NIS2 readiness for an important entity
How readiness is shaped for an entity in the important tier: the scope test, the Article 21 measures, the reporting chain and the evidence behind them.
Compliance3 Sept 20265 min read
On this page
Scope
An important entity carries the same substantive duties as an essential entity. The risk-management measures in Article 21 and the reporting obligations in Article 23 apply to both tiers 1. Supervision is what differs. Article 33 supervises important entities ex post, on evidence, indication or information of non-compliance 2. Readiness for this tier is therefore not a reduced programme. It is the same programme, held so the case can be made from records that already exist.
In scope: the tier determination, the entity data owed to the competent authority, the ten measure families in Article 21(2), the notification chain, and management-body approval and training.
Out of scope: sector-specific Union acts that displace the directive under Article 4, national transposition detail, and day-to-day security operations, which are a capability rather than a governance artefact.
Phases
| Phase | Purpose | Planning horizon | Closes when |
|---|---|---|---|
| 1. Tier determination | Place the entity against the sector annexes and the size ceilings referred to in Article 3 | usually planned over 2–4 weeks | A written determination names sector, subsector, entity type and tier |
| 2. Measure gap assessment | Test each of the ten families in Article 21(2) against what actually operates | usually planned over 6–10 weeks | Every family has a status, an owner and a treatment decision |
| 3. Evidence and reporting build | Produce the registers, the policies and the notification chain, then rehearse it | usually planned over 3–5 months | A rehearsal yields an early warning, a notification and a final report |
| 4. Governance handover | Move approval, review and training into the management body's own cycle | usually planned over 4–6 weeks | The management body has approved the measures on its own record |
Deliverables
| Deliverable | Required by | Who maintains it afterwards |
|---|---|---|
| Scope and tier determination | Article 3(1) and (2) | Compliance owner |
| Entity registration record | Article 3(4), including a two-week change duty 3 | Compliance owner |
| Policies on risk analysis and information system security | Article 21(2), point (a) | Security function |
| Incident-handling procedure and notification runbook | Article 21(2), point (b), and Article 23(4) | Security function |
| Continuity, backup and crisis-management plan | Article 21(2), point (c) | Continuity owner |
| Supplier requirements and supplier assessment record | Article 21(2), point (d), and Article 21(3) | Procurement and security |
| Effectiveness-assessment procedure | Article 21(2), point (f) | Internal audit |
| Management-body approval record and training log | Article 20(1) and (2) 4 | The management body |
Roles
| Role | Side | Accountable for |
|---|---|---|
| Management body | Organisation | Approving the measures, overseeing implementation, following training |
| Compliance owner | Organisation | Tier determination, registration data, evidence set |
| Security function | Organisation | The measures themselves and the notification chain |
| Procurement | Organisation | Supplier requirements and the assessment record |
| Adviser | External | Method, gap assessment, rehearsal design, handover |
What the authority asks
Failure modes
Mapping
| Obligation | Article | Evidence that answers it |
|---|---|---|
| Be placed in the correct tier | Art. 3(1), 3(2) | Tier determination, annex extract |
| Give the authority current entity data | Art. 3(4) | Registration record, change log |
| Have the management body approve and oversee | Art. 20(1) | Signed approval, oversight minutes |
| Train the management body | Art. 20(2) | Training log, curriculum |
| Operate all-hazards risk-management measures | Art. 21(2), points (a)–(j) | Policy set plus operating records |
| Take supplier-specific factors into account | Art. 21(3) | Supplier assessment record |
| Correct known non-compliance without undue delay | Art. 21(4) | Corrective action register |
| Notify a significant incident on the statutory clock | Art. 23(4)(a)–(d) | Early warning, notification, final report |
References
- European Parliament and Council. Directive (EU) 2022/2555 (NIS 2 Directive). OJ L 333, 27.12.2022, p. 80.
https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng5 - The sector annexes are titled Sectors of high criticality and Other critical sectors 6.
- Administrative fines for infringement of Article 21 or 23 are set per tier in Article 34(4) and 34(5) 7.
Sources
- 1Directive (EU) 2022/2555, Arts 21 and 23, CELEX 32022L2555 · verified 2026-09-03
- 2Directive (EU) 2022/2555, Art. 33(1), CELEX 32022L2555 · verified 2026-09-03
- 3Directive (EU) 2022/2555, Art. 3(4), CELEX 32022L2555 · verified 2026-09-03
- 4Directive (EU) 2022/2555, Art. 20, CELEX 32022L2555 · verified 2026-09-03
- 5Directive (EU) 2022/2555, full text, CELEX 32022L2555 · verified 2026-09-03
- 6Directive (EU) 2022/2555, sector annexes, CELEX 32022L2555 · verified 2026-09-03
- 7Directive (EU) 2022/2555, Art. 34(4)–(5), CELEX 32022L2555 · verified 2026-09-03