Skip to content
Topic Developing

NIS2 Addressees and Responsible Entities

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal β€” legal information, not advice.

The 'Addressees' section of NIS2 specifically identifies and defines the entities and authorities to whom the directive applies and who bear responsibility for compliance. This requires a dedicated topic covering the identification, classification, and designation procedures for all addressees under NIS2.

42 linked items 42 Laws

Overview

9 sources Β· Jul 23, 2026

Legal Framework

NIS2 establishes a two-tier classification system for its addressees through Article 3, dividing regulated entities into "essential entities" and "important entities." This classification is foundational to the entire directive, as it determines the scope of obligations, supervisory intensity, and maximum sanctions applicable to each entity.

Essential entities under Article 3(1) include operators in critical sectors such as energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management (B2B), public administration, and space. These entities are typically larger organizations exceeding defined size thresholds β€” generally employing 50 or more staff or exceeding €10 million in annual turnover β€” though Member States may designate smaller entities as essential where warranted by risk factors.

Important entities under Article 3(2) cover operators in important sectors including postal and courier services, waste management, chemicals, food, manufacturing of medical devices, computers and electronics, machinery, motor vehicles, and research. Entities in these sectors that meet the same size thresholds qualify as important entities and are subject to a somewhat lighter supervisory regime.

Article 34 establishes the general conditions for imposing administrative fines, differentiating the maximum penalties by entity classification. Essential entities face fines of up to €10 million or 2% of global annual turnover, whichever is higher. Important entities face fines of up to €7 million or 1.4% of global annual turnover. Management bodies bear personal accountability under Article 20, with potential temporary prohibitions on holding executive functions.

Key Developments

The Court of Justice of the European Union has shaped the interpretation of "establishment" and territorial scope through cases such as Google Spain v AEPD (C-131/12) and Weltimmo (C-230/14), establishing that even minimal but stable operational presence within a Member State can trigger regulatory jurisdiction. While these rulings arose under GDPR, their reasoning on establishment and effective activity informs NIS2's territorial application, particularly for entities providing cross-border digital infrastructure or ICT services.

Enforcement practice across Member States has emphasized that entity classification must be determined by the entity's actual sectoral activity and size, not its self-identification. National competent authorities have begun publishing designation lists, and entities failing to self-identify risk being classified retroactively with associated penalties.

Practical Guidance

  • Conduct a sectoral mapping exercise against Article 3's enumerated sectors to determine whether your organization falls within essential or important entity categories, documenting the analysis for evidentiary purposes.

  • Calculate size thresholds using the most recent audited financial data, tracking both headcount and annual turnover, as these figures determine classification and must be updated annually.

  • Register proactively with the relevant national competent authority where designation procedures require self-notification, as failure to register does not exempt an entity from obligations and may trigger Article 34 fines.

  • Establish governance documentation demonstrating management body oversight of cybersecurity risk, as Article 20 personal liability provisions require evidence that leadership approved, monitored, and reviewed cybersecurity measures.

  • Map all cross-border operations and establishments to identify all Member State competent authorities with potential jurisdiction, as NIS2's territorial scope may capture entities with even minimal but stable operational presence in multiple jurisdictions.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 42
Art. 3(1) For the purposes of this Directive, the following entities shall be considered to be essential entities: NIS2 Art. 3(1)(e) any other entities of a type referred to in Annex I or II that are identified by a Member State as essential entities pursuant to Article 2(2), points… NIS2 Art. 3(2) For the purposes of this Directive, entities of a type referred to in Annex I or II which do not qualify as essential entities pursuant to paragraph 1… NIS2 Art. 3(3) By 17 April 2025, Member States shall establish a list of essential and important entities as well as entities providing domain name registration serv… NIS2 rec 89 Recital 89 β€” essential entities cyber hygiene and training NIS2 Dec 2022 art 3 Essential and important entities NIS2 Dec 2022 rec 103 Recital 103 β€” essential entities notifying service recipients threats NIS2 Dec 2022 art 32 Supervisory and enforcement measures in relation to essential entities NIS2 Dec 2022 art 33 Supervisory and enforcement measures in relation to important entities NIS2 Dec 2022 rec 17 Recital 17 β€” essential entities identification from prior directive NIS2 Dec 2022 art 34 General conditions for imposing administrative fines on essential and important entities NIS2 Dec 2022 art 46 Addressees NIS2 Dec 2022 rec 83 Recital 83 β€” security of private network systems NIS2 Dec 2022 rec 15 Recital 15 β€” essential and important entity classification NIS2 Dec 2022 rec 18 Recital 18 β€” national entity lists scope overview NIS2 Dec 2022 rec 19 Recital 19 β€” Member States submission of entity information NIS2 Dec 2022 rec 21 Recital 21 β€” Commission guidance on scope and proportionality NIS2 Dec 2022 rec 77 Recital 77 β€” entity cybersecurity risk management responsibility NIS2 Dec 2022 rec 79 Recital 79 β€” all-hazards cybersecurity risk management measures NIS2 Dec 2022 rec 80 Recital 80 β€” cybersecurity certification compliance standards promotion NIS2 Dec 2022 rec 81 Recital 81 β€” proportionate cybersecurity risk management measures NIS2 Dec 2022 rec 82 Recital 82 β€” proportionate cybersecurity risk management measures NIS2 Dec 2022 rec 85 Recital 85 β€” supply chain cybersecurity risk management NIS2 Dec 2022 rec 86 Recital 86 β€” managed security service provider risk NIS2 Dec 2022 Show 22 more β†’