If your company sells technology, connectivity, or services to a client in the European Union — or simply bills an Italian company — you may soon receive a security questionnaire that didn't exist before. It's not new bureaucracy for its own sake: it's NIS2, and for most SMBs operating in or toward Europe, it's the first time cybersecurity stops being optional.
Who does it actually apply to?
The NIS2 Directive (EU 2022/2555) replaced the original 2016 NIS directive and dramatically expanded the universe of companies required to actively manage cyber risk. The law classifies organizations into essential entities (energy, transport, banking, health, water, digital infrastructure) and important entities (manufacturing, food, digital providers, postal services, and more). The usual filter is size — mid-size and large companies, 50 employees or more — but several sectors have no size floor and are covered regardless of headcount.
Here's the part most SMBs don't see coming: even if your company isn't directly in scope, if you sell to a client who is, they'll likely ask you for evidence that you manage cyber risk — because the directive requires covered companies to assess the risk of their own supply chain. NIS2 stopped being a critical-infrastructure topic and became a supply-chain topic.
What it actually demands, beyond the firewall
Having a firewall and antivirus gets you less close to NIS2 than it seems. The directive requires three concrete things that change how a company operates day to day:
- Continuous risk management: not a one-off annual audit, but a living process of identifying and treating risk, reviewed regularly.
- Incident reporting on tight deadlines: early warning within 24 hours of detecting a significant incident, formal notification within 72 hours, final report within a month.
- Supply-chain due diligence: assessing the risk of your own technology vendors, not just your own posture.
The 24-hour deadline is what surprises SMBs the most: there's no time to assemble a committee once the incident has already happened. NIS2 also places ultimate responsibility for risk management on the company's management body — not just IT — with specific training required for those in leadership.
What happens if you don't comply
Fines scale with company size and can reach €10 million or 2% of global turnover for essential entities. In practice, though, almost no SMB ends up paying a fine like that: the real cost is losing a contract because a client asked for evidence of risk management and you didn't have it, or getting shut out of a tender.
What that security questionnaire will actually ask for
If your client is in scope for NIS2, the questionnaire that lands in your inbox tends to follow the same pattern, regardless of sector. Getting ready for it ahead of time saves weeks of back-and-forth:
- Evidence that MFA is active on the accounts that administer your systems and on anything that touches client data.
- A documented incident-response procedure, with names and timelines — not a generic statement of intent.
- Proof that your backups actually restore, not just that they run on schedule.
- A list of who you subcontract to — because your client's due diligence cascades down to your own vendors.
Having this ready before it's requested turns a negotiation from "let's see if we can" into "here's the report."
The first 5 steps
You don't need to solve everything over a weekend. This is the order that reduces the most risk first:
- Inventory which systems, data, and vendors are critical to your operation. Without this, every subsequent measure is taken blind.
- Define the incident-reporting process — who decides, who gets notified, on what timeline — and test it with a simple drill, rather than leaving it in a document no one reads.
- Turn on MFA on every critical access point: email, VPN, admin panels. It's the single measure with the best cost-to-impact ratio.
- Verify your 3-2-1 backup — having it configured isn't enough; you need to prove it actually restores.
- Segment your network with basic VLANs, so an incident on one system doesn't spread to the entire operation.
How we approach it at DITAP
At DITAP, we don't sell certifications we don't hold — we're not NIS2-certified, and you should be wary of any vendor promising "full compliance" on a sales call. Our position is one of progressive alignment: we design the managed-security infrastructure and processes — managed firewall, MFA, 3-2-1 backup, segmentation, 24/7 monitoring — that cover a good part of the directive's minimum technical measures, documented so you can show real evidence to a client or an auditor.
If you want to understand exactly where your company stands, we run a NIS2 compliance gap assessment with concrete, prioritized findings. And if you'd rather understand the full picture first — scope, obligations, a 90-day plan —, the complete NIS2 compliance guide for SMBs covers it in more depth than fits in this post.


