Important entities
The same measures, different supervision. Important entities self-assess every two years and are audited only at the request of the authority.
Where important entities sit under the Act
Important entities are not a lighter version of essential ones. The measures are the same, the thirteen of Annex II, and what differs is the form of periodic verification and the intensity of supervision.
Essential entities undergo a cyber security audit at least once every two years, under Article 34(1). Important entities carry out a self-assessment at least once every two years, under Article 35(1), and an audit only when the competent authority requests one, under Article 34(4). The self-assessment results in a declaration of conformity or an action plan, submitted to the authority no later than eight days after it is drawn up.
The level of measures for important entities is likewise set by the national risk assessment, under Article 38 of the Regulation. An important entity at high risk may sit at the advanced level, and an essential one at low risk at the basic level.
Where important entities usually get stuck
What we do for you
Who falls into the important entity category
The category is set by the competent authority and the level of measures by the national risk assessment; both are explained in the overview of the Act.
Royal Mail: six weeks without international despatch
Ransomware hit the system that prints customs declarations for items going abroad. Counters stayed open, but no international item could leave the country, and it took roughly six weeks to restore the service in full. The attackers did not go for the most sensitive system, they went for the one the business cannot run without. Every organisation has a few of those, and they are usually missing from the critical asset list.
SOURCE: Royal Mail statements and evidence to a UK parliamentary committee, 2023.
Frequently asked questions
The questions important entities ask first, mostly about the self-assessment and what follows if the authority asks for an audit.
Do important entities have fewer measures?
They do not. What differs is only the form of periodic verification, a self-assessment instead of a mandatory audit, and the upper limit of the fine.What is a self assessment?
A check of your own compliance using the same methodology and the same scoring formulas as an audit. You run it yourself every two years and keep a record of it.When does an audit happen anyway?
At the request of the competent authority, most often after an incident, a complaint or a weak self assessment. At that point there is no time left to prepare.How large are the fines?
Up to EUR 7,000,000 or 1.4 per cent of total annual turnover for important entities, whichever is higher.How do we know whether we are essential or important?
The category follows sector and size, with exceptions, and the competent authority sends the categorisation notice. The twelve month deadline runs from that notice.What does a self-assessment produce?
A declaration of conformity or an action plan, under Article 35(3) and (4). Either is submitted to the competent authority without delay and no later than eight days after being drawn up. The entity bears the cost.Can we outsource the self-assessment?
You can. Article 35(2) expressly allows the use of an external self-assessment provider. Responsibility for the content and for the submission remains yours.What if the authority requests an audit?
An audit is then carried out, under Article 34(4), and the report is submitted immediately on receipt. That is why an important entity has to keep its evidence file ready for somebody else’s eye, not just its own.Related pages
The pages that set out what important entities need in place before a self-assessment.
Let us check whether you are essential or important.
Half an hour, no obligation. We establish whether you are an essential or an important entity and what follows from that.
