What is the NIS2?
The Network and Information Security directive, or NIS2 directive, is intended to improve the cybersecurity and resilience of essential and important services in EU member states. This directive is currently being transposed into national law and will enter into force sometime in 2025 and will apply to governments and at least 30,000 companies.
This page contains an overview of the Essential Entities as named in the NIS2.
These are large organizations that are active in a sector from the table below. An organization is large based on the following criteria:
- At least 250 employees or;
- An annual turnover of €50 million or more and a balance sheet total of €43 million or more.
Sector | Subsector | Type of entity |
1. Energy | (a) Electricity | — Electricity undertakings as defined in Article 2, point (57), of Directive (EU) 2019/944 of the European Parliament and of the Council (1), which carry out the function of ‘supply’ as defined in Article 2, point (12), of that Directive |
— Distribution system operators as defined in Article 2, point (29), of Directive (EU) 2019/944 | ||
— Transmission system operators as defined in Article 2, point (35), of Directive (EU) 2019/944 | ||
— Producers as defined in Article 2, point (38), of Directive (EU) 2019/944 | ||
— Nominated electricity market operators as defined in Article 2, point (8), of Regulation (EU) 2019/943 of the European Parliament and of the Council (2) — Market participants as defined in Article 2, point (25), of Regulation (EU) 2019/943 providing aggregation, demand response or energy storage services as defined in Article 2, points (18), (20) and (59), of Directive (EU) 2019/944 — Operators of a recharging point that are responsible for the management and operation of a recharging point, which provides a recharging service to end users, including in the name and on behalf of a mobility service provider | ||
(b) District heating and cooling | — Operators of district heating or district cooling as defined in Article 2, point (19), of Directive (EU) 2018/2001 of the European Parliament and of the Council (3) | |
(c) Oil | — Operators of oil transmission pipelines | |
— Operators of oil production, refining and treatment facilities, storage and transmission | ||
— Central stockholding entities as defined in Article 2, point (f), of Council Directive 2009/119/EC (4) | ||
(d) Gas | — Supply undertakings as defined in Article 2, point (8), of Directive 2009/73/EC of the European Parliament and of the Council (5) | |
— Distribution system operators as defined in Article 2, point (6), of Directive 2009/73/EC | ||
— Transmission system operators as defined in Article 2, point (4), of Directive 2009/73/EC | ||
— Storage system operators as defined in Article 2, point (10), of Directive 2009/73/EC | ||
— LNG system operators as defined in Article 2, point (12), of Directive 2009/73/EC | ||
— Natural gas undertakings as defined in Article 2, point (1), of Directive 2009/73/EC | ||
— Operators of natural gas refining and treatment facilities | ||
(e) Hydrogen | — Operators of hydrogen production, storage and transmission | |
2. Transport | (a) Air | — Air carriers as defined in Article 3, point (4), of Regulation (EC) No 300/2008 used for commercial purposes |
— Airport managing bodies as defined in Article 2, point (2), of Directive 2009/12/EC of the European Parliament and of the Council (6), airports as defined in Article 2, point (1), of that Directive, including the core airports listed in Section 2 of Annex II to Regulation (EU) No 1315/2013 of the European Parliament and of the Council (7), and entities operating ancillary installations contained within airports | ||
— Traffic management control operators providing air traffic control (ATC) services as defined in Article 2, point (1), of Regulation (EC) No 549/2004 of the European Parliament and of the Council (8) | ||
(b) Rail | — Infrastructure managers as defined in Article 3, point (2), of Directive 2012/34/EU of the European Parliament and of the Council (9) | |
— Railway undertakings as defined in Article 3, point (1), of Directive 2012/34/EU, including operators of service facilities as defined in Article 3, point (12), of that Directive | ||
(c) Water | — Inland, sea and coastal passenger and freight water transport companies, as defined for maritime transport in Annex I to Regulation (EC) No 725/2004 of the European Parliament and of the Council (10), not including the individual vessels operated by those companies | |
— Managing bodies of ports as defined in Article 3, point (1), of Directive 2005/65/EC of the European Parliament and of the Council (11), including their port facilities as defined in Article 2, point (11), of Regulation (EC) No 725/2004, and entities operating works and equipment contained within ports | ||
— Operators of vessel traffic services (VTS) as defined in Article 3, point (o), of Directive 2002/59/EC of the European Parliament and of the Council (12) | ||
(d) Road | — Road authorities as defined in Article 2, point (12), of Commission Delegated Regulation (EU) 2015/962 (13) responsible for traffic management control, excluding public entities for which traffic management or the operation of intelligent transport systems is a non-essential part of their general activity | |
— Operators of Intelligent Transport Systems as defined in Article 4, point (1), of Directive 2010/40/EU of the European Parliament and of the Council (14) | ||
3. Banking |
| Credit institutions as defined in Article 4, point (1), of Regulation (EU) No 575/2013 of the European Parliament and of the Council (15) |
4. Financial market infrastructures |
| — Operators of trading venues as defined in Article 4, point (24), of Directive 2014/65/EU of the European Parliament and of the Council (16) |
— Central counterparties (CCPs) as defined in Article 2, point (1), of Regulation (EU) No 648/2012 of the European Parliament and of the Council (17) | ||
5. Health |
| — Healthcare providers as defined in Article 3, point (g), of Directive 2011/24/EU of the European Parliament and of the Council (18) |
— EU reference laboratories referred to in Article 15 of Regulation (EU) 2022/2371 of the European Parliament and of the Council (19) | ||
— Entities carrying out research and development activities of medicinal products as defined in Article 1, point (2), of Directive 2001/83/EC of the European Parliament and of the Council (20) — Entities manufacturing basic pharmaceutical products and pharmaceutical preparations referred to in section C division 21 of NACE Rev. 2 — Entities manufacturing medical devices considered to be critical during a public health emergency (public health emergency critical devices list) within the meaning of Article 22 of Regulation (EU) 2022/123 of the European Parliament and of the Council (21) | ||
6. Drinking water |
| Suppliers and distributors of water intended for human consumption as defined in Article 2, point (1)(a), of Directive (EU) 2020/2184 of the European Parliament and of the Council (22), excluding distributors for which distribution of water for human consumption is a non-essential part of their general activity of distributing other commodities and goods |
7. Waste water |
| Undertakings collecting, disposing of or treating urban waste water, domestic waste water or industrial waste water as defined in Article 2, points (1), (2) and (3), of Council Directive 91/271/EEC (23), excluding undertakings for which collecting, disposing of or treating urban waste water, domestic waste water or industrial waste water is a non-essential part of their general activity |
8. Digital infrastructure |
| — Internet Exchange Point providers |
— DNS service providers, excluding operators of root name servers | ||
— TLD name registries | ||
— Cloud computing service providers | ||
— Data centre service providers | ||
— Content delivery network providers | ||
— Trust service providers | ||
— Providers of public electronic communications networks | ||
— Providers of publicly available electronic communications services | ||
9. ICT service management (business-to-business) |
| — Managed service providers — Managed security service providers |
10. Public administration |
| — Public administration entities of central governments as defined by a Member State in accordance with national law |
— Public administration entities at regional level as defined by a Member State in accordance with national law | ||
11. Space |
| Operators of ground-based infrastructure, owned, managed and operated by Member States or by private parties, that support the provision of space-based services, excluding providers of public electronic communications networks |