secria.eu

what is the difference between an essential entity and an important entity

Stricter oversight for critical, lighter for important

The difference lies not in the obligations themselves, but in the oversight of them. Critical and important entities are subject to the same duty of care, the same registration obligation and the same incident notification obligation. The distinction arises from the sector in which an organization operates and the size of that organization — together these determine whether an organization is designated as critical or important. Critical entities typically come from sectors considered more vulnerable or more socially critical, such as energy, drinking water or digital infrastructure, and are often the larger organizations within those sectors. Important entities are in sectors that are classified slightly less heavily, or are smaller organizations within a heavier sector.

The practical consequence lies mainly in oversight: critical entities may be subject to active, ongoing supervision, while for important entities oversight is more likely to be reactive — that is, following a notification or indication that something is not right. For an entrepreneur wondering which category their own organization falls into, it is a separate question to first establish whether there is any legal obligation at all; anyone who does not yet know this can start with how do I know if my company falls under NIS2. The sector in which an organization operates is one of the most important entry points, and those sectors are listed on the page about which sectors fall under the NIS2 directive.

Where this distinction comes from

The distinction between critical and important comes from the sectoral classification and size criteria of the NIS2 Directive, and has been further developed in the Netherlands in the Cybersecurity Act, the national transposition of that directive. The duty of care that applies to both categories is laid down in Article 21(2) of the Directive, together with the ten measures that follow from it. The NCSC provides guidance on how that duty of care and the notification obligation work in practice.

What you concretely need to do

The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.

View the subscription First the free NIS2 check

This is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.

Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.