Important entities under the NIS2

In addition to essential entities, the NIS2 directive also recognizes important entities. They fall under the same Cybersecurity Act, with largely the same obligations, but with different supervision and lower maximum fines.

What makes an entity important?

Most organizations covered by NIS2 are important entities. You are usually important in these situations:
Are you in doubt between essential and important? View the distinction on our page about essential entities, or consult the National Coordinator for Security and Counterterrorism. for the complete overview.

The seven other critical sectors

Organizations in these sectors are usually classified as important entities, regardless of whether they are medium-sized or large:
Postal and courier servicesWaste managementChemicalsFoodManufacturing of critical productsDigital providersResearch organizations
A medium-sized organization in one of the eleven sectors of high criticality, such as energy or healthcare, also falls into this category.

What does it mean to be an important entity?

Supervision is lighter than for essential entities, but the obligations remain largely the same:

Reactive supervision

The supervisor intervenes after an incident, complaint, or concrete indication.

Lower fines

Up to 7 million euros, or 1.4 percent of the global annual turnover.

Equal basic obligations

Risk management, reporting obligation, and executive responsibility apply just as with essential entities.

The complete overview of fines and sanctions under NIS2 can be found on our Fines and sanctions.

Are you an important entity?

Even if supervision is reactive, preparation is wise. We are happy to think along with you about the steps to take.