NIS2 Directive Explained: A Pragmatic Guide for SMEs
Everything small and medium-sized businesses need to know about NIS2 compliance, key security requirements, direct management liability, and practical steps.
- NIS2 expands cybersecurity obligations to 18 critical and important sectors across the EU.
- Company directors and managing executives face direct personal liability for non-compliance.
- Core requirements include incident reporting within 24 hours, MFA, supply chain security, and data backups.
- Fines reach up to €10M or 2% of global annual turnover for essential entities.
The Network and Information Security Directive (NIS2) represents the most sweeping overhaul of European cybersecurity law in over a decade. While the original NIS Directive primarily targeted major critical infrastructure operators, NIS2 brings thousands of medium-sized businesses directly into scope.
If your company operates in energy, transport, health, digital infrastructure, manufacturing, or food distribution—or provides essential digital services to those sectors—understanding your obligations is urgent.
Who Must Comply with NIS2?
NIS2 categorizes organizations into Essential Entities and Important Entities based on sector criticality and company size:
- Essential Entities: Large enterprises in high-criticality sectors (energy, transport, banking, health, drinking water, digital infrastructure, public administration).
- Important Entities: Medium-sized enterprises (50+ employees or €10M+ annual turnover) in critical sectors, plus businesses in sectors like postal services, waste management, chemical manufacturing, food production, and digital providers (search engines, online marketplaces, cloud services).
Important Note on Supply Chains: Even if your company falls below the employee threshold, enterprise customers who are in scope must audit their supply chains under Article 21. You will likely face contractual cybersecurity requirements from your clients.
Key Cybersecurity Risk Management Measures (Article 21)
Article 21 mandates that organizations implement appropriate and proportionate technical, operational, and organizational measures, including:
- Risk analysis and information security policies: Formal policies approved by leadership.
- Incident handling: Established procedures to detect, contain, and remediate cybersecurity incidents.
- Business continuity: Resilient offline backups, disaster recovery plans, and crisis management protocols.
- Supply chain security: Assessing the security posture of direct suppliers and service providers.
- Multi-Factor Authentication (MFA): Enforced across all remote access, email, and administrative portals.
- Basic cyber hygiene practices and cybersecurity training: Regular employee security training and awareness testing.
- Cryptography and encryption: End-to-end data encryption in transit and at rest.
Mandatory Incident Reporting Timelines
NIS2 enforces strict early-warning timelines for significant cyber incidents:
- Early Warning (within 24 hours): Notify your national CSIRT / competent authority indicating whether the incident was caused by unlawful or malicious acts or could have a cross-border impact.
- Incident Notification (within 72 hours): Update the initial assessment with severity and impact indicators.
- Final Report (within 1 month): Detailed root-cause analysis, mitigation applied, and financial impact assessment.
Management Accountability & Penalties
Unlike previous cybersecurity regulations, NIS2 introduces personal management liability. Corporate management bodies must approve cybersecurity risk-management measures, oversee their implementation, and undergo mandatory cybersecurity training.
Administrative fines are substantial: - Essential Entities: Up to €10,000,000 or 2% of total worldwide annual turnover. - Important Entities: Up to €7,000,000 or 1.4% of total worldwide annual turnover.
Immediate Next Steps for SMEs
- Perform a Scope Assessment: Verify whether your sector, revenue, and client supply chains trigger NIS2 obligations.
- Audit Core Controls: Ensure MFA is universally enforced, backups are verified and air-gapped, and endpoint security is active on all company devices.
- Draft an Incident Response Plan: Define who contacts the national reporting authority within the 24-hour window when an incident occurs.