← Back to Insights
June 2026·5 min read

NIS2: What SMEs Need to Know Before the Deadline

The NIS2 Directive is the EU's updated cybersecurity law, and it's broader than most people realise. If your business operates in the EU — or sells to companies that do — there's a reasonable chance it applies to you or your customers.

What is NIS2?

NIS2 (Network and Information Security Directive 2) replaces the original NIS Directive from 2016. It significantly expands the number of sectors and organisations covered, and it increases the obligations on those organisations to manage cybersecurity risk.

The directive came into force in January 2023, with EU member states required to transpose it into national law by October 2024.

Who does it apply to?

NIS2 covers two categories of organisations:

Essential entities — sectors like energy, transport, banking, health, water, and digital infrastructure. These face the strictest obligations and oversight.

Important entities — a broader set including manufacturing, food production, postal services, waste management, and digital providers. This is where most SMEs will fall if they're in scope.

Size matters: generally, organisations with 50+ employees or €10M+ in annual turnover in a covered sector are in scope. But smaller companies can also be caught if they're deemed critical to supply chains.

What does it require?

At its core, NIS2 requires organisations to:

- Implement risk management measures (think: access controls, incident response, encryption, supply chain security) - Report significant incidents to national authorities within 24–72 hours - Ensure senior management is accountable for cybersecurity — this is a key change from NIS1 - Assess and manage cybersecurity risks in your supply chain

The penalties for non-compliance are significant: up to €10M or 2% of global annual turnover for important entities, and up to €20M or 4% for essential entities.

What should you do now?

Step 1: Determine if you're in scope. Check your sector and size against the NIS2 criteria. If you're unsure, assume you are and work backwards.

Step 2: Gap assess your current controls. NIS2 doesn't prescribe a specific framework, but ISO 27001 or the NIST Cybersecurity Framework map well to its requirements. A gap assessment will show you where you stand.

Step 3: Fix the basics first. Multi-factor authentication, patching, access reviews, and an incident response plan will address a significant portion of NIS2's requirements and are good practice regardless.

Step 4: Document everything. NIS2 requires you to demonstrate compliance, not just achieve it. Policies, risk registers, and evidence of controls matter.

Step 5: Get your supply chain in order. If you're a supplier to larger organisations, expect to receive security questionnaires. If you're a buyer, you need to be asking them.

The deadline has passed for most member states. If you haven't started, the time to act is now — not when you receive a questionnaire from a customer or a notice from a regulator.

Want to talk through what this means for your business?

Get in touch