Pragmatic NIS2 Compliance for Medium-Sized Organizations

NIS2 Important Entities: Obligations and Compliance

Important entities under NIS2 must meet the same cybersecurity requirements as essential entities under Article 21, with reactive supervision and fines up to EUR 7 million. We guide you through classification, registration, and cost-effective compliance implementation.

  • Cost-effective NIS2 compliance for Important Entities
  • Pragmatic cybersecurity measures
  • Efficient incident response processes
  • Flexible security architectures

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

  • Your strategic goals and objectives
  • Desired business outcomes and ROI
  • Steps already taken

Or contact us directly:

Certifications, Partners and more...

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

NIS2 Important Entities: Classification and Requirements

Why ADVISORI

  • Specialized expertise for medium-sized organizations
  • Cost-effective and practical solution approaches
  • Proportional implementation strategies for Important Entities
  • Continuous support for compliance optimization

Compliance Notice

Although Important Entities are subject to less stringent supervisory measures than Essential Entities, they must still implement appropriate cybersecurity measures and can be sanctioned for violations.

ADVISORI in Numbers

11+

Years of Experience

120+

Employees

520+

Projects

We develop customized, proportional compliance strategies that meet the specific needs and resources of Important Entities.

Our Approach:

Assessment of Important Entity status and proportional requirements

Risk assessment focusing on business-critical assets

Development of cost-effective security measures

Implementation of lean governance structures

Establishing sustainable monitoring and reporting

"Important Entities need pragmatic cybersecurity solutions that ensure compliance without compromising operational flexibility. ADVISORI supports medium-sized organizations in finding the right balance between security and efficiency."
Sarah Richter

Sarah Richter

Head of Information Security, Cyber Security

Expertise & Experience:

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Our Services

We offer you tailored solutions for your digital transformation

Important Entity Compliance Assessment

Comprehensive assessment of your compliance status and development of a customized implementation strategy.

  • Detailed analysis of your Important Entity status
  • Assessment of proportional security requirements
  • Gap analysis of existing cybersecurity measures
  • Development of cost-effective implementation roadmap

Proportional Cybersecurity Measures

Implementation of appropriate security solutions that match your specific requirements and resources.

  • Development of flexible security architectures
  • Implementation of cost-effective security technologies
  • Building lean incident response processes
  • Establishing continuous monitoring and improvement

Our Competencies

Choose the area that fits your requirements

NIS2 Cross-Border Cooperation

The NIS2 Directive requires effective cross-border cooperation mechanisms for critical infrastructures. We support you in the strategic implementation of coordinated security measures and incident response procedures at the EU level.

NIS2 Essential Entities

Essential entities under NIS2 face the strictest cybersecurity requirements: active supervisory oversight, fines up to EUR 10 million, and full Article 21 compliance. We support you through classification, registration, and complete implementation.

NIS2 Reporting Requirements

The NIS2 Directive requires essential and important entities to report significant cybersecurity incidents in three stages. We help you build legally compliant incident reporting processes with clear 24h and 72h deadline management.

Frequently Asked Questions about NIS2 Important Entities

What are NIS2 important entities?

Important entities under NIS 2 are: 1. Medium-sized organizations in critical sectors from Annex II such as postal, waste management, food, chemicals, and digital providers, with at least

50 employees or at least EUR

10 million in annual turnover; 2. Medium-sized organizations from Annex I sectors with 50–249 employees or EUR 10–50 million in turnover that do not qualify as essential. Important entities face identical Article

21 requirements but only reactive supervision.

What is the difference between essential and important entities under NIS2?

The key difference lies in supervision intensity and fines: Essential entities face active supervision meaning authorities can proactively audit them. Important entities face only reactive supervision triggered by specific incidents or complaints. Fines for essential entities: up to EUR

10 million or 2% of global annual turnover. Fines for important entities: up to EUR

7 million or 1.4% of annual turnover. The security requirements under Article

21 are identical for both categories, only enforcement differs.

What obligations do important entities have under NIS2?

Important entities must: 1. Register with the competent authority such as BSI in Germany, 2. Implement all ten security measures from Article

21 NIS 2 including risk analysis, incident handling, BCM, supply chain security, MFA, and cryptography, 3. Report significant cybersecurity incidents within 24h and 72h deadlines, 4. Conduct management cybersecurity training per Article 20, 5. Establish an NIS2-compliant governance structure. Unlike essential entities, they are not proactively audited.

How am I classified as an important entity under NIS2?

You are an important entity if you operate in an NIS 2 sector and meet the size thresholds for important but not essential entities. Self-classification follows these steps: 1. Sector check against NIS 2 Annexes I and II, 2. Size check using the EU SME definition of employees and turnover or balance sheet, 3. Review of automatic classifications for critical infrastructure operators and trust service providers, 4. Registration with the competent authority. Errors in self-classification can lead to fines, so professional legal and technical guidance is recommended.

NIS2 fines for important entities: how high?

For important entities, competent authorities can impose fines of up to EUR

7 million or 1.4% of total global annual turnover, whichever is higher. Personal liability of management under Article

20 applies in principle to important entities as well, though national implementations vary. Reactive supervision does not mean violations go unpunished, reporting deadline violations or incidents can trigger enforcement proceedings and fines.

How does NIS2 self-classification work?

NIS 2 self-classification involves four steps: 1. Sector check against NIS 2 Annexes I and II to identify which annex applies, 2. Size check per EU SME definition covering employee count and annual turnover or balance sheet total, 3. Check for automatic classifications such as critical infrastructure operators and qualified trust service providers, 4. Registration with the competent national authority specifying entity category. Professional legal and technical support for self-classification is strongly recommended to avoid compliance gaps and potential enforcement action.

Success Stories

Discover how we support companies in their digital transformation

Digitalization in Steel Trading

Steel trading company from Germany

Digital Transformation in Steel Trading

Case Study

Results

Over 2 billion euros in annual revenue through digital channels
More than half of revenue through online channels as a strategic goal
Improved customer satisfaction through automated processes

AI-Powered Manufacturing Optimization

Industrial group from Germany

Smart Manufacturing Solutions for Maximum Value Creation

Case Study

Results

Significant increase in production performance
Reduction of downtime and production costs
Improved sustainability through more efficient resource utilization

AI Automation in Production

Automation specialist from Germany

Intelligent Networking for Future-Proof Production Systems

Case Study

Results

Improved production speed and flexibility
Reduced manufacturing costs through more efficient resource utilization
Increased customer satisfaction through personalized products

Generative AI in Manufacturing

Technology group from Germany

AI Process Optimization for Improved Production Efficiency

Case Study

Results

Reduction of AI application implementation time to just a few weeks
Improvement in product quality through early defect detection
Increased manufacturing efficiency through reduced downtime

Let's

Work Together!

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance