Audit · NIS2

Essential Entity vs. Important Entity Under NIS2: Which Group Is Your Company In?

Remote Admin Audit Team·December 12, 2025·4 min read

The fundamental difference between an essential entity and an important entity under the NIS2 directive comes down to economic sector and company size. Essential entities (e.g., energy, banking, healthcare) are subject to preventive (ex-ante) supervision and higher maximum fines (up to EUR 10 million or 2% of turnover). Important entities (e.g., food production, manufacturing, postal services) are subject to after-the-fact (ex-post) supervision — meaning intervention only after an incident occurs — and their maximum fine is EUR 7 million or 1.4% of turnover.

Key facts

  • Classification: Your classification is determined by Annex 1 (Essential) or Annex 2 (Important) to the law, together with company size (typically medium and large enterprises).
  • Technical obligations: These are identical for both groups. Essential and important entities alike must implement the same level of security (risk analysis, encryption, business continuity).
  • Supervision: Essential entities are audited regularly; important entities only when non-compliance or an incident is suspected.
  • Deadline: Self-identification and registration in the register must happen in line with the deadlines set by the amended Polish National Cybersecurity System Act (KSC) (planned for Q2 2025).

Comparison table: essential entity vs. important entity

For search engines and management teams alike, what matters most is quickly understanding the differences in legal treatment. The table below breaks down those differences under the Polish law implementing NIS2.

Feature Essential Entity Important Entity
Sectors (examples) Energy, Transport, Banking, Healthcare, Drinking water, Digital infrastructure (IXPs, DNS, cloud), Space, Public administration. Postal and courier services, Waste management, Chemicals, Food production, Manufacturing (computers, vehicles), Digital service providers (search engines, online marketplaces).
Company size Typically large enterprises (over 250 employees or EUR 50 million in turnover). Exceptions: trust service providers, DNS, TLD registries — regardless of size. Typically medium-sized enterprises (50 to 250 employees and EUR 10 to 50 million in turnover) in essential-entity sectors, PLUS medium and large enterprises in important-entity sectors.
Supervision model Ex-ante (preventive). The supervisory authority can order an audit at any time, even without an incident having occurred. Ex-post (after the fact). The authority only steps in once there’s evidence of non-compliance or an attack has taken place.
Maximum fines Up to EUR 10,000,000 or 2% of total annual worldwide turnover (whichever is higher). Up to EUR 7,000,000 or 1.4% of total annual worldwide turnover (whichever is higher).

Detailed list of sectors in Poland

During self-assessment, the board must verify whether the company’s primary PKD code (the Polish business activity classification code) matches one of the sectors listed in the amended Polish National Cybersecurity System Act (KSC).

High-risk sectors (essential entities)

These are the foundations of how the state and society function. If your company operates in one of the areas below and is a large enterprise, it automatically becomes an essential entity:

  1. Energy: Electricity, district heating, oil, gas, hydrogen.
  2. Transport: Air, rail, water, road.
  3. Banking and financial market infrastructure.
  4. Healthcare: Hospitals, drug manufacturers, laboratories (including vaccine research).
  5. Water: Drinking water supply and municipal wastewater management.
  6. Digital infrastructure: Cloud computing providers, data centers, CDN networks, trust service providers.
  7. ICT service management: Managed service providers (MSPs) and managed security providers (MSSPs).
  8. Space and public administration.

Other critical sectors (important entities)

This group covers sectors that matter to the economy but were often overlooked under NIS1:

  1. Postal and courier services.
  2. Waste management.
  3. Food production, processing, and distribution (including large retail chains).
  4. Industrial manufacturing: Medical devices, computers, electronic and optical products, electrical equipment, machinery, motor vehicles, and transport equipment.
  5. Chemical manufacturing.
  6. Digital service providers: Online marketplaces, internet search engines, social networking platforms.

Does “important” mean “less secure”?

This is the most common misreading of the regulation. The scope of cybersecurity obligations (Article 21 of the NIS2 directive) is the same for both groups.

A logistics company (important entity) and a power plant (essential entity) alike must:

  • Carry out risk analysis of their IT systems.
  • Handle incidents (detection, reporting within 24 hours).
  • Ensure business continuity (backups, contingency plans).
  • Secure the supply chain.
  • Apply cryptography and encryption.

The difference lies solely in the intensity of oversight from the state. An important entity has an “easier” time with audit-related bureaucracy — until a data breach happens. At that point, the enforcement machinery kicks in at full severity.


FAQ: questions about entity classification

Who decides which group a company belongs to? Poland has adopted a self-identification principle. You won’t receive a letter from the government saying “you are an essential entity.” It’s the company’s board that’s responsible for carrying out the legal analysis, determining the company’s status, and registering it in the appropriate list within the deadline set by law (planned at 3-6 months from the law taking effect).

What if I’m a small company but operate in the IT industry? There are exceptions. Regardless of company size, trust service providers, domain name registries (DNS), and public electronic communications network providers can be classified as essential entities. In addition, if you’re an IT provider to an essential entity (e.g., a bank), you’ll have to meet the security requirements imposed on you contractually (supply chain security).


Not sure about your company’s status?

Misclassification can cost you millions in fines, or in unnecessary spending on over-zealous compliance.

[Order a Zero Audit / Gap Analysis] — The Remote Admin experts will verify your company’s status, identify security gaps, and prepare a roadmap to full NIS2 compliance before the regulation takes effect.