Abstract network of blue nodes with one cluster set apart, representing NIS2 important entity classification under Article 3(2)

NIS2 Important Entity: The 6 Routes Into Article 3(2) — 4 Apply No Matter How Small You Are

Article 3(2) of the NIS2 Directive is one sentence long, and it never describes an important entity. It subtracts one: “entities of a type referred to in Annex I or II which do not qualify as essential entities pursuant to paragraph 1 of this Article shall be considered to be important entities” [1]. There is no positive test. You do not read Article 3(2) and find yourself in it — you land there by failing to appear anywhere in Article 3(1).

That structure matters more than it sounds. The population of important entities is not “medium-sized companies in Annex II sectors”, which is how most guides summarise it. It is everything the essential list leaves behind — and that list leaves behind a 4,200-person car manufacturer, a twelve-person internet service provider and a regional government department, each for a completely different reason.

What Article 3(2) Actually Says

In plain language: you are an important entity when two things are true at once. First, NIS2 applies to you at all. Second, none of the seven essential categories in Article 3(1) catches you.

The first condition is Article 2. You are in scope if you are an entity of a type listed in Annex I or Annex II and you qualify as a medium-sized enterprise or exceed those ceilings [1]. You are also in scope, “regardless of their size”, if Article 2(2) catches you — as a provider of public electronic communications networks or services, a trust service provider, a DNS provider or TLD registry, a sole provider of an essential service in a Member State, an entity whose disruption would hit public safety or create systemic risk, or a public administration entity [1]. The second condition is Article 3(1), covered in our guide to the NIS2 essential entity definition. Fail to match any of its seven limbs and Article 3(2) closes over you by default.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Article 3(2) has a second sentence that is easy to skip: it also captures “entities identified by Member States as important entities pursuant to Article 2(2), points (b) to (e)” [1]. The same national designation power that Article 3(1)(e) uses to make an entity essential can instead place it in the important tier — a national call, not an EU one.

The Six Routes to Important Entity Status

Because Article 3(2) is residual, the only honest way to enumerate important entities is to work through everything Article 2 pulls in and remove what Article 3(1) claims. Six distinct routes survive that subtraction. Four sit under Article 2(2) and apply regardless of size.

Route Legal basis Who it catches Does size matter?
1. Medium-sized Annex I entity Art. 2(1) in scope; Art. 3(1)(a) applies only above the medium ceilings Energy, transport, banking, health, water, digital infrastructure and public administration entities that are medium-sized rather than large — except electronic communications providers Yes — size is the only thing keeping you out of the essential tier
2. Annex II entity, medium-sized or large Art. 2(1); Art. 3(1)(a) is Annex I only Postal and courier, waste management, chemicals, food, manufacturing, digital providers, research organisations Only to get you in scope. Growing never upgrades you
3. Non-qualified trust service provider Art. 2(2)(a)(ii); Art. 3(1)(b) covers qualified providers only Timestamping, e-seal or e-signature providers without qualified status No
4. Small or micro electronic communications provider Art. 2(2)(a)(i); Art. 3(1)(c) upgrades only medium-sized providers Small ISPs, regional fibre operators, niche VoIP and messaging services No — being tiny keeps you in scope, it just keeps you out of the essential tier
5. Regional public administration Art. 2(2)(f)(ii); Art. 3(1)(d) elevates only central government Regional authorities designated after a national risk-based assessment No
6. Member State designation Art. 3(2), second sentence, via Art. 2(2)(b) to (e) Sole providers, entities of national or regional criticality, systemic-risk entities that a Member State classes as important rather than essential No

Route 4 breaks the usual mental model. “Medium-sized means important” holds everywhere except electronic communications, where Article 3(1)(c) makes medium-sized providers essential — so in that one sector the small operator is important and the medium one is not. Ireland’s National Cyber Security Centre words its own summary carefully for exactly this reason, saying a medium-sized enterprise “generally” falls in scope as an important entity [3].

The Size Test, and the Two Places It Trips People Up

NIS2 does not define company size itself. It borrows Commission Recommendation 2003/361/EC, where a medium-sized enterprise employs fewer than 250 people and has turnover of no more than €50 million or a balance sheet total of no more than €43 million, while a small enterprise employs fewer than 50 people and has turnover and/or a balance sheet total of no more than €10 million [2][5].

Trap one: the financial limbs are alternatives, not a pair. The Commission sets the test as staff headcount plus either turnover or balance sheet total [5], and Ireland’s NCSC states it directly: “An entity can choose to meet either the turnover ceiling or the balance sheet total ceiling, and exceeding one of these doesn’t affect its status as an SME” [3]. A waste-management firm with 35 staff, €12 million turnover and a €4 million balance sheet is still a small enterprise on the balance-sheet limb, and therefore out of scope. Guides that write the threshold as “50–249 employees and €10–50 million turnover” get this backwards and pull organisations into scope that do not belong there.

Trap two: you do not change tier the day you cross a line. Under Article 4(2) of the Recommendation’s Annex, crossing a ceiling “will not result in the loss or acquisition of the status of medium-sized, small or microenterprise unless those ceilings are exceeded over two consecutive accounting periods” [2]. Hire your fiftieth employee in 2026 and, on the Recommendation’s own arithmetic, status turns on the second consecutive set of accounts, not the first.

Two mechanics decide more borderline cases than the headline numbers do. Headcount is measured in annual work units, so part-time and seasonal staff count as fractions and apprentices on training contracts are excluded [2]. And group structure is aggregated: 100 % of a linked enterprise’s staff and financials are added to yours, a partner enterprise’s pro rata to the shareholding [2]. NIS2 then removes one filter that would otherwise apply — Article 2(1) expressly disapplies Article 3(4) of the Recommendation’s Annex, so 25 % or more public ownership does not strip SME status here [1]. That sentence keeps many municipal utilities in the important tier rather than pushing them into the essential one.

Ten Worked Classifications

Two contrasting pairs are included deliberately — the same sector and the same test produce a different answer once size moves.

Organisation Annex Size Verdict Why
Car manufacturer, 4,200 staff, €1.2bn turnover II (Manufacturing, NACE C29) Large Important Art. 3(1)(a) elevates Annex I entities only. Annex II has no size upgrade
Electricity distribution operator, 130 staff I (Energy) Medium Important Does not exceed the medium ceilings, so Art. 3(1)(a) does not reach it
Electricity distribution operator, 310 staff I (Energy) Large Essential Exceeds the medium ceilings — Art. 3(1)(a)
Food wholesaler, 60 staff, €18m turnover II (Food) Medium Important In scope under Art. 2(1); no Art. 3(1) limb applies
Waste-management firm, 35 staff, €12m turnover, €4m balance sheet II (Waste) Small Out of scope Still small on the balance-sheet limb, and no Art. 2(2) hook
Regional internet service provider, 12 staff I (Digital infrastructure) Micro Important In scope regardless of size under Art. 2(2)(a)(i); Art. 3(1)(c) upgrades medium-sized providers only
Internet service provider, 90 staff I (Digital infrastructure) Medium Essential Art. 3(1)(c) — the one place where medium-sized means essential
Timestamping provider without qualified status, 40 staff I (Digital infrastructure) Small Important In scope regardless of size; Art. 3(1)(b) covers qualified trust service providers only
Online marketplace, 55 staff II (Digital providers) Medium Important Annex II digital provider — see our marketplace requirements guide
Regional government department designated under Art. 2(2)(f)(ii) I (Public administration) Any Important Art. 3(1)(d) elevates central government entities only

Nobody hands you this verdict. Ireland’s NCSC is explicit that “It is not the role of the NCSC to confirm if entities are, or are not, in scope of the NIS2 Directive. This determination must be made by the entity as they know the specifics of their business” [3]. Its Am I in Scope tool assists, but the classification — and the documented reasoning behind it — is yours to own and defend. Our five-step NIS2 scope test walks the same logic in sequence.

What “Important” Changes — and What It Doesn’t

The word oversells the relief. Important entities carry identical substantive duties: the same ten cybersecurity risk-management measures under Article 21, the same incident notification timetable under Article 23, the same management accountability under Article 20, and the same registration duty under Article 3(4) — including notifying any change to your registered details “within two weeks of the date of the change” [1]. See our entity registration guide for that filing.

What changes is how you are watched, and how hard you can be hit.

Dimension Essential (Art. 32, 34(4)) Important (Art. 33, 34(5))
Trigger for supervision Proactive, ex ante Only “when provided with evidence, indication or information” of alleged non-compliance — ex post
Audits Regular, targeted and ad hoc audits; random checks Targeted security audits only
Monitoring officer Can be imposed under Art. 32(4)(g) Not available — Art. 33(4) has no equivalent power
Suspension of certification or authorisation Available under Art. 32(5)(a) Not available — Art. 33(5) imports only Art. 32(6), (7) and (8)
Temporary ban on managerial functions Available under Art. 32(5)(b) Not available, for the same reason
Maximum administrative fine At least €10,000,000 or 2 % of total worldwide annual turnover, whichever is higher At least €7,000,000 or 1.4 % of total worldwide annual turnover, whichever is higher

The Article 33(5) point is the sharpest and the least reported. It states that “Article 32(6), (7) and (8) shall apply mutatis mutandis” to important entities [1] — paragraph (5) is conspicuously absent from that list. On the text, the two most feared NIS2 sanctions, suspending an operating authorisation and barring a chief executive from managerial functions, cannot be used against an important entity. Fines, binding instructions, cease orders and forced public disclosure of an infringement all remain fully available under Article 33(4) [1]. The tier changes your enforcement exposure; it does not soften a single control you have to build. Our penalties guide covers how Member States have transposed these ceilings.

What Each Role Should Do Next

Role The action that actually matters
Compliance officer / legal Write the classification down as a dated memo citing the Article 3(1) limbs you ruled out and the accounting periods you relied on. Ex post supervision starts when someone hands the authority a document — make sure the first one is yours
CISO / IT security Build to Article 21 as if you were essential. Nothing in Article 33 reduces the control set; it only changes who knocks first
SME owner / non-technical Test the two financial limbs separately before assuming you are in scope. Under 50 staff and inside either the €10m turnover or the €10m balance-sheet ceiling, you are still small
Board Note what the important tier removes: no certification suspension, no management ban. The €7,000,000 / 1.4 % ceiling and personal accountability under Article 20 stay

Frequently Asked Questions

Is every Annex II organisation an important entity? No. Annex II tells you which sector you are in; Article 2 decides whether you are in scope at all. A small or micro Annex II entity with no Article 2(2) hook sits outside NIS2 entirely. Once in scope, though, an Annex II entity is important at any size.

Can a Member State move us into the essential tier? Yes. Article 3(1)(e) lets a Member State designate any Annex I or II entity as essential under Article 2(2), points (b) to (e) — typically as a sole provider or an entity of national criticality. Article 3(2)’s second sentence gives the same authority the option of classing you important instead.

We provide domain name registration services. Which tier? Neither, on the face of the Directive. Article 2(4) applies NIS2 to registrars regardless of size, but registrars are not a type listed in Annex I or Annex II — and Article 3(2) classifies Annex I and II types only. Article 3(3) reinforces this by requiring Member States to list “essential and important entities as well as entities providing domain name registration services” as separate populations [1]. TLD name registries, which are in Annex I, are essential under Article 3(1)(b). Check your national transposition, since Member States implement this differently.

We just passed 50 employees. Are we in scope now? Not necessarily this year. Article 4(2) of the Recommendation’s Annex ties the change of status to ceilings being exceeded over two consecutive accounting periods [2]. Use the interval to prepare rather than to wait.

We are a medium-sized Annex I entity and a large Annex II entity. Which wins? Essential status is determined first. If any limb of Article 3(1) catches you for any service you provide, you are an essential entity; Article 3(2) picks up only what is left. Our essential vs important comparison works through the overlap cases.

Do important entities get a lighter version of Article 21? No — Article 21 applies to both tiers in identical terms. Article 21(1) does build in proportionality — “due account shall be taken of the degree of the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity” [1] — but that calibration sits inside the measures themselves, not in your tier.

Sources

  1. Directive (EU) 2022/2555 (NIS2) — EUR-Lex. Articles 2, 3, 20, 21, 23, 32, 33, 34 and Annexes I and II.
  2. Commission Recommendation 2003/361/EC concerning the definition of micro, small and medium-sized enterprises — EUR-Lex. Annex Articles 2 to 6.
  3. NIS2 FAQ — National Cyber Security Centre, Ireland.
  4. Am I in Scope self-assessment tool — National Cyber Security Centre, Ireland (linked above).
  5. SME definition — European Commission, DG Internal Market, Industry, Entrepreneurship and SMEs.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: