Essential entities under NIS2

The NIS2 directive must improve the cybersecurity and resilience of essential and important services in the European Union. The Netherlands is transposing this directive into the Cybersecurity Act, which will enter into force on August 15, 2026, and will apply to governments and thousands of companies.

What makes an entity essential?

An entity is essential when it is large and active in a designated sector. According to the NIS2 directive, large means:
Some organizations are always classified as essential, even without meeting these size requirements. Consider trust service providers and certain providers of digital infrastructure. The complete overview of exceptions and thresholds can be found at the National Coordinator for Security and Counterterrorism..

The eleven sectors of high criticality

Large organizations in one of these eleven sectors are usually classified as an essential entity:
EnergyTransportBankingFinancial market infrastructureHealthcareDrinking waterWaste waterDigital infrastructureICT management (B2B)GovernmentSpace
Do you want to know exactly what applies to your own sector, including specific obligations and points of attention? View the full details per sector.

What does it mean to be an essential entity?

The difference compared to an important entity lies mainly in supervision and sanctions:

Proactive supervision

The supervisor actively monitors, even without indications of a violation.

High fines

Up to 10 million euros, or 2 percent of the global annual turnover.

Personal management ban

As an ultimate sanction, a director can be temporarily suspended. Rarely used, but it is a genuine power.

The complete overview of fines and sanctions under NIS2 can be found on our Fines and sanctions.

Are you an essential entity?

Be sure of where you stand and what is expected of your organization. We are happy to think along with you about the steps to take.