NIS 2 Essential vs Important Entities: Compliance Differences in Baseline Obligations

The Italian NIS framework differentiates baseline obligations for essential and important entities across security measures and incident typologies. Practical guide to annex mapping, control depth, and audit scope.

January 23, 2026 2 min read

Two people in front of a wall planner pointing at a deadline Made with AI
Contents
  1. Key takeaways
  2. Baseline annex mapping
  3. Operational implications for compliance teams
  4. 90-day implementation checklist
  5. FAQ
  6. Related reading
  7. Official sources

The Italian NIS framework distinguishes essential and important entities and calibrates baseline obligations accordingly. For compliance planning, the practical objective is to map entity classification to the correct annexes, control depth, and incident-typology obligations.

Sources: ACN baseline reading guide, ACN baseline obligations determination

Key takeaways

  • Essential and important entities follow different baseline annexes.
  • Security-measure depth is generally higher for essential entities.
  • Incident typologies are differentiated by entity category, with additional scope for essential entities.
  • Classification must be documented because it drives control selection and audit scope.

Sources: ACN baseline reading guide

Baseline annex mapping

1. Security measures

  • Annex 1: baseline security measures for important entities.
  • Annex 2: baseline security measures for essential entities.

2. Significant incidents

  • Annex 3: baseline significant incidents for important entities.
  • Annex 4: baseline significant incidents for essential entities.

Sources: ACN baseline reading guide, ACN baseline obligations determination

Operational implications for compliance teams

Area Important entities Essential entities
Measure baselineBaseline set per Annex 1Extended/deeper baseline per Annex 2
Incident typologiesTypologies per Annex 3Typologies per Annex 4 (including additional scope)
Program planningStandard baseline rolloutEnhanced control depth and evidence coverage
Audit preparationAnnex-specific evidence mappingBroader evidence set due to expanded obligations

Sources: ACN baseline reading guide

90-day implementation checklist

  1. Confirm and document entity classification rationale.
  2. Map applicable annexes and obligations to control owners.
  3. Re-baseline evidence requirements according to entity category.
  4. Validate incident-classification workflow against the correct annex set.
  5. Run governance review on classification-dependent compliance gaps.

FAQ

Can one control set be applied unchanged to both categories?

Not reliably. Baseline obligations are differentiated by category and should be mapped to the applicable annexes.

Sources: ACN baseline reading guide

Do essential entities have additional incident scope?

Official baseline guidance indicates differentiated incident typologies, with additional scope for essential entities.

Sources: ACN baseline reading guide

What is the first audit risk in this area?

Using the wrong annex mapping for entity classification, which leads to incomplete controls and evidence.

Sources: ACN baseline obligations determination, ACN baseline reading guide

Official sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

February 10, 2026

NIS 2 Incident Typology Model: Condition, Compromise, and Affected Object

ACN baseline guidance classifies significant incidents through condition, compromise, and object of compromise. Practical guide to using the typology…

February 18, 2026

NIS 2 Point of Contact and CSIRT Contact Role: Accountability and Operating Duties

NIS 2 implementation guidance distinguishes the legal Point of Contact from the operational CSIRT contact role. Practical guide to role formalization…

February 17, 2026

NIS 2 Supply-Chain Security: Managing Critical Suppliers and High-Impact Procurements

NIS 2 supply-chain security is a governance obligation covering supplier identification, risk assessment, contractual integration, and lifecycle moni…