NIS2 glossary
15 terms, each with its article reference. Short definition first, then what it means in practice.
| Term | Reference | Definition |
|---|---|---|
| Essential entity | Art. 3(1) | An entity in an Annex I sector that exceeds the ceilings for medium-sized enterprises, plus specific categories listed regardless of size. |
| Important entity | Art. 3(2) | An entity in scope that does not qualify as essential — typically medium-sized enterprises and entities in Annex II sectors. |
| Significant incident | Art. 23(3) | An incident that has caused or is capable of causing severe operational disruption or financial loss, or considerable material or non-material damage to others. |
| Early warning | Art. 23(4)(a) | The first filing, due within 24 hours of becoming aware of a significant incident. |
| Size-cap rule | Art. 2(1) | The rule that brings medium-sized and large enterprises in Annex I and II sectors into scope by default. |
| CSIRT | Art. 10 | Computer Security Incident Response Team — the national body designated by each member state to receive incident notifications and provide assistance. |
| Competent authority | Art. 8 | The national authority responsible for supervising NIS2 compliance and enforcing it. |
| Lex specialis | Art. 4 | The principle by which a sector-specific EU act displaces the equivalent NIS2 provisions when it is at least equivalent in effect. |
| Management body | Art. 20 | The governing organ of an entity, which must approve cybersecurity risk-management measures, oversee their implementation and follow training. |
| Supply chain security | Art. 21(2)(d) | The obligation to address security in relationships with direct suppliers and service providers. |
| Coordinated vulnerability disclosure | Art. 12 | The process by which a reporter discloses a vulnerability to a vendor in a way that allows a fix before public disclosure. |
| TLPT (threat-led penetration testing) | DORA art. 26 | Adversary-simulation testing against live production systems, mandated by DORA for significant financial entities. |
| Registration | Art. 3(4) · Art. 27 | The duty to notify your national authority that you are an entity in scope, with specified identifying information. |
| Ex ante supervision | Art. 32 | Proactive supervision applied to essential entities, without needing any indication of non-compliance. |
| Basic cyber hygiene practices | Art. 21(2)(g) | The baseline practices every entity must implement, alongside cybersecurity training. |