Important Entities (NIS2)

Organisations with NIS2 obligations but less strict than essential entities.

Important Entities are organisations designated under the NIS2 Directive that provide important digital services or critical infrastructure support services. These include cloud service providers, DNS service providers, and other digital service providers that support business operations across the EU.

Important Entities face less stringent requirements than Essential Entities under NIS2 but must still implement appropriate security measures, incident reporting procedures, and supply chain risk management. The differentiation recognises the varying criticality of services provided.

Frequently asked questions

What are important entities under NIS2?
Important entities are organisations that fall under NIS2 obligations but are subject to lighter supervision than essential entities.
What is the difference between essential and important entities?
Both must meet the same NIS2 security and reporting obligations, but essential entities face both proactive (ex-ante) and reactive supervision, while important entities face only reactive (ex-post) supervision, triggered by indications of non-compliance.
How do you know if you are an important entity?
Important entities are medium-sized organisations in the high-criticality (Annex I) sectors, and medium or large organisations in the other critical (Annex II) sectors — unless they are specifically designated as essential.