# NIS2 Addressees and Responsible Entities — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/nis2-addressees-identification
> Sources are cited per item. Verify against the official texts before relying on them.

The 'Addressees' section of NIS2 specifically identifies and defines the entities and authorities to whom the directive applies and who bear responsibility for compliance. This requires a dedicated topic covering the identification, classification, and designation procedures for all addressees under NIS2.

## Overview

## Legal Framework

NIS2 establishes a two-tier classification system for its addressees through Article 3, dividing regulated entities into "essential entities" and "important entities." This classification is foundational to the entire directive, as it determines the scope of obligations, supervisory intensity, and maximum sanctions applicable to each entity.

Essential entities under Article 3(1) include operators in critical sectors such as energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management (B2B), public administration, and space. These entities are typically larger organizations exceeding defined size thresholds — generally employing 50 or more staff or exceeding €10 million in annual turnover — though Member States may designate smaller entities as essential where warranted by risk factors.

Important entities under Article 3(2) cover operators in important sectors including postal and courier services, waste management, chemicals, food, manufacturing of medical devices, computers and electronics, machinery, motor vehicles, and research. Entities in these sectors that meet the same size thresholds qualify as important entities and are subject to a somewhat lighter supervisory regime.

Article 34 establishes the general conditions for imposing administrative fines, differentiating the maximum penalties by entity classification. Essential entities face fines of up to €10 million or 2% of global annual turnover, whichever is higher. Important entities face fines of up to €7 million or 1.4% of global annual turnover. Management bodies bear personal accountability under Article 20, with potential temporary prohibitions on holding executive functions.

## Key Developments

The Court of Justice of the European Union has shaped the interpretation of "establishment" and territorial scope through cases such as Google Spain v AEPD (C-131/12) and Weltimmo (C-230/14), establishing that even minimal but stable operational presence within a Member State can trigger regulatory jurisdiction. While these rulings arose under GDPR, their reasoning on establishment and effective activity informs NIS2's territorial application, particularly for entities providing cross-border digital infrastructure or ICT services.

Enforcement practice across Member States has emphasized that entity classification must be determined by the entity's actual sectoral activity and size, not its self-identification. National competent authorities have begun publishing designation lists, and entities failing to self-identify risk being classified retroactively with associated penalties.

## Practical Guidance

- Conduct a sectoral mapping exercise against Article 3's enumerated sectors to determine whether your organization falls within essential or important entity categories, documenting the analysis for evidentiary purposes.

- Calculate size thresholds using the most recent audited financial data, tracking both headcount and annual turnover, as these figures determine classification and must be updated annually.

- Register proactively with the relevant national competent authority where designation procedures require self-notification, as failure to register does not exempt an entity from obligations and may trigger Article 34 fines.

- Establish governance documentation demonstrating management body oversight of cybersecurity risk, as Article 20 personal liability provisions require evidence that leadership approved, monitored, and reviewed cybersecurity measures.

- Map all cross-border operations and establishments to identify all Member State competent authorities with potential jurisdiction, as NIS2's territorial scope may capture entities with even minimal but stable operational presence in multiple jurisdictions.

## Legislation (full text of key provisions)

### Essential and important entities

*Source: NIS2, nis2-art-3-en, 2022-12-14 — https://overview.legal/posts/95768*

### Supervisory and enforcement measures in relation to essential entities

*Source: NIS2, nis2-art-32-en, 2022-12-14 — https://overview.legal/posts/96354*

### Supervisory and enforcement measures in relation to important entities

*Source: NIS2, nis2-art-33-en, 2022-12-14 — https://overview.legal/posts/96417*

### General conditions for imposing administrative fines on essential and important entities

*Source: NIS2, nis2-art-34-en, 2022-12-14 — https://overview.legal/posts/96449*

### Addressees

*Source: NIS2, nis2-art-46-en, 2022-12-14 — https://overview.legal/posts/96528*

This Directive is addressed to the Member States.

### Recital 89 — essential entities cyber hygiene and training

*Source: NIS2, nis2-rec-89-en, 2022-12-14 — https://overview.legal/posts/96706*

Essential and important entities should adopt a wide range of basic cyber hygiene practices, such as zero-trust principles, software updates, device configuration, network segmentation, identity and access management or user awareness, organise training for their staff and raise awareness concerning cyber threats, phishing or social engineering techniques. Furthermore, those entities should evaluate their own cybersecurity capabilities and, where appropriate, pursue the integration of cybersecurity enhancing technologies, such as artificial intelligence or machine-learning systems to enhance their capabilities and the security of network and information systems.

### Recital 103 — essential entities notifying service recipients threats

*Source: NIS2, nis2-rec-103-en, 2022-12-14 — https://overview.legal/posts/96734*

Where applicable, essential and important entities should communicate, without undue delay, to their service recipients any measures or remedies that they can take to mitigate the resulting risks from a significant cyber threat. Those entities should, where appropriate and in particular where the significant cyber threat is likely to materialise, also inform their service recipients of the threat itself. The requirement to inform those recipients of significant cyber threats should be met on a best efforts basis but should not discharge those entities from the obligation to take, at their own expense, appropriate and immediate measures to prevent or remedy any such threats and restore the normal security level of the service. The provision of such information about significant cyber threats to the service recipients should be free of charge and drafted in easily comprehensible language.

### Recital 17 — essential entities identification from prior directive

*Source: NIS2, nis2-rec-17-en, 2022-12-14 — https://overview.legal/posts/96562*

Member States should be able to decide that entities identified before the entry into force of this Directive as operators of essential services in accordance with Directive (EU) 2016/1148 are to be considered to be essential entities.

### Recital 83 — security of private network systems

*Source: NIS2, nis2-rec-83-en, 2022-12-14 — https://overview.legal/posts/96694*

Essential and important entities should ensure the security of the network and information systems which they use in their activities. Those systems are primarily private network and information systems managed by the essential and important entities’ internal IT staff or the security of which has been outsourced. The cybersecurity risk-management measures and reporting obligations laid down in this Directive should apply to the relevant essential and important entities regardless of whether those entities maintain their network and information systems internally or outsource the maintenance thereof.

### Recital 15 — essential and important entity classification

*Source: NIS2, nis2-rec-15-en, 2022-12-14 — https://overview.legal/posts/96558*

Entities falling within the scope of this Directive for the purpose of compliance with cybersecurity risk-management measures and reporting obligations should be classified into two categories, essential entities and important entities, reflecting the extent to which they are critical as regards their sector or the type of service they provide, as well as their size. In that regard, due account should be taken of any relevant sectoral risk assessments or guidance by the competent authorities, where applicable. The supervisory and enforcement regimes for those two categories of entities should be differentiated to ensure a fair balance between risk-based requirements and obligations on the one hand, and the administrative burden stemming from the supervision of compliance on the other.

## Related topics

- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Public Authority** — https://overview.legal/topics/overheid
  Government bodies and their data processing activities
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Public Sector** — https://overview.legal/topics/public-sector
  Processing by public authorities
- **Identification** — https://overview.legal/topics/identificatie
  Methods and processes for identifying individuals
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons

---
Generated by overview.legal · https://overview.legal/topics/nis2-addressees-identification · 2026-08-22
