NIS 2 introduces a two-tier classification system that determines the supervision regime, penalty levels, and certain obligations that apply to covered organizations. Understanding whether your organization is an Essential Entity or an Important Entity is the first step in scoping your NIS 2 compliance program. This guide explains the classification criteria, practical differences, and steps to determine your entity type.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
Monthly billing · cancel anytime · 30-day money-back guarantee
Yes. Member states can designate organizations as Essential regardless of the default classification rules if their disruption would have significant national or cross-border impact. Additionally, if your organization grows beyond the large entity size threshold, your classification would change. Monitor your member state's designations and reassess when your organization experiences significant growth.
Absolutely. Reactive supervision means authorities investigate based on triggers such as incidents, complaints, or information from other sources. When an investigation occurs, non-compliance is assessed against the full Article 21 requirements. Organizations that have not implemented proper measures face penalties up to 7 million euros. Reactive supervision is not lax supervision.
If your organization provides services in multiple sectors, you may be classified differently for each service. For compliance purposes, the most stringent classification typically applies to the organization overall. Work with legal counsel to map your services to NIS 2 sectors and determine the appropriate classification for each.
NIS 2 applies the size thresholds at the entity level, but group relationships can affect the turnover calculation. The directive references the SME Recommendation criteria which considers partner and linked enterprises. Large corporate groups should assess applicability for each legal entity providing services in covered sectors, considering group turnover for threshold calculations.
You report to the competent authority in the member state where you provide your services. If you provide services in multiple member states, you report to the authority in each relevant member state. For certain digital infrastructure providers, NIS 2 establishes jurisdiction based on the main establishment, similar to GDPR's lead supervisory authority concept.
NIS 2 classification does not directly change your ISO 27001 scope, but it may inform scope decisions. If your organization is classified as Essential, the heightened supervision and penalty exposure may justify expanding your ISMS scope to cover all services in the NIS 2 scope. Many organizations align their ISO 27001 and NIS 2 scopes for efficiency.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
PoliWriter creates all the policies you need for NIS 2 Directive compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free