Themio · Regulatory Guides

NIS2: What It Means for Your SME

Cybersecurity obligations, sector scope and the transposition gap, explained with sourced 2026 data.

EU map highlighting France, Ireland, Spain and the Netherlands in relation to NIS2 transposition
NIS2 at a glance

The core facts for European executives

18 Critical Sectors

From energy, healthcare and water to digital infrastructure, public administration and IT services.

50+ Staff or €10M+

The standard scope threshold, plus smaller suppliers pulled in via critical supply chain clauses.

24h Incident Duty

Mandatory early-warning notice to national authorities within 24 hours of detecting a significant incident.

4 States at the CJEU

France, Ireland, Spain and the Netherlands referred to the Court of Justice of the EU over transposition delays.
Directive (EU) 2022/2555

What is NIS2

NIS2 (Directive EU 2022/2555) sets minimum cybersecurity standards across 18 sectors the EU treats as critical: energy, transport, health, water, banking, digital infrastructure, public administration, digital service providers, and more.

It replaced the 2016 NIS Directive and widened the net considerably, pulling in thousands of mid-sized companies the first version never touched.

Applicability criteria

Does NIS2 apply to your company

Two tests decide it. Size: 50 or more employees, or turnover above €10 million. Sector: your activity falls into one of the 18 categories the Directive lists as essential or important. Meet both and you're in scope, whether a regulator has contacted you or not.

The supply chain cascade:

NIS2 also reaches down into supply chains: if you supply software, IT services or hardware to a covered entity, that entity's NIS2 obligations can flow into your contract even if your own company sits below the size threshold.

Mandatory measures

Core obligations

1

Cyber Risk Management Programme

Run a cyber risk management programme covering your networks and information systems, policies on risk analysis, and information system security.

2

24-Hour Incident Notification

Notify significant incidents to your national authority within 24 hours of becoming aware, with a fuller report to follow.

3

Cybersecurity Governance Owner

Name a person responsible for cybersecurity governance, with direct management body oversight and accountability.

4

Supply Chain Risk Management

Manage supply chain risk, including your own suppliers' security posture and contractual verification.

Essential vs. Important Entities Supervision

Essential entities face direct supervision and can be audited without a prior incident; important entities are supervised reactively, typically after an incident or a complaint. Both carry the same core obligations; the difference is how closely a regulator watches you.

Four-stage visual of the core NIS2 compliance obligations
Enforcement update

Where transposition stands in September 2026

NIS2 was due for transposition into national law by 17 October 2024. As of 19 August 2026, France, Ireland, Spain and the Netherlands still had no fully notified transposition.

CJEU Referral (European Commission ip_26_1499):

The European Commission referred all four Member States (France, Ireland, Spain and the Netherlands) to the Court of Justice of the EU specifically for failing to notify their transposition measures, and is asking the Court for financial penalties—a lump sum plus daily payments—until transposition is complete. 23 of 27 Member States now report full transposition.

Don't wait for the French law

A missing national transposition doesn't mean a missing obligation. Sector regulators already hold security powers under existing national frameworks, and once the French law lands, the transition window is likely to be short. Companies that start now, mapping their systems, naming a security owner, drafting an incident response plan, arrive at the deadline with something to show. Companies that wait arrive with a document to write under pressure.

Benchmark & Field Data

What ENISA's own data shows

10.6%
of IT FTEs at EU organisations in NIS-covered sectors are dedicated to cybersecurity roles (ENISA, NIS Investments 2025).
81.1%
of cybercrime incidents affecting EU organisations over the past year involved ransomware.
~60%
of attack entry points involve phishing campaigns targeting employees.

SMEs report the smallest share of the sample and the lowest confidence in their ability to anticipate, withstand and recover from an incident. NIS2 compliance and basic security hygiene point at the exact same gap.

Frequently Asked Questions

Common questions about NIS2 for SMEs

My company has fewer than 50 employees. Does NIS2 still apply?
Usually not directly, but check your supply chain position. If a covered client requires you to meet NIS2-equivalent security terms in your contract, the obligation reaches you regardless of your own headcount. Small suppliers to hospitals, energy companies and public administrations see this most often.
What counts as a "significant incident" I need to report within 24 hours?
NIS2 doesn't give a single bright line; national guidance varies. As a working rule, an incident is significant if it causes, or could cause, severe operational disruption or financial loss, or affects other people or organisations. When in doubt, notify. Under-reporting carries more regulatory risk than over-reporting.
Is NIS2 enforced in France if the transposition law hasn't passed yet?
Partially. Without a transposition law, the specific NIS2 penalty regime isn't directly enforceable in France yet. But sector regulators retain existing powers under prior national cybersecurity frameworks, and the four-state CJEU referral, France included, signals the Commission expects transposition soon, likely with a short compliance runway once it lands.
What's the difference between an "essential" and an "important" entity?
Essential entities, larger organisations in the highest-criticality sectors like energy and banking, face proactive supervision: regulators can audit them without a prior incident. Important entities face reactive supervision, generally triggered by an incident or complaint. Both carry the same core obligations; the difference is how closely a regulator watches you.
How does NIS2 relate to GDPR and the AI Act?
They're separate regimes that often apply to the same company. GDPR governs personal data specifically; NIS2 governs the security of networks and systems generally, personal data or not. The AI Act governs AI systems specifically. A single security incident, a ransomware attack that exposes customer records for instance, can trigger notification duties under both GDPR and NIS2 at once. See the full SME Compliance Barometer for how all three interact.

Not sure where your company stands on NIS2, GDPR or the AI Act?

Audit your systems, detect compliance gaps, and generate your remediation roadmap in under 2 minutes with Themio.