ComplianceEuropeCybersecurity, Privacy & Compliance

NIS2 Compliance Checklist for SMEs

A practical readiness checklist for SMEs assessing whether NIS2 or national implementing law may affect their organisation, customers or supply-chain obligations.

MENTARA Editorial
On this page
Quick orientationCybersecurity, Privacy & Compliance

A practical readiness checklist for SMEs assessing whether NIS2 or national implementing law may affect their organisation, customers or supply-chain obligations.

NIS2EuropeCyber SecurityCompliance

What NIS2 actually is

NIS2 is an EU directive on cyber security that replaced the original 2016 NIS rules. The critical word is directive: it is not directly binding law. Each member state had to write it into national law, which means your actual obligations come from your national statute, not from the EU text.

Two consequences follow, and both catch SMEs out:

  • The rules differ by country. Scope, registration process and reporting portals vary.
  • The deadline has passed. Transposition was due 17 October 2024. As of mid-2026 roughly 23 of 27 member states have fully transposed, and first fines have already landed in Belgium, Italy and Hungary.

Are you actually in scope?

Most SMEs are not directly in scope. Scope is a combination of sector and size.

Essential entitiesImportant entities
Typical sectorsEnergy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, spacePostal and courier, waste management, chemicals, food, manufacturing (medical devices, computers, electronics, machinery, vehicles), digital providers, research
Size thresholdGenerally 250+ staff, or turnover above €50mGenerally 50+ staff, or turnover above €10m
SupervisionProactive — audits and inspections without causeReactive — investigated after evidence of a problem
Maximum fine€10m or 2% of global turnover, whichever is higher€7m or 1.4% of global turnover, whichever is higher

Some entities are in scope regardless of size — sole providers of a critical service in a member state, trust service providers, DNS and TLD registries, and certain public administration bodies.

The indirect route into scope — which is how most SMEs get caught

Even if the law does not apply to you directly, NIS2 requires in-scope entities to manage supply chain security. In practice that means your enterprise customers will push obligations down to you contractually.

If you sell to energy, health, finance, transport or public sector organisations in the EU, expect security questionnaires, contractual security clauses, incident notification duties and audit rights — whether or not you are legally in scope. That contractual exposure is real and immediate, and it is a commercial issue rather than a legal one.

The ten required measures

Article 21 sets a baseline that national laws follow. In-scope entities must have:

  1. Risk analysis and information system security policies
  2. Incident handling
  3. Business continuity, backup management and crisis management
  4. Supply chain security, including supplier relationships
  5. Security in acquisition, development and maintenance of systems
  6. Policies to assess the effectiveness of the measures
  7. Basic cyber hygiene practices and security training
  8. Policies on cryptography and encryption
  9. Human resources security, access control and asset management
  10. Multi-factor authentication, secured communications and emergency communication systems

None of this is exotic. It is broadly the ISO 27001 control set, which is why organisations with ISO 27001 already in place find NIS2 comparatively manageable.

Incident reporting — the tightest deadline

This is the part most organisations are unprepared for, because the first clock is 24 hours.

WhenWhat you must submit
Within 24 hoursEarly warning to the national CSIRT — is it suspected malicious, is it cross-border
Within 72 hoursIncident notification with initial assessment, severity, impact, indicators of compromise
On requestIntermediate status update
Within 1 monthFinal report — root cause, mitigation applied, cross-border impact

Practical implication: you need to know, before an incident, who decides it is reportable, who writes the report, and which national portal it goes to. That decision cannot be made for the first time at 2am.

Management liability

Article 20 makes management bodies responsible for approving cyber risk measures and overseeing implementation — and they can be held personally liable. Member states can also temporarily bar individuals from management roles at essential entities. This is a genuine change from NIS1 and is why NIS2 gets board attention.

A practical sequence for an SME

  1. Establish scope properly. Identify each legal entity, its country, sector and headcount/turnover. Get written legal advice if you are near a threshold — this is one of the few places where paying for an opinion is clearly worth it.
  2. Check your national law, not the directive. Use the ECSO transposition tracker to find the current status and the local statute.
  3. Register if required. Most national laws require in-scope entities to register with the competent authority — miss this and you are non-compliant before any incident occurs.
  4. Gap-assess against the ten measures. Map to ISO 27001 if you already have it.
  5. Build the incident reporting runbook. Decision-maker, thresholds, template, portal, contact details, out-of-hours path.
  6. Handle the supply chain both ways — assess your suppliers, and prepare answers for your customers' questionnaires.

Frequently asked questions

We are a UK company — does NIS2 apply?

Not directly; the UK is not implementing NIS2 and is pursuing its own Cyber Security and Resilience Bill. But UK companies with EU establishments, or selling into in-scope EU organisations, are affected through those entities and through contracts.

Does ISO 27001 make us compliant?

It covers most of the technical and organisational measures, but not registration, national reporting mechanisms or the management liability provisions. It is a strong foundation, not a completed answer.

What if our member state has not transposed yet?

The obligation arrives when national law arrives. Do not treat delay as a reprieve — the direction is fixed, and late-transposing states have tended to give short implementation runways.

Further reading

Security and governance

Discuss your security and governance requirements.

MENTARA can help structure technology implementation and delivery requirements without claiming legal or regulated advisory services.

Discuss the requirement
Weekly briefing

Enterprise technology intelligence, delivered weekly.

AI, cyber security, cloud, enterprise software and technology workforce guidance.

New guides and comparisons, no more than weekly.