Back to Blog Next Article
August 3, 2026 Nicolas Pinault (Co-founder & Product Development) 8 min read NIS2

NIS2 Compliance for SMEs in 2026:
Does It Apply to You and What Do You Need to Implement?

Executive Summary
  • NIS2 applies to medium and large companies in covered sectors - but three categories of smaller companies are caught even below the official thresholds.
  • Article 21 defines ten categories of cybersecurity measures that covered entities must implement: from risk analysis and MFA to supply chain security and business continuity.
  • Incident notification is strict: 24-hour early warning, 72-hour full notification, 1-month final report to your national authority.
  • NIS2 introduces personal liability for senior management - executives can face temporary bans from management roles for serious non-compliance.
  • The Cyber Resilience Act (CRA), applying from September 2026, fills the gap for software and connected product makers that NIS2 misses.
10
Article 21 Measures

obligatory categories of cybersecurity measures that covered entities must implement under NIS2.

24 h
Early Warning

strict deadline to notify your national authority (ANSSI) after detecting a significant cybersecurity incident.

Most SMEs Think They Are Exempt. Some Are Wrong.

NIS2 has a clear size threshold: it applies to medium and large companies - broadly, those with 50 or more employees or €10 million or more in annual turnover, operating in a covered sector. If you run a 15-person software consultancy or a 30-person e-commerce operation, you might assume the directive does not concern you.

You may be right. But there are three situations where smaller companies are caught regardless of size. Just like with the GDPR , there is no absolute exemption for small businesses if they are part of a critical supply chain. Most SMEs think they are exempt (see our latest compliance statistics ). Some are wrong.

First : if your company is the sole provider of a service essential to the economy or public safety in your member state, NIS2 applies regardless of headcount. Sole providers of niche critical infrastructure services are explicitly in scope.

Second : if you are an ICT or digital service provider in the supply chain of a covered entity, your client's NIS2 obligations cascade to you. Article 21(3) requires covered entities to assess the cybersecurity practices of their direct suppliers and service providers. In practice, this means covered companies are now inserting cybersecurity requirements into procurement contracts with smaller vendors. Your client's NIS2 compliance becomes your contractual obligation, regardless of whether NIS2 directly applies to you.

Third : if your company manufactures or distributes software or connected products placed on the EU market, the Cyber Resilience Act (CRA) applies to you from September 2026 - independently of NIS2 and independently of your size. The CRA has no SME size-based exemption for product makers. Furthermore, if you use AI tools in your operations, you must also navigate the intersection of NIS2 and the EU AI Act .

What NIS2 Is and Who It Covers

NIS2 (Directive EU 2022/2555) replaced the original NIS Directive in October 2024. Its transposition deadline was 17 October 2024. Most EU member states have transposed; France's transposition via ANSSI is progressing, with full application expected in the course of 2025.

NIS2 divides covered entities into two tiers:

Essential entities - large companies (250+ employees or €50M+ turnover and €43M+ balance sheet) in the most critical sectors: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space.

Important entities - medium companies (50+ employees or €10M+ turnover and €10M+ balance sheet) in a second tier of sectors: postal and courier services, waste management, chemicals, food production and distribution, manufacturing (medical devices, computers, electronics, machinery, motor vehicles), digital providers (online marketplaces, online search engines, social networking platforms), and research.

Company profile NIS2 applies? Notes
EU company, covered sector, 50+ employees or €10M+ turnover ✅ Yes Important entity minimum
EU company, covered sector, 250+ employees or €50M+ turnover ✅ Yes Essential entity
EU company, covered sector, below 50 employees and below €10M ⚠️ Possibly If sole provider of critical service, or designated by member state
EU company, non-covered sector ❌ No NIS2 does not apply directly
EEA company (Norway, Iceland, Liechtenstein) ✅ Yes NIS2 incorporated via EEA Agreement
Non-EU company operating in EU ✅ If in scope Must designate EU representative if providing services in EU
Any size, EU market software/hardware manufacturer ✅ Via CRA Cyber Resilience Act applies from September 2026 (reporting) / December 2027 (full)
SME as ICT supplier to NIS2-covered client ⚠️ Indirectly Article 21(3) supply chain obligations flow down via contract

The 10 Article 21 Cybersecurity Measures

Article 21 of NIS2 specifies ten categories of risk management measures that covered entities must implement. These are not aspirational - they are enforceable obligations. Here is what each means in practice for a tech-oriented SME.

  • 1. Risk analysis and information system security policies: You need a documented, regularly reviewed information security policy that covers your risk landscape - assets, threats, vulnerabilities, and treatment plans. This is the foundation everything else sits on.
  • 2. Incident handling: A defined procedure for detecting, classifying, and responding to security incidents. This includes who gets called, what gets logged, when regulators get notified, and how you communicate with affected parties.
  • 3. Business continuity and crisis management: Backup management, disaster recovery plans, and documented crisis management procedures. Specifically: can your systems recover from a ransomware attack within your business's acceptable downtime?
  • 4. Supply chain security: Assess the cybersecurity posture of your direct suppliers and service providers - cloud providers, SaaS tools, hardware vendors, and subcontractors. This does not require an audit of every vendor, but it does require a structured approach to supplier risk assessment.
  • 5. Security in network and information systems acquisition, development and maintenance: Security must be built into how you procure, develop, and maintain systems - not added later. For development teams, this means secure coding practices, dependency management, and vulnerability testing in the CI/CD pipeline.
  • 6. Policies to assess the effectiveness of security measures: You cannot just implement measures - you must verify they work. This means security testing (penetration testing, vulnerability assessments), metrics, and regular review cycles.
  • 7. Cybersecurity hygiene and training: All staff with access to information systems must receive basic cybersecurity training. Management must be trained and must formally oversee and approve the organisation's cybersecurity risk management measures (Article 20).
  • 8. Policies on cryptography and encryption: A documented approach to where encryption is applied, which algorithms and key lengths are used, and how keys are managed and rotated. This covers data at rest and data in transit.
  • 9. Human resources security and access control: Defined joiners/movers/leavers processes, role-based access control, and - critically - multi-factor authentication (MFA). NIS2 explicitly requires MFA or continuous authentication for access to sensitive systems.
  • 10. Use of multi-factor authentication and secure communications: MFA is not optional under NIS2 for covered entities. This includes internal systems, remote access, and privileged accounts. Secure communication channels must also be used for sensitive internal communications.

Incident Notification: The 24/72/1-Month Timeline

Under Article 23, covered entities must follow a three-stage notification process when a significant incident occurs:

Stage Deadline What to report
Early warning 24 hours Basic facts: incident detected, suspected cause, initial scope
Incident notification 72 hours Initial assessment: severity, impact, indicators of compromise
Final report 1 month Full technical details, root cause, remediation steps taken

A significant incident is one that causes or could cause severe operational disruption or financial loss to the entity - or material damage to others. The determination is yours to make in the first 24 hours, which is why having a pre-written incident response process matters.

In France, notifications go to ANSSI. ANSSI has published guidance on notification formats and thresholds at ssi.gouv.fr .

Management Personal Liability

NIS2 introduced something that surprised many European executives: personal liability of senior management (Article 20).

Management bodies must approve cybersecurity risk management measures, oversee their implementation, and receive regular cybersecurity training. Member states are required to hold management personally liable for negligence when NIS2 obligations are not met. This can include temporary bans from management roles for individuals at essential entities in serious cases.

For a CTO or CISO, this means cybersecurity is no longer a department-level matter - it is a board-level accountability with personal consequences.

Key Deadlines

Obligation Deadline / Status
NIS2 application in EU (where transposed) 18 October 2024
France full transposition (ANSSI) In progress - expected 2025; verify at ssi.gouv.fr
CRA reporting obligations (software/product makers) 11 September 2026
CRA full application 11 December 2027
Incident early warning 24 hours from detection
Incident full notification 72 hours from detection
Incident final report 1 month after notification

For EEA and Accession Country Companies

EEA companies (Norway, Iceland, Liechtenstein): NIS2 has been incorporated into the EEA Agreement. Norwegian, Icelandic, and Liechtenstein companies meeting the size and sector thresholds face equivalent obligations. The Norwegian National Security Authority (NSM), the Icelandic CERT (FME), and Liechtenstein's relevant authority are the national competent authorities.

Serbia - EU accession status: Candidate. NIS alignment is a requirement under Chapter 10 (Information society and media) of the accession negotiations. Serbian technology companies with EU clients are increasingly required to demonstrate NIS2-equivalent security practices by their EU customers - even before domestic law requires it.

Ukraine - EU accession status: Candidate (June 2022). Ukraine's cybersecurity framework is being revised as part of the EU acquis alignment. Ukrainian IT and software companies - a significant sector - exporting to EU clients should implement NIS2-aligned security practices now as a market access requirement.

Montenegro, Albania, North Macedonia - All three have EU accession obligations to align domestic cybersecurity legislation with the NIS2 framework. Companies in these markets serving EU customers should treat NIS2-level security as a current due diligence requirement, not a future one. Refer to ENISA guidance for more EU coordination updates.

Frequently Asked Questions

My company has 40 employees and €8 million revenue. Does NIS2 apply to us?
Not directly, provided you are not a sole provider of a critical service and your member state has not specifically designated your entity. However, if you supply ICT services or software to companies covered by NIS2, your clients' Article 21(3) supply chain obligations will likely flow to you via contract. You may also fall within scope of the Cyber Resilience Act (CRA) if your company places software or connected products on the EU market.
What does 'significant incident' mean under NIS2 and when must we notify ANSSI?
Under Article 23 of NIS2, a significant incident is one that causes or is capable of causing severe operational disruption to your services or financial loss to your organisation, or significant damage to other persons. If you detect an incident crossing that threshold, you must file an early warning with your national competent authority (ANSSI in France) within 24 hours of becoming aware — even if your information is incomplete. A full incident notification follows within 72 hours, and a final report within 1 month.
Does NIS2 require us to appoint a dedicated CISO?
NIS2 does not require a named CISO by title, but Article 20 requires that the management body approves and oversees cybersecurity risk management measures. In practice, for medium-sized covered entities, someone must own cybersecurity accountability at a senior level — whether that is the CTO, a dedicated CISO, or a qualified external provider.
We are a 20-person software company. Does NIS2 or the Cyber Resilience Act apply to us?
NIS2 likely does not apply directly given your size, unless you are in the supply chain of a NIS2-covered entity or a sole critical service provider. However, the Cyber Resilience Act (CRA, Regulation EU 2024/2847) applies to any company that places software or products with digital elements on the EU market — with no size-based exemption for the product-maker. CRA reporting obligations apply from 11 September 2026; full obligations from 11 December 2027.
We are a Serbian company supplying cloud services to French clients. Does NIS2 apply?
NIS2 itself applies to entities established in EU member states, so as a Serbian company you are not directly in scope. However, your French clients — if they are NIS2-covered entities — must assess the cybersecurity practices of their supply chain under Article 21(3). In practice, this means you will face contractual cybersecurity requirements from covered EU clients. Aligning to NIS2 standards now protects your commercial relationships and positions you competitively as EU accession progresses.
Nicolas Pinault

Nicolas Pinault leads the technical architecture of Themio's AI compliance platform and has implemented NIS2-aligned security measures across Themio's EU cloud infrastructure.

Themio.ai automates NIS2 scope assessment and gap analysis for SMEs - find out in under 2 minutes whether NIS2 applies to your company and where your gaps are against Article 21. Run your NIS2 check →