- Meaning
- In scope of NIS2, but not “essential”
- Sectors
- Post, waste, chemicals, food, manufacturing and others
- Supervision
- Mainly reactive (trigger-based)
- Fines
- At least EUR 7 million or 1.4 % of annual turnover
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is an important entity?
Important entities come from sectors such as postal and courier services, waste management, the production of and trade in chemicals, food, or manufacturing. They are subject to NIS2 in full, but count as somewhat less systemically critical than essential entities. The category is the second of the two entity classes and captures a great many mid-sized operations that have never faced sector-specific cybersecurity regulation before.
Which sectors count? (Annex II)
The core of the important entities is formed by the “other critical sectors” in Annex II to the NIS2 Directive. If you operate there above the relevant thresholds – as a rule medium-sized enterprises with 50 or more employees or EUR 10 million in turnover – you typically fall into this class:
- Postal and courier services
- Waste management
- Manufacture, production and trade in chemicals
- Production, processing and distribution of food
- Manufacturing / production of goods – medical devices, computing equipment, electronics, machinery or motor vehicles, for example
- Digital providers – online marketplaces, search engines, social networking platforms
- Research organisations
Same duties, different supervision. Your sector decides the classification, not the scope of the security measures. A food manufacturer from Annex II has to take the same technical and organisational precautions as an energy supplier from Annex I – it is simply checked when there is a reason to, rather than in advance. The highly critical sectors in Annex I, by contrast, usually lead to classification as an essential entity, where supervision is proactive and the level of fines is higher.
Same duties, different supervision
The substantive duties – Risk management, reporting obligations along the 24h/72h/one-month chain and Governance exercised by the management body – are largely identical to those of essential entities. The registration duty and the training duty for senior management apply unchanged as well. The central difference lies in supervision: important entities are supervised reactively – that is, on the occasion of an incident or where there are concrete indications – and not proactively through routine, pre-announced inspections. The competent authority therefore only acts once there is some sign of a failure.
A lower level of fines
The level of fines is lower too: Article 34 sets a minimum ceiling of EUR 7 million or 1.4 % of total worldwide annual turnover – against EUR 10 million or 2 % for essential entities. In each case the higher of the two amounts applies, and Member States may set higher amounts. Even at the lower level, substantial sanctions remain possible, and senior management stays responsible for the measures.
Do not underestimate it
“Important” does not mean “less obliged”. The technical and organisational measures have to be implemented in full; only the intensity of the checks is lower. The reactive approach to supervision tempts some operations into assuming they can put measures off until somebody comes to look – but anyone who only starts on documentation, risk analysis and reported processes after a security incident has already lost the evidence of proper precautions, and risks a fine at exactly the moment the authority takes a closer look.
An example makes this clear. A waste disposal operator with 90 staff classifies itself as an important entity and attends to its registration duty with the body its Member State has designated, in the form and by the date set there. It establishes the same risk analysis and the same reporting process as an essential operator and documents its measures carefully – but expects checks only when there is a reason for them, rather than unannounced audits.
Next steps
In concrete terms, important entities should work through these points:
- Check your classification: compare your sector (Annex II) with your size class – does “important” fit, or is it “essential” after all?
- Complete your registration: the body, the form and the deadline are set by your Member State; where that date has passed, the duty stays in place and late registration is still required.
- Set up risk management: introduce technical and organisational measures and document them in audit-proof form.
- Set up the reporting chain: define processes for the 24-hour, 72-hour and one-month deadlines.
- Involve senior management: complete the training – the liability of the management body remains.
Further reading: European Commission – NIS2 Directive
Frequently asked questions
What is an important entity?
An important entity is an organisation in scope of NIS2 that is not classed as an essential entity. It usually comes from the other critical sectors under Annex II to the directive, such as post, waste management, chemicals, food or manufacturing. As a rule it covers medium-sized enterprises with 50 or more employees or more than EUR 10 million in turnover. The directive has applied since 18 October 2024.
What fines apply to important entities?
For important entities, Article 34 of NIS2 sets a minimum ceiling of at least EUR 7 million or 1.4 % of total worldwide annual turnover, whichever is higher, and Member States may set higher amounts. That is lower than for essential entities, where the minimum ceiling is EUR 10 million or 2 % of turnover. Even at the lower level, substantial sanctions remain possible, and the management body stays responsible for the risk measures.
Are the duties lighter than for essential entities?
No. The substantive security and reporting duties of important entities are largely identical to those of essential entities, including risk management, the registration duty and the reporting chain of a 24-hour early warning, a 72-hour notification and a one-month final report. What is lighter is above all the intensity of supervision, which is reactive and trigger-based rather than proactive, and the level of fines, with a minimum ceiling of EUR 7 million or 1.4 % of turnover.