Skip to main content →
Search Client access
Free tool · Compliance

Am I an essential or important entity under NIS2?

Seven questions that cross-check your sector (Annexes I and II of the Directive), your size and the special cases with no size threshold — and tell you whether you are an essential entity, an important entity or out of scope, with the exact article behind the verdict, your obligations and your fine bracket.

Free, no sign-up Instant result Your answers never leave your browser
Quick answer

Essential or important: the difference in one table.

Directive (EU) 2022/2555 (NIS2) applies, as a general rule, to the entities in its Annexes I and II from the size of a medium-sized enterprise upwards. Recommendation 2003/361/EC defines a medium-sized enterprise as one with fewer than 250 employees and annual turnover of up to €50M or a balance sheet total of up to €43M. Essential entities are those in Annex I that exceed those medium-size ceilings, plus the no-threshold cases of art. 3.1 (qualified trust service providers, TLD name registries and DNS service providers, central public administration, CER critical entities). Important entities are all other entities in scope: medium-sized Annex I entities and Annex II entities (art. 3.2).

Essential entityImportant entity
Who it isAnnex I ("sectors of high criticality") exceeding the medium-sized enterprise ceilings; and, with no size threshold: qualified trust service providers, TLD name registries, DNS service providers, central public administration and CER critical entities (art. 3.1).All other entities in scope: medium-sized Annex I entities and Annex II entities ("other critical sectors"), unless designated essential by the State (art. 3.2).
Maximum fine (art. 34)At least €10,000,000 or 2% of total worldwide annual turnover — whichever is higher (art. 34.4).At least €7,000,000 or 1.4% of total worldwide annual turnover — whichever is higher (art. 34.5).
SupervisionEx ante and ex post (art. 32).Ex post only, upon evidence of non-compliance (art. 33).
Reporting of significant incidents (art. 23.4)The same for both: early warning ≤ 24 hours · incident notification ≤ 72 hours · final report ≤ 1 month.
⚠️ Status in Spain: Spain has not yet transposed NIS2 — Royal Decree-Law 12/2018 (the Spanish transposition of NIS1) remains in force. The European Commission referred Spain to the CJEU on 8 July 2026 over the missing transposition (case INFR(2024)0270), requesting financial sanctions. Source for the text of the Directive: EUR-Lex, CELEX 32022L2555.

Last verified: 24 July 2026.

How it works

Three steps, no data sent anywhere.

01

You answer 7 questions

About your sector (the 11 Annex I and 7 Annex II sectors), the activities with no size threshold, your relationship with the public administration, your size and the special cases.

02

Everything happens in your browser

The logic is local JavaScript: no answer is sent to any server or stored anywhere.

03

You get a verdict with the articles

Essential, important, out of scope or special case — with the article of the Directive behind it, your obligations, the reporting deadlines and your fine bracket.

Question 1 1 / 7

Which sector does your organisation operate in?

Annexes I and II of the NIS2 Directive define its scope. Choose the one that best describes your main activity.

Annex I · Sectors of high criticality
Annex II · Other critical sectors
Outside the annexes

Do you carry out any of these activities?

These activities fall under NIS2 regardless of the size of the entity (art. 2.2.a and 2.4). Tick all that apply — or “None of these”.

Are you a public administration entity?

The judiciary, parliaments and central banks are excluded, as are national security, defence and law enforcement activities (art. 2.7 and Annex I, point 10).

How big is your organisation?

Criterion from Recommendation 2003/361/EC: a medium-sized enterprise has fewer than 250 employees and turnover of up to €50M or a balance sheet of up to €43M. If your balance sheet exceeds €43M and your turnover €50M, tick “More than €50M”. Partner and linked companies in your group also count.

Employees
Annual turnover (if your balance sheet is lower, use the balance sheet)

Have you been identified as a critical entity (CER Directive)?

Directive (EU) 2022/2557 (CER) on the resilience of critical entities. If an authority has designated you a critical entity, NIS2 applies to you with no size threshold (art. 2.3).

Were you designated an operator of essential services under NIS1, or have you been notified by an authority?

Designation as an operator of essential services under Royal Decree-Law 12/2018 (the Spanish transposition of NIS1), or a notification from the CCN, INCIBE or a sectoral ministry.

Even if you are small: are you the sole provider of your service in Spain, or would an outage of your service seriously affect public safety, public order or public health?

This route (art. 2.2, points b to e) always depends on an express designation by the State: it does not operate automatically.

Indicative result

Your classification under the NIS2 Directive

Legal notice: this result is indicative and generated automatically from your answers. It does not replace advice from a legal or compliance professional on your organisation's specific case, and the definitive classification in Spain will depend on the transposition law and on the official list of entities. If a doubt has legal or financial implications, consult the official source or book a session with me.
Review your result in a free session →
The guide behind the test

Who falls under NIS2 and what it demands.

Criteria, fines and the status of the Spanish transposition last verified: 24 July 2026 (official sources at the end).

Directive (EU) 2022/2555, known as NIS2, extends mandatory cybersecurity to entire sectors of the European economy. Its scope is drawn with two lists and one threshold: Annex I covers eleven "sectors of high criticality" (energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, business-to-business ICT service management, public administration and space) and Annex II another seven "other critical sectors" (postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research). As a general rule (art. 2.1), the Directive applies to entities in those annexes that are medium-sized enterprises or larger under Recommendation 2003/361/EC: a medium-sized enterprise has fewer than 250 employees and annual turnover of up to €50M or a balance sheet of up to €43M. Micro and small enterprises are generally out of scope — with no-threshold exceptions (art. 2.2): DNS service providers, TLD name registries, trust service providers, electronic communications, the sole national provider of an essential service or entities whose disruption would have a significant impact on public safety, public security or public health. If you are weighing several regulations, the test which regulations apply to me? assesses NIS2 alongside the ENS, DORA, the AI Act and the GDPR.

Essential or important: what really changes

Entities are essential (art. 3.1) if they are Annex I entities exceeding the medium-size ceilings and — regardless of size — qualified trust service providers, TLD name registries and DNS service providers, central public administration and entities identified as critical under Directive (EU) 2022/2557 (CER); also medium-sized providers of electronic communications and, if Spain so decides, the former operators of essential services under NIS1. Entities are important (art. 3.2) if they are any other entity in scope: medium-sized Annex I entities and Annex II entities. The substantive obligations are the same for both; what changes is supervision — ex ante and ex post for essential entities (art. 32), ex post only for important ones (art. 33) — and the fine ceiling.

The obligations: risk management and management accountability

Art. 21.2 requires, as a minimum, ten blocks of measures: security policies and risk analysis; incident handling; business continuity with backups and crisis management; supply chain security; security in the acquisition, development and maintenance of systems, including vulnerability handling; procedures to assess the effectiveness of the measures; basic cyber hygiene and training; cryptography and, where appropriate, encryption; human resources security, access control and asset management; and multi-factor authentication, secured communications and emergency communications where appropriate. Art. 20 adds the governance piece: management bodies must approve those measures, oversee their implementation and be held liable for infringements, as well as attend cybersecurity training. The whole cybersecurity and compliance block of this site develops these measures in practice.

Incident reporting: 24 hours, 72 hours, 1 month

In the event of a significant incident — one that causes or is capable of causing severe operational disruption or financial loss, or that affects third parties by causing considerable damage (art. 23.3) — art. 23.4 imposes three clocks: an early warning within a maximum of 24 hours of becoming aware of it, a full incident notification within 72 hours with the initial assessment of severity and indicators of compromise, and a final report within 1 month. Trust service providers notify within 24 hours, and the CSIRT may request intermediate reports. Recipients of the affected services must also be informed.

Fines: up to €10M or 2% of worldwide turnover

Art. 34 sets fines of a maximum of at least €10,000,000 or 2% of total worldwide annual turnover (whichever is higher) for essential entities, and of at least €7,000,000 or 1.4% (whichever is higher) for important ones. These are harmonised minimums for the ceiling: national law may set higher amounts. For essential entities, art. 32.6 additionally allows managerial duties to be temporarily suspended in the event of persistent non-compliance.

The situation in Spain: referred to the CJEU

Spain had to transpose NIS2 by 17 October 2024 and, as of 24 July 2026, it has not done so: no transposition law has been published in the BOE (Spanish Official Gazette). The Council of Ministers approved the Draft Bill on Cybersecurity Coordination and Governance on 14 January 2025 — which envisages a National Cybersecurity Centre as the single coordinating authority — but there is no record of its referral to Parliament as a bill. The European Commission sent a letter of formal notice on 28 November 2024, a reasoned opinion on 7 May 2025 and, on 8 July 2026, referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU, requesting financial sanctions (case INFR(2024)0270). In the meantime, Royal Decree-Law 12/2018 (the Spanish transposition of NIS1) remains in force, with its reference CSIRTs (CCN-CERT for the public sector, INCIBE-CERT for private entities and citizens, and ESPDEF-CERT for defence), as does the ENS (Spanish National Security Framework, RD 311/2022) for the public sector and its suppliers — if you work with the public administration, measure your readiness with the ENS self-assessment. Nor is there yet an official NIS2 entity registry in Spain or a self-registration deadline in force.

Frequently asked questions

Before you start the test.

Does NIS2 apply to me if I am an SME?+

The general rule (art. 2.1 of the Directive) is that NIS2 applies to entities in Annexes I or II from medium-sized enterprise upwards under Recommendation 2003/361/EC (a medium-sized enterprise has fewer than 250 employees and annual turnover of up to 50 million euros or a balance sheet of up to 43 million). A micro or small enterprise is generally out of scope, with exceptions that carry no size threshold: DNS service providers, TLD name registries, trust service providers, providers of electronic communications or the sole provider in a Member State of an essential service, among other cases under art. 2.2. Moreover, even if you fall outside, your in-scope customers may contractually require security measures from you as part of their supply chain security (art. 21.2.d).

What is the difference between an essential entity and an important entity?+

Essential entities (art. 3.1) are Annex I entities that exceed the medium-sized enterprise ceilings, plus several no-threshold cases: qualified trust service providers, TLD name registries and DNS service providers, central public administration and critical entities designated under the CER Directive. Important entities (art. 3.2) are all other entities in scope: medium-sized Annex I entities and Annex II entities. The substantive obligations (arts. 20, 21 and 23) are the same; what changes is supervision — ex ante and ex post for essential entities (art. 32), ex post only for important ones (art. 33) — and the fine ceiling: at least 10 million euros or 2% of worldwide annual turnover versus at least 7 million or 1.4%, in both cases whichever is higher.

Is NIS2 already enforceable in Spain?+

As of 24 July 2026 Spain has not published its NIS2 transposition law: the Council of Ministers approved the Draft Bill on Cybersecurity Coordination and Governance on 14 January 2025, but there is no law in the BOE (Spanish Official Gazette). The European Commission referred Spain to the Court of Justice of the EU on 8 July 2026 for failing to transpose the Directive (case INFR(2024)0270), requesting financial sanctions. In the meantime, Royal Decree-Law 12/2018 (the Spanish transposition of NIS1) remains in force and, for the public sector and its suppliers, so does the ENS (Spanish National Security Framework, RD 311/2022).

What fines does NIS2 provide for?+

Art. 34 of the Directive sets fines of a maximum of at least 10 million euros or 2% of total worldwide annual turnover (whichever is higher) for essential entities, and of at least 7 million euros or 1.4% (whichever is higher) for important ones. These are harmonised minimums for the ceiling: the future Spanish law may set higher ceilings, and its exact amounts are pending official confirmation because the law has not yet been published.

What is the 24-hour early warning?+

It is the first notice under art. 23.4: in the event of a significant incident, the entity must send the CSIRT or the competent authority an early warning within a maximum of 24 hours of becoming aware of it, indicating whether it suspects an unlawful or malicious act or a cross-border impact. It is followed by the full incident notification within 72 hours (with the initial assessment of severity and indicators of compromise) and a final report within 1 month. Exception: trust service providers notify within 24 hours.

Can I be subject to NIS2 and the ENS at the same time?+

Yes. The ENS (Spanish National Security Framework, RD 311/2022) is already enforceable today for the Spanish public sector and for the technology suppliers serving it; NIS2 will be added to that framework once Spain passes its transposition law. A public administration or a public sector supplier in one of the annex sectors may have to comply with both. If you work with the public administration, also check your situation with the ENS self-assessment.

Do I already have to register in a NIS2 registry in Spain?+

Not yet: no official mechanism exists. The Directive (art. 3.3) required Member States to draw up the list of essential and important entities by 17 April 2025, but in Spain, as the transposition law has not been passed, as of 24 July 2026 there is no self-registration deadline in force and no official registration portal in operation. Keep an eye on the BOE: when the law is published, it will set the procedure and its deadlines.

Want to talk through your result?

Shall we review it together?

Book a free 30-minute session. We will go through your classification, which art. 21 measures you are missing and where to start without oversizing the project.

Book a free session →