Essential or important entities: find out whether your SME falls under NIS2, in which category, and what changes in terms of obligations, supervision and fines. A practical guide.

NisPo helps an SME work out whether it is an essential or an important entity under NIS2

“But does it really apply to me? And if it does… am I essential or important?”

It is the first question I get asked. Let me untangle it here, in plain language and without sending you off to three different decrees. All it takes is a sector, a size and two minutes.

The two NIS2 categories

NIS2 doesn’t split the world into “in” and “out”. Whoever is in scope is classified into one of two categories:

  • Essential entities — the ones the State keeps the closest eye on.
  • Important entities — still in scope, but with lighter supervision.

Careful: the baseline obligations are the same for both. The risk-management measures and the notification of significant incidents apply in the same way. What changes are supervision and fines — we’ll get to that shortly.

The 3-step method

1. Are you in a covered sector?

NIS2 lists the sectors in two annexes:

  • Annex I — sectors of high criticality: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure (cloud, data centres, DNS, CDNs, electronic communications), B2B ICT service management (managed service providers), public administration, space.
  • Annex II — other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing (medical devices, electronics, machinery, motor vehicles), digital providers (online marketplaces, search engines, social networks), research.

If your business doesn’t fall into either annex, you are normally out. If you can see it here, carry on.

2. Are you above the size threshold?

This is where the size-cap rule comes in: in the listed sectors, as a general rule, only medium and large enterprises are in scope (thresholds from Recommendation 2003/361/EC):

  • Medium enterprise: 50 to 249 employees (turnover up to €50M).
  • Large enterprise: 250 employees or more (or turnover above €50M).
  • Micro and small enterprises (under 50 employees and €10M): normally out, with some exceptions.

3. Cross-check sector and size

Sector + size give you the category:

Annex I (high criticality)Annex II (other critical)
Medium enterprise (50–249)Important entityImportant entity
Large enterprise (≥250)Essential entityImportant entity

In one line: you are essential if you are a large enterprise in a sector of high criticality. In every other in-scope case you are important.

The “regardless of size” cases

As always, there are exceptions. Some entities are in scope even if they are small, because of the role they play: for example qualified trust service providers, top-level domain name registries and DNS service providers, some providers of electronic communications, parts of the public administration and entities already designated as critical under other regulations. If you are in one of these niches, your size won’t save you: check carefully.

What changes in practice

Knowing your category isn’t an academic exercise. It changes two concrete things:

  • Supervision. Essential entities are subject to proactive supervision (inspections and audits even without an incident). Important entities are subject to reactive supervision, triggered by evidence of non-compliance or after an incident.
  • Fines. The maximum is higher for essential entities than for important ones. In both cases we are talking about amounts that hurt: this is not a risk to file away.

What does not change: security measures, incident handling, the accountability of management bodies and — for both categories — the obligation to register on the ACN platform during the annual window.

What to do now

  1. Check your position with the 3 steps above and register (or update your details) on the ACN platform.
  2. Take stock of your controls: where you are compliant and where you have gaps.
  3. Collect the evidence and keep it ready for a possible audit.

You can do the first two steps by hand. The third is usually where everyone gets stuck — and that is exactly where I come in: I connect your Microsoft systems read-only, automatically check the technical controls I can read and keep every piece of evidence linked to its requirement. The full picture of the Italian obligations is on the NIS2 in Italy and ACN measures page. If you want to know where it all starts, I tell you who I am in the post NIS2 compliance without spreadsheets.


This article is for information only and does not constitute legal advice. The final classification depends on a specific assessment of your company and on ACN’s determinations: if in doubt, let’s talk.

Nispo automatically checks technical controls on Microsoft 365, Google Workspace, AWS and Google Cloud and organises everything else: ACN requirements, evidence, suppliers and remediation.