Table of Contents
NIS2 for small businesses: what changes in practice?
NIS2 for small businesses is not a question of buying a certificate or copying a policy template. Most small firms are not automatically regulated directly by NIS2. Scope depends primarily on the activity performed, the applicable size test, possible size-independent categories and national designation. NIS2 is an EU directive: the relevant Member State’s implementing law determines the competent authority, registration route and local procedures.
The Commission’s NIS2 page, updated 2 July 2026, records uneven transposition across Member States. Before treating any deadline, reporting route or penalty as applicable, check the implementing law for each country in which the business operates.
Legal scope and commercial impact are different questions. A supplier outside direct scope does not automatically inherit every Article 21 duty merely because it serves a regulated customer. That customer may still require security controls, incident-notification commitments and recovery evidence as conditions of doing business.
For NIS2 for small businesses, the practical priority is evidence of repeatable operations: an asset and access list, named patch ownership, tested recovery, an incident call tree and management review of cyber risks. These measures align with the risk-management categories in Article 21.
Is the company legally in scope for NIS2 for small businesses?
Article 2 of Directive (EU) 2022/2555 uses a sector-plus-size test, rather than headcount alone. The directive was adopted on 14 December 2022 and published on 27 December 2022. Those dates identify the legal source; the implementing law in the relevant Member State must be checked before relying on a scope conclusion.
| Question | What to check |
|---|---|
| Does the company perform an Annex I or II activity? | Start with the actual service or sector, such as energy, transport, health, digital infrastructure or certain digital providers. |
| Is it at least medium-sized? | The default rule generally captures medium-sized and larger entities in covered sectors. |
| Is it a small enterprise? | Under the EU SME definition, fewer than 50 employees and turnover and/or balance-sheet total not exceeding €10 million. |
| Does a specific exception apply? | Public electronic communications, trust, DNS/TLD and domain-registration providers can fall in scope regardless of size. |
| Could national law designate it? | Member States may include smaller entities that are uniquely critical, sole providers or have cross-border significance. |
Do not treat the €10 million threshold as a safe harbour. Ownership, partner companies and linked enterprises can affect the calculation. Managed service provider status also needs a country- and service-specific assessment: it should not be assumed that either MSP status or an employee count resolves scope by itself.
The first decision in NIS2 for small businesses is therefore not “Are we under 50 people?” It is “What services do we provide, where do we provide them, and how does the applicable national law classify us?” Obtain qualified local advice where the answer affects registration, reporting or enforcement exposure.

What is the difference between direct duties and supplier pressure?
The distinction is legal, even when the practical controls look similar. An entity in scope has duties imposed through national NIS2 law. An out-of-scope supplier may face contractual obligations that reflect its customer’s regulatory exposure.
| Question | Entity directly in scope | Out-of-scope supplier |
|---|---|---|
| Legal duties | Must meet applicable national rules implementing Articles 21 and 23. | Article 21 does not automatically apply. Duties may arise from contract, other laws or later designation. |
| Evidence requests | Access records, patch ownership, backup tests, incident roles and management oversight may be needed. | Customers may request MFA, restoration results, subcontractor details and vulnerability-notification terms. |
| Incident reporting | A significant incident can trigger statutory reporting under national procedures. | A contract may require prompt customer notice; that is not automatically a report to an authority. |
Supply-chain pressure is often the main real-world impact of NIS2 for small businesses. Regulated customers must address security aspects of relationships with direct suppliers and service providers. The directive does not prescribe one universal supplier questionnaire, so exact requirements vary by buyer, contract and country.
Scenario: a 25-person payroll-services supplier is not directly in scope after local advice, but its regulated customer requires MFA, quarterly access reviews and notice within four hours of a suspected breach. The supplier’s immediate risk is losing the contract if it cannot meet those commitments, not automatically receiving an NIS2 fine.
By contrast, a small digital provider should not dismiss NIS2 because of headcount alone. If its service falls within a size-independent category or it is designated under national law, it may have direct obligations. The relevant authority and implementing law decide that question.
Which NIS2 for small businesses controls create useful evidence rather than compliance theatre?
Article 21 of NIS2 calls for proportionate risk-management measures across assets, access, continuity, suppliers and incident handling. For NIS2 for small businesses, start with routines that reduce downtime and leave an operational trail rather than documents nobody uses.
- Maintain an asset inventory covering devices, cloud services, critical software, administrators and data owners.
- Name an owner for patching each system, set deadlines by severity and record exceptions and remediation decisions.
- Use MFA where appropriate, especially for email, remote access, administrator accounts and cloud consoles.
- Apply least privilege and remove access promptly when staff leave or change roles.
- Separate backups from the main environment and retain dated restoration-test records.
- Track vulnerabilities from discovery to closure, including ownership, mitigation and accepted risk.
- Review suppliers with access to systems or data, including their contacts, subcontractors and notification commitments.
Build an incident-response plan around real decisions: who investigates, who can isolate systems, who contacts customers and who decides whether a report is required. ISO 27001 can support governance, but certification alone does not determine scope, reporting duties or compliance with national law.
A clean backup restored during an exercise is more valuable than an untested statement that backups exist. It demonstrates continuity capability, gives management a realistic recovery picture and provides evidence that can answer customer due-diligence questions.

Who owns cybersecurity when the IT work is outsourced?
Outsourcing IT does not outsource management accountability. For an entity directly in scope, management remains responsible for ensuring that risks are addressed, decisions are recorded and incident obligations can be met. An MSP can operate systems and provide expertise, but it cannot replace the business’s governance.
This is a central governance point for NIS2 for small businesses: a founder or management body should be able to show who reviews cyber risk, approves priorities and budget, and receives the results of recovery or incident exercises. Hiring an MSP is not evidence that those decisions have been made.
The contract and operating model should define who patches which systems, who approves privileged access, who monitors alerts, who can isolate a compromised account and how quickly the MSP must escalate an incident. Keep an up-to-date list of administrator accounts, support contacts and systems covered by the agreement.
Ask for evidence that matters during disruption: backup and restoration-test results, logging availability, patch reports, access-review records, subcontractor details and incident-notification duties. Test the escalation route. If the MSP is unavailable on a Friday evening, the company should still know who can authorise containment, contact customers and obtain access to logs and backups.

What must happen during a significant incident?
For entities directly in scope, containment and reporting may happen at the same time. A ransomware attack affecting core systems, a serious outage or a breach affecting customers may trigger the process, but local law and the competent authority determine what counts as significant.
Under Article 23 of NIS2, the directive sets outer limits of an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and normally a final report within one month. Verify national reporting channels, forms, procedures and deadlines.
For NIS2 for small businesses, a 24-hour first-report capability requires preparation before an incident: a call tree, authority or CSIRT contact route, basic access to relevant logs and clear authority to decide. Do not assume a customer-notification clause is the same as a statutory report.
- Maintain an offline call tree covering management, IT, the MSP, legal advisers and communications owners.
- Give named people authority to classify incidents, engage responders and submit reports.
- Keep authority, CSIRT and customer escalation contacts accessible when normal systems are unavailable.
- Test access to logs, administrator accounts, asset records and backup status.
Why should a small company care about fines and business disruption?
The immediate cost of weak security is often operational: halted orders, unavailable payroll, emergency technical support, replacement hardware and lost working days. Customer impact can lead to delayed renewals, paused contracts or tougher checks at the next tender. This business-resilience case matters whether or not NIS2 directly applies.
For directly covered firms, Article 34 of the NIS2 Directive requires Member States to provide maximum administrative fines of at least €10 million or 2% of worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities, whichever is higher.
These are minimum maximum levels, not automatic penalties. Classification, national law and enforcement determine what applies. For NIS2 for small businesses, leading with recoverability, customer trust and contractual readiness is usually more useful than focusing only on maximum fines designed for entities that may be far larger than the reader.

What should the owner do in the next 30 days?
- Identify the countries, sectors and services the company actually provides, then check the applicable implementing law and authority.
- Verify employee, turnover and balance-sheet figures, including linked and partner enterprises.
- Classify the position as directly in scope, potentially designated or commercially exposed as a supplier.
- Inventory critical systems, data, privileged accounts, cloud services and suppliers.
- Enable MFA where feasible, remove unnecessary privileged access and test one clean backup restoration.
- Agree incident roles and MSP escalation duties, then rehearse a ransomware or account-takeover scenario.
- Keep a usable register of access reviews, restore tests, supplier checks, incidents and management decisions.
Use this checklist to turn NIS2 for small businesses into a proportionate operating programme. Start with the controls that protect the services customers depend on, then keep evidence that they are working. Review the site’s cybersecurity resources alongside local legal and regulatory guidance.
Seek qualified local legal advice on scope, designation, penalties and reporting. Do not wait for a perfect legal answer before fixing weak access controls or testing whether the business can recover.







