- NIS2 applies to medium and large companies in covered sectors - but three categories of smaller companies are caught even below the official thresholds.
- Article 21 defines ten categories of cybersecurity measures that covered entities must implement: from risk analysis and MFA to supply chain security and business continuity.
- Incident notification is strict: 24-hour early warning, 72-hour full notification, 1-month final report to your national authority.
- NIS2 introduces personal liability for senior management - executives can face temporary bans from management roles for serious non-compliance.
- The Cyber Resilience Act (CRA), applying from September 2026, fills the gap for software and connected product makers that NIS2 misses.
Most SMEs Think They Are Exempt. Some Are Wrong.
NIS2 has a clear size threshold: it applies to medium and large companies - broadly, those with 50 or more employees or €10 million or more in annual turnover, operating in a covered sector. If you run a 15-person software consultancy or a 30-person e-commerce operation, you might assume the directive does not concern you.
You may be right. But there are three situations where smaller companies are caught regardless of size. Just like with the GDPR , there is no absolute exemption for small businesses if they are part of a critical supply chain. Most SMEs think they are exempt (see our latest compliance statistics ). Some are wrong.
First : if your company is the sole provider of a service essential to the economy or public safety in your member state, NIS2 applies regardless of headcount. Sole providers of niche critical infrastructure services are explicitly in scope.
Second : if you are an ICT or digital service provider in the supply chain of a covered entity, your client's NIS2 obligations cascade to you. Article 21(3) requires covered entities to assess the cybersecurity practices of their direct suppliers and service providers. In practice, this means covered companies are now inserting cybersecurity requirements into procurement contracts with smaller vendors. Your client's NIS2 compliance becomes your contractual obligation, regardless of whether NIS2 directly applies to you.
Third : if your company manufactures or distributes software or connected products placed on the EU market, the Cyber Resilience Act (CRA) applies to you from September 2026 - independently of NIS2 and independently of your size. The CRA has no SME size-based exemption for product makers. Furthermore, if you use AI tools in your operations, you must also navigate the intersection of NIS2 and the EU AI Act .
What NIS2 Is and Who It Covers
NIS2 (Directive EU 2022/2555) replaced the original NIS Directive in October 2024. Its transposition deadline was 17 October 2024. Most EU member states have transposed; France's transposition via ANSSI is progressing, with full application expected in the course of 2025.
NIS2 divides covered entities into two tiers:
Essential entities - large companies (250+ employees or €50M+ turnover and €43M+ balance sheet) in the most critical sectors: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space.
Important entities - medium companies (50+ employees or €10M+ turnover and €10M+ balance sheet) in a second tier of sectors: postal and courier services, waste management, chemicals, food production and distribution, manufacturing (medical devices, computers, electronics, machinery, motor vehicles), digital providers (online marketplaces, online search engines, social networking platforms), and research.
| Company profile | NIS2 applies? | Notes |
|---|---|---|
| EU company, covered sector, 50+ employees or €10M+ turnover | ✅ Yes | Important entity minimum |
| EU company, covered sector, 250+ employees or €50M+ turnover | ✅ Yes | Essential entity |
| EU company, covered sector, below 50 employees and below €10M | ⚠️ Possibly | If sole provider of critical service, or designated by member state |
| EU company, non-covered sector | ❌ No | NIS2 does not apply directly |
| EEA company (Norway, Iceland, Liechtenstein) | ✅ Yes | NIS2 incorporated via EEA Agreement |
| Non-EU company operating in EU | ✅ If in scope | Must designate EU representative if providing services in EU |
| Any size, EU market software/hardware manufacturer | ✅ Via CRA | Cyber Resilience Act applies from September 2026 (reporting) / December 2027 (full) |
| SME as ICT supplier to NIS2-covered client | ⚠️ Indirectly | Article 21(3) supply chain obligations flow down via contract |
The 10 Article 21 Cybersecurity Measures
Article 21 of NIS2 specifies ten categories of risk management measures that covered entities must implement. These are not aspirational - they are enforceable obligations. Here is what each means in practice for a tech-oriented SME.
- 1. Risk analysis and information system security policies: You need a documented, regularly reviewed information security policy that covers your risk landscape - assets, threats, vulnerabilities, and treatment plans. This is the foundation everything else sits on.
- 2. Incident handling: A defined procedure for detecting, classifying, and responding to security incidents. This includes who gets called, what gets logged, when regulators get notified, and how you communicate with affected parties.
- 3. Business continuity and crisis management: Backup management, disaster recovery plans, and documented crisis management procedures. Specifically: can your systems recover from a ransomware attack within your business's acceptable downtime?
- 4. Supply chain security: Assess the cybersecurity posture of your direct suppliers and service providers - cloud providers, SaaS tools, hardware vendors, and subcontractors. This does not require an audit of every vendor, but it does require a structured approach to supplier risk assessment.
- 5. Security in network and information systems acquisition, development and maintenance: Security must be built into how you procure, develop, and maintain systems - not added later. For development teams, this means secure coding practices, dependency management, and vulnerability testing in the CI/CD pipeline.
- 6. Policies to assess the effectiveness of security measures: You cannot just implement measures - you must verify they work. This means security testing (penetration testing, vulnerability assessments), metrics, and regular review cycles.
- 7. Cybersecurity hygiene and training: All staff with access to information systems must receive basic cybersecurity training. Management must be trained and must formally oversee and approve the organisation's cybersecurity risk management measures (Article 20).
- 8. Policies on cryptography and encryption: A documented approach to where encryption is applied, which algorithms and key lengths are used, and how keys are managed and rotated. This covers data at rest and data in transit.
- 9. Human resources security and access control: Defined joiners/movers/leavers processes, role-based access control, and - critically - multi-factor authentication (MFA). NIS2 explicitly requires MFA or continuous authentication for access to sensitive systems.
- 10. Use of multi-factor authentication and secure communications: MFA is not optional under NIS2 for covered entities. This includes internal systems, remote access, and privileged accounts. Secure communication channels must also be used for sensitive internal communications.
Incident Notification: The 24/72/1-Month Timeline
Under Article 23, covered entities must follow a three-stage notification process when a significant incident occurs:
| Stage | Deadline | What to report |
|---|---|---|
| Early warning | 24 hours | Basic facts: incident detected, suspected cause, initial scope |
| Incident notification | 72 hours | Initial assessment: severity, impact, indicators of compromise |
| Final report | 1 month | Full technical details, root cause, remediation steps taken |
A significant incident is one that causes or could cause severe operational disruption or financial loss to the entity - or material damage to others. The determination is yours to make in the first 24 hours, which is why having a pre-written incident response process matters.
In France, notifications go to ANSSI. ANSSI has published guidance on notification formats and thresholds at ssi.gouv.fr .
Management Personal Liability
NIS2 introduced something that surprised many European executives: personal liability of senior management (Article 20).
Management bodies must approve cybersecurity risk management measures, oversee their implementation, and receive regular cybersecurity training. Member states are required to hold management personally liable for negligence when NIS2 obligations are not met. This can include temporary bans from management roles for individuals at essential entities in serious cases.
For a CTO or CISO, this means cybersecurity is no longer a department-level matter - it is a board-level accountability with personal consequences.
Key Deadlines
| Obligation | Deadline / Status |
|---|---|
| NIS2 application in EU (where transposed) | 18 October 2024 |
| France full transposition (ANSSI) | In progress - expected 2025; verify at ssi.gouv.fr |
| CRA reporting obligations (software/product makers) | 11 September 2026 |
| CRA full application | 11 December 2027 |
| Incident early warning | 24 hours from detection |
| Incident full notification | 72 hours from detection |
| Incident final report | 1 month after notification |
For EEA and Accession Country Companies
EEA companies (Norway, Iceland, Liechtenstein): NIS2 has been incorporated into the EEA Agreement. Norwegian, Icelandic, and Liechtenstein companies meeting the size and sector thresholds face equivalent obligations. The Norwegian National Security Authority (NSM), the Icelandic CERT (FME), and Liechtenstein's relevant authority are the national competent authorities.
Serbia - EU accession status: Candidate. NIS alignment is a requirement under Chapter 10 (Information society and media) of the accession negotiations. Serbian technology companies with EU clients are increasingly required to demonstrate NIS2-equivalent security practices by their EU customers - even before domestic law requires it.
Ukraine - EU accession status: Candidate (June 2022). Ukraine's cybersecurity framework is being revised as part of the EU acquis alignment. Ukrainian IT and software companies - a significant sector - exporting to EU clients should implement NIS2-aligned security practices now as a market access requirement.
Montenegro, Albania, North Macedonia - All three have EU accession obligations to align domestic cybersecurity legislation with the NIS2 framework. Companies in these markets serving EU customers should treat NIS2-level security as a current due diligence requirement, not a future one. Refer to ENISA guidance for more EU coordination updates.
Frequently Asked Questions
My company has 40 employees and €8 million revenue. Does NIS2 apply to us?
What does 'significant incident' mean under NIS2 and when must we notify ANSSI?
Does NIS2 require us to appoint a dedicated CISO?
We are a 20-person software company. Does NIS2 or the Cyber Resilience Act apply to us?
We are a Serbian company supplying cloud services to French clients. Does NIS2 apply?
Themio.ai automates NIS2 scope assessment and gap analysis for SMEs - find out in under 2 minutes whether NIS2 applies to your company and where your gaps are against Article 21. Run your NIS2 check →