held personally liable for neglected risk measures, which is why senior management has to be actively involved.

How does an essential entity differ from an important one?

Essential entities are supervised proactively and without any particular trigger, for example through on-site inspections and security audits, and face higher sanctions (at least EUR 10 million or 2 %). Important entities are supervised reactively, that is only where there are indications of a breach, and face lower sanctions (at least EUR 7 million or 1.4 %). The substantive security and reporting duties along the 24h/72h/one-month chain are largely identical for both classes.

NIS2 classification

Ready for proactive supervision?

Essential entities are also inspected without notice. Compliance Compass keeps your classification, reporting chain and evidence ready to show at any time.