
NIS2 for SMEs — when do you fall under it and what should you do?
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript

What exactly is NIS2?
Let’s get one thing clear first. The NIS2 Directive is the updated European legislation for cybersecurity. The goal is simple: to ensure that organizations are better equipped to withstand cyberattacks, that incidents are reported more quickly, and that digital resilience is increased across Europe. The directive builds on the previous NIS legislation but takes a broader and stricter approach. Many business owners are therefore looking for a clear explanation of NIS2: what is NIS2, why is this legislation being introduced, what exactly does NIS2 stand for, and when does NIS2 come into effect?
The NIS2 Directive had to be implemented by EU member states through national legislation, and in the Netherlands, it has been incorporated into the new Cybersecurity Act. That act faced delays, but there is now an effective date: August 15, 2026. The terms are therefore used interchangeably here and there, but they refer to the same subject. NIS2 is on its way, and organizations must be able to demonstrate that they take cybersecurity seriously.
When does your SME fall under NIS2?
Many SMEs are asking themselves: when is NIS2 mandatory for me? The answer starts with the sectors. The directive identifies two groups: essential sectors and important sectors. Think of healthcare, energy, ICT service providers, transport companies, water management, cloud providers, and digital infrastructure.
In addition, NIS2 looks at size:
- more than 50 employees, or
- more than 10 million euros in revenue.
In that case, you generally fall under the legislation, unless you are in a non-relevant sector. But for SMEs, one category in particular is crucial: suppliers in the supply chain. For example, are you a hardware supplier of network components for a hospital? Then you may still fall under NIS2 legislation, because your services have a direct impact on the continuity of others. This will be the largest group within the SME sector.
How do you know who NIS2 applies to?
There is no magic checklist. But you can ask yourself three honest questions:
- Do we provide products or services that others depend on for their continuity? Think of applications, cloud environments, security services, infrastructure, hosting, or integrations.
- Are you part of a supply chain that includes companies that are subject to NIS2? Large organizations will impose requirements on their suppliers. Even if you do not officially fall under the law yourself, you may still be required to implement NIS2-like measures.
- Do you yourself pose a major or societal risk if your organization goes down? For example, due to critical functions, large customer volumes, or a high dependency on your services.
If you answer "yes" to any of these questions, it is highly likely that you will have to deal with the NIS2 directive (either directly or due to supply chain responsibility).
What should you do if you fall under NIS2?
The question "how to comply with NIS2?" often gets a long answer, but if we want to keep it concise, it comes down to five components. You must at least register your organization as a NIS2 entity, provided you are one (registration obligation).
1. Risk analysis and policy
Understanding threats, vulnerabilities, and measures. NIS2 expects organizations to structurally assess risks and establish policies. Read here how to conduct a risk analysis .
2. Technical security
From patch management and monitoring to access control, encryption, and detection. The directive is strict regarding basic security. You can cover much of this with an ISO 27001 implementation – you can read more about this in our whitepaper (this will be covered later in this article).
3. Incident reporting obligation
You must report serious incidents to the National Cyber Security Centre (or the relevant supervisory authority) within 24 hours.
4. Training and awareness
Employees represent a major risk, so it is a mandatory part of the law to focus on awareness, for example through Guardey.
5. Supplier management and supply chain responsibility
You must demonstrate that suppliers do not weaken your cybersecurity level. This affects almost every SME.
ISO 27001 is a logical fit for this. It provides structure, accountability, and a solid foundation for compliance.
What does NIS2 actually mean for you as an SME?
Even if your company does not formally fall under NIS2 legislation, you will still be affected. Large organizations are passing these requirements on to their suppliers. Cyber insurers are becoming more critical. Quotes and tenders are increasingly requiring proof of cybersecurity measures. In short: NIS2 affects SMEs regardless—either as a legal obligation or as a market development.
How do you get started with NIS2?
Start small, start smart. A gap analysis is a logical first step. It gives you immediate insight into where you stand and which measures are required. This is followed by implementation: documentation, processes, technology, training, and supplier management—everything needed to comply with the NIS2 directive.
To demonstrate compliance, you could choose ISO 27001 as an information security framework to apply NIS2, or opt for the NIS2 Supply Chain certificate. This makes you transparent to customers and ready for the future.
{{LINKCARD}}
NIS2 for SMEs
NIS2 sounds big and complicated, but for most SMEs, it comes down to three things:
- Getting your security in order.
- Establishing clear processes and responsibilities.
- Demonstrating that you take cybersecurity seriously.
Whether or not you are formally subject to the law, now is the time to make your organization more resilient and future-proof.
No-obligation consultation
Want to know exactly where your organization stands? Schedule a no-obligation consultation below. Together, we will identify the risks, determine the necessary steps, and guide you on how to implement them in a smart and practical way.

.avif)
.avif)


















