Cybersecurity
Important Entity
Under NIS2, a medium-sized organization in covered sectors subject to cybersecurity obligations with reactive supervision.
Important entities under NIS2 have significant but less stringent obligations than essential entities, with supervision primarily triggered by incidents or complaints.
Classification Criteria An entity is important if it:
- Operates in a covered sector (including space)
- Qualifies at least as a medium-sized enterprise under Recommendation 2003/361/EC (Art. 2(1)); in Germany, for example, at least 50 employees, or annual turnover and balance sheet total each above €10 million (BSIG § 28(2) no. 3)
- Does not qualify as essential
- Member States can also identify entities regardless of size (Art. 2(2)(b)-(e), 3(2))
Obligations Important entities must:
- Implement appropriate security measures
- Report significant incidents
- Address security risks
- Maintain incident response capability
Supervision Regime
- Reactive (ex-post) supervision
- Triggered by incidents or evidence of non-compliance
- Lighter audit requirements
- Self-assessment acceptable
Penalties Non-compliance can result in:
- Fines up to €7 million or 1.4% of global turnover
- Management recommendations
- Compliance orders
Space Sector Examples
- Medium-sized satellite operators
- Ground station service providers
- Space data processors
- Launch service companies