NIS2 and small businesses: are you in scope?
What the NIS2 directive requires, which organisations it covers, and why suppliers to in-scope organisations feel it even when they are not directly covered.
The short answer
NIS2 is the European directive raising cybersecurity requirements across the union. It applies to entities classified as essential or important in listed sectors, energy, transport, banking, health, water, digital infrastructure, public administration, manufacturing of certain products, postal services, waste, food and others, generally capturing entities of the types listed in Annexes I and II that meet or exceed the medium-sized enterprise thresholds of Commission Recommendation 2003/361/EC, with some entities covered regardless of size. It requires risk management measures, incident handling with reporting deadlines, business continuity, supply chain security, access control, encryption and training, and it makes management bodies accountable for approving and overseeing those measures, with penalties for non-compliance. Direct scope is narrow and is defined by sector and size. Many nevertheless feel it, because in-scope organisations must manage supply chain risk and pass requirements down to their suppliers through contracts and questionnaires. Because scope, registration and enforcement live in national implementing law, the reliable place to check your position is your national authority rather than the directive text.
What it requires of in-scope entities
| Area | Requirement in outline |
|---|---|
| Risk management | Policies and measures proportionate to the risk, approved by management |
| Incident handling | Detection, response, and reporting to the national authority: for a significant incident an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours, and a final report within one month of that notification (Article 23(4)) |
| Business continuity | Backups, disaster recovery, crisis management |
| Supply chain security | Assessing and managing risk from suppliers and service providers |
| Access control | Identity management, multi-factor authentication, privileged access |
| Encryption and cryptography | Policies on use |
| Security in acquisition and development | Requirements through the lifecycle of systems |
| Effectiveness testing | Assessing whether measures work |
| Training | For staff and for management |
| Management accountability | Governing bodies approve and oversee; potential personal consequences |
What a small supplier should do
- Check your direct scope with your national authority’s guidance and sector criteria.
- Ask your largest customers whether they are in scope and what they will require of suppliers.
- Put the basics in place: asset and access register, multi-factor authentication everywhere, patching within defined times, tested backups, logging.
- Write the incident response plan with roles and a notification commitment to customers.
- Train staff on phishing and reporting, and record that you did.
- Prepare a security summary you can send in response to questionnaires.
- Review contracts for security and notification clauses you are agreeing to.
- Revisit annually, since national implementations and customer requirements continue to develop.
The useful framing
For a small business, NIS2 is best understood not as a compliance project but as the reason your customers will start asking for security evidence. The measures it names are the ones a well-run small business should already have, and having them lets you answer a questionnaire in a day and win work that requires it. Businesses that treat it as an opportunity to tidy their security posture come out ahead of those that treat it as paperwork to survive.
What this means for you
NIS2 directly covers essential and important entities in listed sectors, generally medium and large, under national implementing law. A small business is outside it and is reached through customers’ supply chain requirements instead. Check your direct scope nationally, ask your major customers, put the basic measures in place, write the incident plan, and prepare a security summary. This is general information rather than legal advice.
Frequently asked questions
How do we know whether NIS2 applies to us?
Scope depends on sector and size under national implementing law. The directive lists sectors of high criticality and other critical sectors, and generally captures medium and large entities within them, with some entities in scope regardless of size. A typical small business outside those sectors is not directly covered. Because member states implement and register entities differently, the reliable answer comes from your national authority's guidance rather than from reading the directive.
Why are our customers asking about it then?
Because in-scope organisations must manage supply chain risk, which they do by imposing requirements on suppliers. So a small IT supplier, web agency or software vendor serving a hospital, an energy company or a large manufacturer will be asked for security measures, incident notification commitments and evidence. You are not regulated directly; you are contractually required, and the practical effect is similar.
What should a small supplier do?
Put the basics in place and be able to evidence them: an asset and access register, multi-factor authentication, patching within defined times, tested backups, an incident response plan with notification timelines, staff awareness training, and a security summary you can send. That package answers most supply chain questionnaires and is worth having regardless of any directive.
Sources
- European Commission: NIS2 Directive (accessed 2026-09-12)
- EUR-Lex: Directive (EU) 2022/2555 (NIS2) (accessed 2026-09-12)