Skip to content

NIS2 for small teams, in plain terms.

The EU’s NIS2 directive stopped being a big-company topic. Who is actually in scope, what it genuinely requires, and the short list a small operator should do first - without the legal fog.

Stacked glass layers
Layers of obligation - fewer than the fog suggests.

What NIS2 is

NIS2 - Directive (EU) 2022/2555 - is the EU's second attempt at a common cybersecurity baseline. The first version covered a narrow set of operators; NIS2 widens the net to eighteen sectors, adds management liability, and puts real numbers on fines. Member states were required to transpose it into national law by October 2024, so by now the obligations run through your national act, not the directive text itself.

The important mental shift: NIS2 is not a certification you buy. It is a legal duty to run a documented, risk-based security program - and to report serious incidents fast.

Are you in scope?

Rough triage, in three questions:

  1. Sector: the annexes list energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration, space, post, waste, chemicals, food, manufacturing of critical products, digital providers, and research. Digital infrastructure and ICT services catch many companies that do not think of themselves as "critical."
  2. Size: the general cut-off is 50+ employees or over EUR 10M annual turnover. Below that you are usually out -
  3. Unless: you are the sole provider of a service, a trust/DNS/TLD operator, or otherwise designated critical by your member state. Small does not automatically mean exempt.

Entities split into essential and important - the duties are nearly identical; supervision intensity and fine ceilings differ.

What it actually requires

Article 21 lists the measures. Translated out of directive-speak, it is a competent security program:

  • Risk analysis and a written security policy
  • Incident handling that actually functions (see the deadlines below)
  • Business continuity: backups, disaster recovery, crisis roles
  • Supply-chain security - your providers' security is now your problem on paper, too
  • Secure development and vulnerability handling for what you build and buy
  • Basic hygiene: MFA, encryption where appropriate, access control, asset management
  • Training - including for management, who now carry personal responsibility for approving the measures

Nothing on that list is exotic. If you already run ISO 27001-shaped practices, you are most of the way there. If you run nothing, the gap is organizational before it is technical.

Incidents and deadlines

The reporting clock is the part small teams underestimate. For a significant incident:

  • 24 hours - early warning to your national CSIRT or authority
  • 72 hours - fuller notification with an initial assessment
  • One month - final report: root cause, impact, mitigation

Fine ceilings sit at EUR 10M or 2% of worldwide turnover for essential entities (EUR 7M / 1.4% for important ones), and authorities can hold management personally accountable. You do not want to design your reporting process during your first incident.

The first five moves for a small operator

  1. Decide scope honestly - sector plus size plus special cases - and write the answer down, whichever way it lands.
  2. Name one accountable owner. NIS2 punishes "everyone's job."
  3. Write the incident path: who detects, who decides "significant," who files the 24-hour warning, on what form, at which authority.
  4. Close the hygiene basics this quarter: MFA everywhere, tested backups, an access-rights review.
  5. Put your top ten suppliers on one page with what happens if each fails or gets breached. That page is your supply-chain measure, version one.

The directive is long. The first version of doing it right fits on two pages.

Update log (1)

2026-04-28Initial publication.

Sources + verification

Based on the text of Directive (EU) 2022/2555 (NIS2): scope articles and annexes for sector lists, Article 21 for the security-measure baseline, Article 23 for incident reporting timelines, and the penalty articles for the fine ceilings. National transposition laws vary - the directive sets the floor, your member state's implementing act sets your actual obligations. Confirm sector scope against the annexes and your national regulator's guidance.

Keep reading

CVE security.txt: the two-minute change that gets you warned first 2026-07-08 · 3 min Tooling The five headers that fix most of a failed scan 2026-05-06 · 6 min AI Security Two red bars. Read the chart end to end. 2026-07-20 · 5 min
reading as
consumerpro