NIS2: what smaller companies actually need to know
NIS2 is a European directive on network and information security, transposed into national law across member states including Romania and Spain. Most of the coverage aims at large operators. The practical effect on smaller companies arrives differently.
Direct scope, briefly
It applies to medium and large organisations in listed sectors — energy, transport, banking, health, water, digital infrastructure, public administration, postal services, waste, food, manufacturing and others. Broadly, from fifty employees or ten million euro turnover upwards, within those sectors.
If that is you, this is a compliance programme with named management accountability, and it needs proper legal input rather than an article.
How it reaches everyone else
Through the supply chain. In-scope organisations must manage the security of their suppliers, which means their requirements land on you as contract clauses and questionnaires. If you supply a hospital, a bank, a utility or a public body, you will meet NIS2 through their procurement long before any regulator contacts you.
What is being asked for
The measures are unsurprising, which is the useful part:
- Risk analysis and an information security policy
- Incident handling, with defined reporting timelines
- Business continuity and backup management
- Supply chain security
- Security in acquisition and development
- Assessment of whether the measures work
- Cyber hygiene and staff training
- Cryptography and encryption policy
- Access control and asset management
- Multi-factor authentication
A company doing these things competently is largely there already.
Reporting timelines worth memorising
For in-scope entities: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month.
Twenty-four hours is short. It requires knowing beforehand who decides, who writes, and where it is sent.
A sensible starting point
Whether or not you are in scope, do these:
- Write down the asset inventory and who owns each system
- Produce a one-page incident response plan with names and phone numbers
- Turn on multi-factor authentication everywhere
- Verify backups by restoring them
- Keep the answers to the security questionnaires you have already received
That work is not wasted regardless of how the scope question resolves.
We help with the assessment through IT consulting.
