Guide · NIS2

NIS2 compliance: who must comply, essential vs important entities, with the text

Updated 6 October 2026 · 8 min read

NIS2 asks two questions in order, whether the entity's type appears in Annex I or II, and whether it is at least medium-sized or meets one of the size-independent triggers in Article 2(2). Article 3 then sorts the in-scope entities into essential and important ones, and both classes take the same ten risk-management measures and report incidents on the same 24-hour, 72-hour and one-month clock.

For the purposes of this Directive, entities of a type referred to in Annex I or II which do not qualify as essential entities pursuant to paragraph 1 of this Article shall be considered to be important entities.

Official text on EUR-Lex · Open the source

The figure behind it

Article 3(3) set a dated deadline: by 17 April 2025, Member States had to establish a list of essential and important entities, reviewed at least every 2 years thereafter. Source: Directive (EU) 2022/2555 (NIS2), Article 3(3), EUR-Lex text as held by Rekvira (corpus of 2 September 2026)

NIS2 (Directive (EU) 2022/2555) is a directive, so what binds you day to day is your Member State's transposing law. The tests below are the Directive's own, as Rekvira returned them on 24 September 2026; national laws build on them.

Step one: is your type in Annex I or II?

Scope starts with the kind of activity, not with how important you feel. If your activity is not a type listed in Annex I or Annex II, the size tests below do not come into play.

Step two: are you big enough, or caught regardless of size?

The size test is Article 2(1):

"This Directive applies to public or private entities of a type referred to in Annex I or II which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed the ceilings for medium-sized enterprises provided for in paragraph 1 of that Article, and which provide their services or carry out their activities within the Union." (Article 2(1))

A small or micro entity of the same type is out under that test, but Article 2(2) brings entities in "regardless of their size" in six cases:

PointArticle 2(2): in scope regardless of size when
(a)The services are public electronic communications networks or services, trust services, or top-level domain name registries and DNS services
(b)The entity is "the sole provider in a Member State of a service which is essential for the maintenance of critical societal or economic activities"
(c)Disruption "could have a significant impact on public safety, public security or public health"
(d)Disruption "could induce a significant systemic risk", in particular with cross-border impact
(e)The entity is critical "because of its specific importance at national or regional level"
(f)It is a public administration entity of central government, or at regional level after a risk-based assessment
Article 2(2), points (a) to (f), as returned by read_unit on 24 September 2026.

Essential or important: what does Article 3 decide?

Article 3(1) lists the essential entities. The core is point (a), "entities of a type referred to in Annex I which exceed the ceilings for medium-sized enterprises", joined regardless of size by qualified trust service providers, top-level domain name registries and DNS service providers (point (b)), and by the public administration entities of Article 2(2)(f)(i) (point (d)). Member States can add more under points (e) to (g).

Everything else in scope is important:

"For the purposes of this Directive, entities of a type referred to in Annex I or II which do not qualify as essential entities pursuant to paragraph 1 of this Article shall be considered to be important entities." (Article 3(2))

The class changes how you are supervised, not what you must do. Important entities are supervised after the fact: competent authorities act "when provided with evidence, indication or information that an important entity allegedly does not comply", through "ex post supervisory measures" (Article 33(1)). Essential entities fall under the wider supervisory regime of Article 32.

Who decides your class?

Your Member State, on a list it had to build by a fixed date:

"By 17 April 2025, Member States shall establish a list of essential and important entities as well as entities providing domain name registration services. Member States shall review and, where appropriate, update that list on a regular basis and at least every two years thereafter." (Article 3(3))

The list is built from what entities report. Article 3(4) requires entities to submit at least their name, address and contact details (including IP ranges), their sector and subsector, and the Member States where they provide services, and to notify changes "within two weeks of the date of the change". Waiting to be told is not how the Directive works.

What does every in-scope entity have to do?

Article 21(2) sets the floor, an "all-hazards approach" with at least ten measures:

  1. Policies on risk analysis and information system security.
  2. Incident handling.
  3. Business continuity, including backup management, disaster recovery and crisis management.
  4. Supply chain security, including relationships with direct suppliers and service providers.
  5. Security in acquisition, development and maintenance, including vulnerability handling and disclosure.
  6. Policies and procedures to assess whether the measures work.
  7. Basic cyber hygiene and cybersecurity training.
  8. Cryptography and, where appropriate, encryption.
  9. Human resources security, access control and asset management.
  10. Multi-factor or continuous authentication and secured communications, where appropriate.

And a significant incident is reported on a clock:

  1. 24 hours

    Early warning, including whether the incident may be malicious or cross-border (Article 23(4)(a))

  2. 72 hours

    Incident notification with an initial assessment of severity and impact (Article 23(4)(b))

  3. On request

    Intermediate report on status updates (Article 23(4)(c))

  4. 1 month

    Final report after the incident notification (Article 23(4)(d))

  • 10

    minimum measures in Article 21(2)

  • 24 h

    to the early warning of a significant incident

  • 2 weeks

    to notify changes in the details you gave for the Member State list

Directive (EU) 2022/2555, Articles 3(4), 21(2) and 23(4), as returned by read_unit on 24 September 2026.

Recorded run

The question:Who must comply with NIS2, and is my organisation an essential or an important entity?

  1. get_workflow(workflow_id="nis2-essential-entity")

    Load the NIS2 scoping playbook.

  2. read_unit(regulation="nis2", kind="article", number="2")

    Scope, whole: the size test and the size-independent triggers.

    Article 2 whole, 14 paragraph pinpoints, including "Regardless of their size, this Directive also applies to entities of a type referred to in Annex I or II"

  3. read_unit(regulation="nis2", kind="article", number="3")

    Essential and important entities, and the Member State list.

    "By 17 April 2025, Member States shall establish a list of essential and important entities" and "within two weeks of the date of the change"

  4. read_unit(regulation="nis2", kind="paragraph", article="33", number="1")

    How important entities are supervised.

    "ex post supervisory measures"

  5. read_unit(regulation="nis2", kind="paragraph", article="21", number="2")

    The minimum risk-management measures every in-scope entity takes.

    "shall be based on an all-hazards approach" and "the use of multi-factor authentication or continuous authentication solutions"

  6. read_unit(regulation="nis2", kind="paragraph", article="23", number="4")

    The incident reporting deadlines.

    "within 24 hours of becoming aware of the significant incident, an early warning" and "a final report not later than one month after the submission of the incident notification"

  7. verify_citation(regulation="nis2", citation="Article 3(3)", quote="By 17 April 2025, Member States shall establish a list of essential and important entities")

    Check the list deadline before quoting it.

    Quote found for the Article 3(3) deadline.

Real calls to Rekvira’s production server, captured 24 September 2026. Corpus as of 2 September 2026.

Limits

Rekvira holds the Directive, not the national laws that transpose it, and national laws may widen scope or add duties. The sector descriptions in Annexes I and II and your Member State's list decide your position; Rekvira gives you the text to check them against.

Do this in your assistant

Use Rekvira to scope our organisation under NIS2. Read Articles 2, 3, 21 and 23. Tell me which Annex I or II type our activity matches, whether the size test or an Article 2(2) trigger applies, whether we would be essential or important under Article 3, and quote each passage you rely on.

Paste this into Claude, ChatGPT, Cursor or any MCP client connected to https://mcp.rekvira.com/mcp. No account is needed to start.Install steps for each client

Start with the keyless trial.

No account, no API key, and free during the beta.

https://mcp.rekvira.com/mcp