If you are an essential entity, the supervisor does not wait for an incident to come looking. That single fact — proactive, ex-ante supervision — is what separates your obligations under NIS2 from everyone else’s, and it changes what “compliant” has to mean.
NIS2 sorts in-scope organisations into two tiers, essential and important, and most commentary treats the difference as a matter of higher fines. It is not. Both tiers carry the same core measures and the same reporting duties. What genuinely differs is how you are supervised — and for an essential entity in a sector like energy, water, or digital infrastructure, that difference is the whole game.
Essential versus important, and why energy sits at the top
The classification is a function of sector and size. Large organisations in the directive’s highly-critical sectors — Annex I: energy, transport, banking, health, water, digital infrastructure and the rest — are essential entities. Medium-sized organisations in those sectors, and entities in the second list of sectors, are important. Energy and utility operators of any scale therefore tend to land in the essential tier, at the maximum of the directive’s supervisory and penalty exposure.
Free · 4 minutes
Do you actually know what you are running — and what it is about to cost you?
Fourteen questions on the systems you depend on, the ones nobody owns, and the support dates that turn a routine upgrade into a forced re-platform. Banded finding on screen, full sheet by email.
Essential entities are subject to ex-ante supervision: competent authorities may run regular and targeted audits, on-site inspections and remote checks, require a security audit by an independent body, and issue binding instructions to remediate — all without needing a triggering incident. Important entities get ex-post supervision, where authorities generally act only once there is evidence of a problem. The practical consequence is stark. An important entity can, in effect, run on “we will fix it if they ask.” An essential entity cannot, because they can ask at any time, unprompted, and expect to be shown.
The measures, the clock, and the boardroom
The substance is Article 21: ten all-hazards measures covering risk analysis, incident handling, business continuity and backup, supply-chain security, secure acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, human-resources and access control, and multi-factor authentication. Article 23 sets the reporting clock — a 24-hour early warning to your national CSIRT, a 72-hour notification with an initial impact assessment, and a final report within a month. For entities in digital infrastructure and digital-provider roles, a directly applicable implementing regulation turns those high-level measures into more than 150 specific technical requirements, no national transposition required.
Then there is the part that reaches individuals. Under Article 20, the management body must approve the risk-management measures and oversee their implementation, and members must undergo training. Where an essential entity fails, supervisors can sanction the management body personally, up to and including a temporary ban from holding a management role. This is deliberate: NIS2 moves cyber accountability out of the IT function and into the boardroom, and attaches it to people who cannot delegate it away. The practical effect is that boards now have to ask for evidence in the meeting, not merely approve a policy and move on.
The transposition reality is a moving target
NIS2 is a directive, so your actual obligations live in national law — and national law is uneven. The transposition deadline was 17 October 2024, and only a handful of member states met it. By mid-2026 the large majority had adopted transposing legislation, but several — including France, Ireland, Luxembourg, the Netherlands and Spain — were still in their legislative processes, with the Netherlands’ law expected around mid-2026 and Germany’s having taken effect in December 2025. A targeted amendment proposed in January 2026 would adjust scope at the edges and route incident notifications through a single ENISA portal, but it had not been adopted and does not change the Article 21 measures or the Article 23 deadlines. Treat any single country deadline as provisional and confirm against the applicable national transposition.
On enforcement, honesty helps: as of mid-2026 there had been no headline fines against named entities; activity was still at the supervisory-notice stage. But for essential entities that is cold comfort, because ex-ante supervision does not depend on enforcement momentum. The audit can arrive because it is your turn, not because something broke.
Where this bites hardest, and the through-line
Energy and utility estates concentrate the problem. Operational technology accumulated over decades, life-cycles measured in twenty-year horizons, and systems that predate current governance mean the first honest question — what do we even have, and which of it underpins a critical service — is often unanswered. NIS2’s chain-responsibility principle then pushes the same demand down your supply chain: an essential entity must assess and document the cyber risk of its critical suppliers, so your suppliers inherit obligations even where the directive does not name them directly. And where those systems are products with digital elements, the Cyber Resilience Act‘s reporting duty lands on the manufacturer in parallel.
Underneath all of it is the same shift I keep returning to: from control presence to control effectiveness, evidenced on demand. An essential entity does not need to prove it wrote the policy; it needs to prove the measure is implemented, working, owned and traceable — the moment an ex-ante auditor asks. That is an evidence and assurance problem before it is a security-tooling problem, and it is worth also mapping the notification overlaps early: a personal-data breach can trigger a 72-hour duty to your data-protection authority at the same time as the 24-hour NIS2 duty to your CSIRT — two authorities, two clocks, one incident.
Where an essential entity also manufactures a connected product, the CRA’s product-side obligations stack on top — see NIS2 vs CRA for how the two actually interact.
If you are an essential entity and could not, today, show an auditor a complete and current picture of your critical services and the controls around them, that gap is the exposure. A technology control assessment maps it; as a fractional CTO I build the estate visibility and evidence to close it. See how engagements are scoped.
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming