NIS2 Compliance for Small and Medium Businesses: What You Need to Do Now

Introduction

Cybersecurity is no longer just a problem for banks, hospitals, telecom providers, or large corporations. With the arrival of the NIS2 Directive, many small and medium businesses across Europe need to take cybersecurity far more seriously.

NIS2 is the European Union’s updated cybersecurity directive. Its purpose is to improve the security of companies and organizations that provide important services to society and the economy. That includes obvious sectors such as energy, healthcare, transport, banking and digital infrastructure, but also many businesses that may not immediately think of themselves as “critical.”

For small and medium businesses, this can feel confusing. Are you covered? What do you need to do? Do you need expensive consultants? Will there be fines? And most importantly: where should you start?

This guide explains NIS2 compliance for small and medium businesses in plain English. No legal fog. No unnecessary panic. Just the practical steps your business should take now.

What Is NIS2?

NIS2 stands for the Network and Information Security Directive 2. It replaces the original NIS Directive and expands cybersecurity obligations across the European Union.

The main goal is simple: businesses and organizations that are important to the functioning of society must be better protected against cyberattacks, system failures, ransomware, data breaches and supply-chain risks.

The old idea was that cybersecurity belonged mainly to IT departments. NIS2 changes that. Under NIS2, cybersecurity becomes a business risk, a management responsibility and a compliance obligation.

In other words, “we have antivirus” is not a cybersecurity strategy. It is a starting point. A very small one.

Why NIS2 Matters for Small and Medium Businesses

Many SMEs assume cybersecurity rules only apply to large companies. That is a dangerous assumption.

NIS2 can apply to medium-sized businesses in covered sectors, and sometimes even to smaller organizations depending on the type of service they provide. Even if your business is not directly covered, you may still be affected indirectly if you supply services to a company that is covered by NIS2.

For example, if your company provides IT services, software, logistics, cloud support, manufacturing components, food distribution, digital platforms or managed services to larger organizations, those clients may start asking you for proof of cybersecurity controls.

That means NIS2 is not only a legal issue. It is also a commercial issue. Businesses that can show they take cybersecurity seriously may have an advantage when bidding for contracts or working with larger clients.

Who Needs to Comply with NIS2?

NIS2 applies to organizations in specific sectors considered important or essential to the EU economy and society. These include sectors such as:

  • Energy
  • Transport
  • Banking and financial market infrastructure
  • Healthcare
  • Drinking water and wastewater
  • Digital infrastructure
  • ICT service management
  • Public administration
  • Space
  • Postal and courier services
  • Waste management
  • Chemicals
  • Food production and distribution
  • Manufacturing
  • Digital providers
  • Research

NIS2 usually divides organizations into two categories: essential entities and important entities.

Essential Entities

Essential entities are generally larger organizations or organizations operating in highly critical sectors. They face stricter supervision and potentially higher penalties.

Important Entities

Important entities are also covered by NIS2 but usually face a slightly lighter supervision model. However, “lighter” does not mean “optional.” These businesses still need to implement cybersecurity risk-management measures and report significant incidents.

What About Small Businesses?

Many small businesses are not directly covered by NIS2 simply because they do not meet the size or sector criteria. However, some smaller organizations can still fall within scope if they provide specific critical digital services or operate in certain sensitive areas.

Also, SMEs that supply services to NIS2-covered organizations may be asked to meet cybersecurity requirements contractually. So even if the law does not knock on your front door, your customers might.

The Main NIS2 Requirements for Businesses

NIS2 is not just about installing software. It requires a structured approach to cybersecurity. The main requirements include risk management, incident reporting, supply-chain security, business continuity and management accountability.

Let’s break that down.

1. Cybersecurity Risk Assessment

The first step is to understand your risks. You cannot protect what you have not identified.

A proper cybersecurity risk assessment should answer questions such as:

  • What systems are critical to our business?
  • What data do we store and process?
  • Who has access to our systems?
  • What would happen if our systems were unavailable for two days?
  • Which suppliers have access to our data or infrastructure?
  • Are our backups reliable?
  • Are our employees trained to recognize phishing attacks?

For SMEs, this does not need to be a 200-page corporate report. But it does need to be documented, practical and reviewed regularly.

A simple risk register can already be a strong starting point. List your key systems, the risks linked to them, the possible impact, and the measures you have in place.

2. Security Policies and Procedures

NIS2 expects businesses to have policies for managing information security. These policies should explain how your organization handles cybersecurity risks.

Useful policies include:

  • Information security policy
  • Password and access control policy
  • Backup policy
  • Incident response policy
  • Supplier security policy
  • Remote working policy
  • Data protection and encryption policy
  • Device and asset management policy

Do not make the mistake of creating policies nobody reads. A good policy is clear, short and usable. If your employees need a law degree to understand your password policy, you have already lost the plot.

3. Incident Handling

Cyber incidents happen. The question is whether your business knows what to do when they happen.

NIS2 requires organizations to have incident-handling procedures. That means you need a plan for detecting, reporting, responding to and recovering from cybersecurity incidents.

Your incident response plan should include:

  • Who is responsible during an incident
  • How incidents are detected
  • Who must be informed internally
  • Which external parties may need to be contacted
  • How evidence is preserved
  • How systems are restored
  • How customers or partners are informed if necessary
  • How the incident is reviewed afterwards

Common incidents include ransomware, phishing, stolen credentials, data breaches, malware infections, unauthorized access and major system outages.

For a small business, the incident response team may only be two or three people. That is fine. The important thing is that everyone knows their role before the crisis starts.

4. Incident Reporting

One of the most important parts of NIS2 is incident reporting.

If your organization suffers a significant cyber incident, you may need to report it to the relevant authority or computer security incident response team.

The general reporting timeline under NIS2 includes:

  • An early warning within 24 hours
  • A more detailed notification within 72 hours
  • A final report within one month

This means your business needs to know how to recognize a significant incident quickly. Waiting a week because “we were still investigating” is not a great compliance strategy.

A practical step is to create an incident reporting checklist that includes:

  • Date and time of discovery
  • Systems affected
  • Type of incident
  • Estimated business impact
  • Data or services affected
  • Initial containment actions
  • Contact person responsible
  • Whether external reporting may be required

5. Business Continuity and Backup Management

NIS2 also focuses on business continuity. If your business is hit by ransomware, a server failure or a supplier outage, can you keep operating?

Business continuity planning should include:

  • Regular backups
  • Backup testing
  • Disaster recovery procedures
  • Crisis communication
  • Alternative working methods
  • Recovery time objectives
  • Clear responsibility during disruptions

Backups deserve special attention. Many companies have backups, but far fewer test whether those backups actually work. An untested backup is like a parachute packed by a stranger. Maybe fine. Maybe not the best time to find out.

Use the 3-2-1 backup principle as a starting point:

  • Keep at least 3 copies of important data
  • Store them on 2 different types of storage
  • Keep 1 copy offline or offsite

6. Supply Chain Security

Supply-chain cybersecurity is one of the biggest areas of focus under NIS2.

Your business may have strong internal security, but if your IT provider, cloud platform, software supplier or payment provider is weak, you can still be exposed.

Supply-chain security means reviewing and managing the cybersecurity risks linked to your suppliers.

Start by identifying critical suppliers such as the following:

  • Managed IT providers
  • Cloud hosting companies
  • Software vendors
  • Payment processors
  • Accounting software providers
  • Logistics platforms
  • Data storage providers
  • External developers
  • Marketing platforms with customer data access

Then ask practical questions:

  • Does this supplier have access to our systems or data?
  • Do they use multi-factor authentication?
  • Do they have security certifications?
  • How do they handle incidents?
  • Where is our data stored?
  • What happens if their service goes offline?
  • Are cybersecurity obligations included in the contract?

For SMEs, this does not mean you need to audit every supplier like a multinational corporation. But you should identify your most important vendors and check whether they meet reasonable security expectations.

7. Access Control and Multi-Factor Authentication

Access control is one of the easiest areas to improve and one of the most commonly abused by attackers.

Your business should apply the principle of least privilege. That means employees only get access to the systems and data they actually need.

Important access-control measures include:

  • Multi-factor authentication for email, cloud systems and admin accounts
  • Strong password requirements
  • Separate admin accounts
  • Regular access reviews
  • Immediate removal of access when employees leave
  • Logging of important account activity
  • Restricted access to sensitive data

If you do only one thing this week, enable multi-factor authentication on your business email and cloud accounts. Email is often the front door for cyberattacks, and attackers love businesses that leave the front door open with a welcome mat.

8. Cyber Hygiene and Employee Training

Cybersecurity is not only about technology. People are often the first target.

Phishing emails, fake invoices, malicious attachments and social engineering attacks remain common because they work.

NIS2 expects organizations to improve cyber hygiene and awareness. For SMEs, this can include:

  • Regular phishing awareness training
  • Clear rules for handling suspicious emails
  • Secure password practices
  • Safe use of business devices
  • Guidelines for remote work
  • Training on reporting incidents quickly
  • Basic management training on cybersecurity risks

Training does not need to be boring. In fact, boring security training is one of the fastest ways to make employees mentally leave the building. Keep it practical, short and relevant to real situations they may face.

9. Encryption and Secure Communication

NIS2 also includes expectations around cryptography and secure communication.

Your business should consider encryption for:

  • Laptops
  • Mobile devices
  • Sensitive files
  • Backups
  • Databases
  • Cloud storage
  • VPN connections
  • Internal and external communication

Encryption helps protect data if devices are lost, stolen or accessed by unauthorized people.

Also review how your team communicates during a crisis. If your email system is down because of a cyberattack, how will your team coordinate? Having an emergency communication method can make a major difference.

10. Management Responsibility

NIS2 makes cybersecurity a leadership issue.

Management must understand the risks, approve cybersecurity measures and oversee implementation. This is important because many cyber risks are business decisions, not purely technical decisions.

For example:

  • How much downtime can the business tolerate?
  • Which systems are most critical?
  • What budget is needed for cybersecurity?
  • Which suppliers are acceptable?
  • What level of risk is the business willing to accept?

These are management questions.

Business owners and directors do not need to become cybersecurity engineers. But they do need to understand enough to make informed decisions and ensure the right measures are in place.

Practical NIS2 Compliance Checklist for SMEs

Here is a practical checklist to help your business get started.

Step 1: Check Whether NIS2 Applies to You

Identify your sector, company size and services. Check whether your business falls into a covered NIS2 sector or supplies services to organizations that are covered.

Step 2: Assign Responsibility

Choose a person responsible for coordinating cybersecurity and NIS2 preparation. In a small business, this may be the owner, operations manager or IT manager.

Step 3: Create an Asset Inventory

List your systems, devices, software, cloud services, data types and suppliers. You cannot secure what you do not know exists.

Step 4: Perform a Risk Assessment

Identify your biggest cybersecurity risks and document how you plan to reduce them.

Step 5: Enable Multi-Factor Authentication

Start with email, cloud tools, admin accounts, finance systems and remote access.

Step 6: Improve Backup and Recovery

Make sure backups are automated, protected and tested regularly.

Step 7: Create an Incident Response Plan

Document what your business will do if a cyber incident occurs.

Step 8: Review Suppliers

Identify critical suppliers and check whether they follow reasonable cybersecurity practices.

Step 9: Train Employees

Teach staff how to recognize phishing, report incidents and handle data securely.

Step 10: Keep Evidence

Save policies, risk assessments, training records, supplier checks, backup test results and incident response exercises. Compliance is easier when you can prove what you have done.

Common Mistakes SMEs Should Avoid

Many small and medium businesses make the same cybersecurity mistakes. Avoid these:

Mistake 1: Assuming NIS2 Does Not Apply

Do not guess. Check your sector, size and role in the supply chain.

Mistake 2: Treating Cybersecurity as an IT-Only Problem

Cybersecurity affects operations, finance, legal, sales, customer trust and business continuity.

Mistake 3: Ignoring Suppliers

A weak supplier can become your biggest risk.

Mistake 4: Having Backups but Never Testing Them

Backups only matter if they can actually restore your business.

Mistake 5: No Incident Plan

The middle of a cyberattack is not the ideal time to start Googling “what to do after ransomware.”

Mistake 6: Weak Access Controls

Old user accounts, shared passwords and no MFA are gifts to attackers.

Do SMEs Need ISO 27001 for NIS2?

NIS2 does not automatically require every business to become ISO 27001 certified. However, frameworks such as ISO 27001, the NIST Cybersecurity Framework and CIS Controls can help structure your cybersecurity program.

For many SMEs, full certification may be too much at the beginning. A better approach is to use these frameworks as guidance and build step by step.

Start with the basics:

  • Know your assets
  • Assess risks
  • Secure access
  • Back up data
  • Train employees
  • Prepare for incidents
  • Review suppliers
  • Document your measures

Once the foundation is strong, you can decide whether formal certification makes sense for your business.

How NIS2 Can Become a Business Advantage

NIS2 compliance may feel like another regulatory burden, but it can also become a competitive advantage.

Customers, partners and larger companies increasingly want to work with suppliers that are secure and reliable. If your business can demonstrate good cybersecurity practices, you may stand out from competitors that are still winging it.

Strong cybersecurity can help you:

  • Win trust from clients
  • Reduce downtime
  • Protect customer data
  • Avoid costly incidents
  • Improve supplier relationships
  • Qualify for larger contracts
  • Strengthen your reputation

In a digital economy, trust is currency. Cybersecurity helps you protect it.

What Should Your Business Do Now?

If you run a small or medium business in Europe, the best time to prepare for NIS2 is now. Waiting until enforcement begins or until a customer asks for proof will only create pressure.

Start with a simple action plan:

  1. Check if your business is directly or indirectly affected by NIS2.
  2. Assign someone responsible for cybersecurity preparation.
  3. Create a list of your systems, data and suppliers.
  4. Perform a basic risk assessment.
  5. Enable multi-factor authentication.
  6. Review backup and recovery procedures.
  7. Create an incident response plan.
  8. Train your employees.
  9. Review critical suppliers.
  10. Keep documentation as evidence.

You do not need to become perfect overnight. But you do need to start. Cybersecurity compliance is not a one-time project. It is an ongoing business process.

Conclusion

NIS2 raises the cybersecurity standard for businesses across Europe. For small and medium businesses, the directive may seem complicated at first, but the core message is straightforward: understand your risks, protect your systems, prepare for incidents, manage your suppliers, and make cybersecurity a leadership priority.

Even if your business is not directly covered by NIS2, your customers, partners, or suppliers may still expect stronger cybersecurity controls from you.

The smartest approach is to prepare early, focus on practical improvements and document what you do. Start with the basics: MFA, backups, risk assessment, incident response, supplier checks and employee training.

NIS2 is not just about avoiding fines. It is about protecting your business, your customers and your reputation in a world where cyber threats are no longer rare events. They are part of doing business.

Frequently Asked Questions About NIS2 Compliance

What does NIS2 mean for small businesses?

NIS2 may not apply to every small business directly, but small businesses can still be affected if they operate in a covered sector or supply services to organizations that must comply. Customers may ask for proof of cybersecurity controls.

Does NIS2 apply to all SMEs?

No. NIS2 mainly applies to organizations in specific sectors and usually to medium or large entities. However, some smaller organizations may still be covered depending on the services they provide.

What are the main NIS2 requirements?

The main requirements include cybersecurity risk management, incident handling, business continuity, supply-chain security, access control, encryption, multi-factor authentication, staff training and incident reporting.

What is the NIS2 incident reporting deadline?

For significant incidents, NIS2 generally requires an early warning within 24 hours, a more detailed notification within 72 hours and a final report within one month.

Do I need ISO 27001 for NIS2 compliance?

NIS2 does not automatically require ISO 27001 certification for every organization. However, ISO 27001 can help businesses build a structured cybersecurity management system.

What is the first step toward NIS2 compliance?

The first step is to determine whether your organization falls within the scope of NIS2. After that, create an asset inventory, perform a risk assessment, and start implementing basic cybersecurity measures.

Can NIS2 affect my business if I am only a supplier?

Yes. If your customers are covered by NIS2, they may require you to meet certain cybersecurity standards as part of their supply-chain risk management.

What cybersecurity measures should SMEs prioritize first?

SMEs should prioritize multi-factor authentication, secure backups, access control, patch management, employee awareness, supplier review, and an incident response plan.

Scroll to Top