Who is in scope: essential and important entities
NIS2 requires organizations to determine if they fall within the scope of "Essential" or "Important" entities based on their sector, size, and criticality. This classification determines whether an organization is subject to proactive supervision (Essential) or reactive supervision (Important), as well as the applicable enforcement regimes.
What it means
The directive shifts from a purely sectoral approach to a hybrid model that considers both the type of service provided and the size of the entity. Entities are categorized into two tiers: "Essential" entities (typically those in high-criticality sectors like energy, transport, health, and digital infrastructure) and "Important" entities (such as postal services, waste management, or chemicals).
In practice, most medium-sized enterprises and larger organizations within these listed sectors are automatically in scope. However, the directive allows Member States to designate smaller entities as "Essential" if they provide a service that is critical to the economy or society, regardless of their size.
While both categories must implement the same baseline cybersecurity risk-management measures, the primary difference lies in oversight. Essential entities face stricter, proactive supervision (e.g., scheduled audits), whereas Important entities are generally subject to ex-post supervision triggered by incidents or complaints.
How to meet it
- Review Annex I and Annex II of the Directive against your organization's business activities to identify which sector you fall under.
- Assess your company size (employee headcount and annual turnover/balance sheet) using EU definitions for medium-sized enterprises and larger to determine if you automatically qualify.
- Check national implementing legislation in each Member State where you operate, as countries may have expanded the list of sectors or adjusted thresholds.
- Verify with national competent authorities whether your organization has been specifically designated as a "critical entity" regardless of size.
- Formally document the classification process and result (Essential vs. Important) within your corporate governance records.
Evidence an auditor asks for
- A formal Scope Determination Document that maps business functions to Annex I or II sectors.
- Evidence of company size verification (e.g., financial statements or HR headcount reports) used to justify the classification.
- Written confirmation or registration documents from the national regulatory authority confirming your status.
- A record of the internal decision-making process (e.g., board minutes or compliance memos) where the scope was analyzed and signed off.
Common pitfalls
- Assuming that "Important" entities are exempt from security requirements; both tiers must implement the risk-management measures outlined in Article 21.
- Relying exclusively on the EU Directive text rather than the specific national laws of the Member State, which is where actual enforcement and precise thresholds reside.
- Overlooking the "criticality" clause, leading small companies to believe they are out of scope when they have been designated as Essential by a government body.