Glossary
Essential entity (NIS2)
An essential entity is, under the NIS2 directive, an organisation operating in a sector of high criticality and above the size thresholds set by the directive. It is subject to proactive supervision, unlike an important entity, which is supervised after the fact.
Essential or important: what changes
Both categories carry the same substantive obligations — risk management measures, supply chain security, notification of significant incidents, management accountability. The difference lies in supervision: essential entities face proactive controls (inspections, audits, evidence requests at the authority's initiative), important entities face controls triggered by an indication of non-compliance. Maximum penalties also differ.
The knock-on effect on vendors
A company outside the scope can still be affected in practice: its regulated customers must assess and govern their suppliers, and pass those requirements down through contracts and questionnaires. For a vendor, the challenge becomes the ability to answer quickly and with evidence. See NIS2 vendor compliance and the NIS2 page.
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours