Scan your site free
EU Compliance

Does NIS2 apply to your small business? A plain-English guide

July 20, 2026  ·  6 min read  ·  By masoSec

If you run a small business in the EU, you've probably heard the term "NIS2" somewhere — a client email, a supplier questionnaire, a LinkedIn post from a compliance consultant. Most of the coverage is written for large enterprises, which leaves smaller business owners with one real question unanswered: does this actually apply to me?

The honest answer is: probably not directly, but it might reach you anyway. Here's how the rules actually work.

What NIS2 is, in one paragraph

NIS2 (Directive (EU) 2022/2555) is the EU's updated cybersecurity law. It replaces the original 2016 NIS Directive and significantly widens both the number of sectors covered and the number of companies within those sectors that are regulated. The directive entered into force in January 2023, and EU member states were required to transpose it into national law by 17 October 2024 — so it's now live (or in the process of becoming fully enforced) across the EU, with national laws implementing it at slightly different paces.

Are you directly in scope? Two things decide it: sector and size

NIS2 splits regulated organisations into essential entities and important entities. Both categories only apply to companies operating in specific sectors listed in the directive's annexes:

Annex I — "highly critical" sectors

Energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management (B2B), public administration, and space.

Annex II — "other critical" sectors

Postal and courier services, waste management, chemicals, food production and distribution, certain manufacturing, digital providers (marketplaces, search engines, social networks), and research organisations.

On top of sector, there's a size threshold. As a general rule, NIS2 applies to medium and large organisations: roughly 50 or more employees, or more than €10 million in annual turnover or balance sheet total. Micro and small businesses below that threshold are generally excluded — with some specific exceptions regardless of size, such as sole providers of a critical service in a country, public administration bodies, providers of public electronic communications networks, and top-level domain name registries or DNS service providers.

So if you're a small business outside these sectors, or below the size threshold, you are very likely not directly regulated by NIS2.

Then why does everyone keep asking about it?

Because NIS2 doesn't stop at the companies it directly regulates. One of its core requirements — supply chain security — obliges every in-scope company to assess and manage the cybersecurity risk of its suppliers and service providers. In practice, that means a mid-size logistics company, hospital, or software vendor that is covered by NIS2 has to start asking its own vendors (that's potentially you) to demonstrate basic security controls.

This is showing up as security questionnaires attached to contract renewals, clauses requiring MFA and incident reporting, and occasionally full vendor security audits — sent to businesses that have never heard of NIS2 and aren't in scope themselves. If your biggest customer is a hospital, an energy company, a bank, or a larger IT/software provider, this is worth expecting even if the law never touches you directly.

NIS2 doesn't require your customers to only work with regulated suppliers. It requires them to know and manage the risk their suppliers introduce — and passing security requirements down the chain is the easiest way for a large company to do that.

What NIS2 actually requires (the baseline measures)

Whether you're formally in scope or just trying to satisfy a customer's security questionnaire, the underlying requirements (Article 21(2) of the directive) are the same practical baseline:

1

Risk analysis and security policy

A documented information security policy, reviewed at least annually.

2

Incident handling

A plan for detecting, responding to, and reporting security incidents, with defined roles.

3

Business continuity and backups

Tested backup and disaster recovery procedures with a realistic restore time.

4

Supply chain security

Assessing the cybersecurity practices of your own key suppliers — the same requirement that likely brought you here.

5

Secure development and patch management

Security built into how you acquire, build, and maintain IT systems, including timely patching.

6

Cyber hygiene and staff training

Regular security awareness training and enforced basics like password policies.

7

Cryptography

Encryption of sensitive data at rest and in transit, with a documented policy.

8

Access control and asset management

Least-privilege access, an inventory of systems, and periodic access reviews.

9

Multi-factor authentication

MFA enforced on remote access, admin consoles, email, and other privileged accounts.

If you're formally in scope: reporting deadlines and penalties

Entities that are directly regulated face strict incident reporting timelines: an early warning to the national authority or CSIRT within 24 hours of becoming aware of a significant incident, a more detailed notification within 72 hours, and a final report within one month. Penalties for non-compliance are substantial — up to €10 million or 2% of global annual turnover for essential entities, and up to €7 million or 1.4% of turnover for important entities, whichever is higher in each case.

If you're a small supplier rather than a directly regulated entity, these specific fines don't apply to you — but losing a contract for failing a security review carries its own cost.

What to actually do about it

1
Work out where you actually stand

Check your sector against Annex I/II and your size against the ~50-employee / €10M threshold. If you're unsure, check whether any of your contracts already reference NIS2 or ask for security attestations — that's often the clearest signal.

2
Fix the basics first

MFA on every privileged and remote-access account, SPF/DKIM/DMARC on your email domain, offsite backups that you've actually tested restoring, and a written (even short) incident response plan. These cover a large share of what any security questionnaire will ask.

3
Put it in writing

A one-page security policy reviewed annually satisfies the "documented policy" requirement in almost every framework, NIS2 included. Undocumented good practices don't count in an audit.

4
Run a self-assessment before your customer does

masoSec includes a free NIS2 self-assessment covering these exact baseline measures, so you can find and fix gaps before they show up in a vendor review. It's available from your masoSec dashboard once you sign up.

Start with your website and email — check them now

See your actual security score in about 10 seconds — no signup needed. This covers the technical basics (HTTPS, security headers, exposed files) that every NIS2 baseline starts with.