Skip to content
Ditap®
Back to guides
Compliance

NIS2 Compliance Guide for SMBs

By Jhonatan MatiasPublished May 18, 202610 min read

Updated: July 2, 2026

NIS2 Compliance Guide for SMBs

For most European SMBs, the NIS2 Directive (EU 2022/2555) is the first time cybersecurity stops being optional and becomes an obligation with deadlines, penalties, and board-level accountability. This guide explains, without legal padding, what that means in practice: who is in scope, what needs to happen, and where to start in the next 90 days.

What NIS2 is and why it should matter to you

NIS2 is the European update to the cybersecurity directive that replaced the original NIS from 2016. Member states had to transpose it into national law starting October 2024, and it massively widens the universe of companies required to actively manage cyber risk — no longer just classically critical sectors like energy, transport, or banking.

For an SMB operating in the European Union, or selling to a European company — including Italy, where DITAP has a direct presence —, NIS2 is no longer just a critical-infrastructure issue: it's a supply-chain issue. If your customer is an essential or important entity, they will very likely ask you for evidence that you manage risk, even if your company isn't directly in scope of the law.

This guide is an operational introduction, not legal advice. Exact applicability depends on your sector, size, and each member state's transposition text — for a binding reading, consult a specialized legal advisor.

Is your company in scope?

NIS2 classifies organizations into two tiers: essential entities (energy, transport, banking, health, water, digital infrastructure, public administration, space) and important entities (postal services, waste management, chemicals, food, manufacturing, digital providers, research). Both tiers share the same underlying obligations; the difference lies in supervision intensity and the ceiling on penalties.

Size is the usual filter: mid-size and large companies are generally in scope — 50+ employees, or turnover and balance sheet above the thresholds each country sets when transposing the directive. But there's an important exception: several sectors, such as digital infrastructure, trust service providers, or public administration, have no size floor at all — they're in scope regardless of headcount.

  • You sell technology, connectivity, or infrastructure services to an essential or important entity.
  • You operate in hospitality, healthcare, logistics, or manufacturing with a presence in the EU.
  • A client or partner has already asked you, contractually, for evidence of cyber risk management or a security questionnaire.
  • You are part of the supply chain of a company that is directly in scope.

If you recognized yourself in any of those, even without being strictly obligated, it's worth treating NIS2 as the reference standard: it's what your clients and insurers will start requiring over the next 24 months, whether or not the law formally applies to your case.

The concrete obligations of the directive

Beyond the list of technical measures, NIS2 requires three very concrete things that change how a company operates day to day:

  • Continuous risk management: not a one-off audit, but a living process of identifying, assessing, and treating cyber risk, reviewed and updated regularly.
  • Incident reporting on tight deadlines: early warning to the competent authority within 24 hours of detecting a significant incident, formal notification within 72 hours, and a final report within a month.
  • Supply-chain due diligence: assessing the cybersecurity risk of your own technology vendors — which means that if your client is in scope, they will likely audit you too.

The 24-hour window is what surprises SMBs the most: there's no time to assemble a committee once the incident has already happened. You need a detection and escalation process defined in advance — with named owners, phone numbers, and a tested contact channel — not a plan improvised in the moment.

Governance: the board is accountable

One of the sharpest changes NIS2 introduces is that ultimate responsibility for cyber risk management sits with the company's management body, not just the IT department. That means formal approval of the risk management strategy, oversight of its implementation, and, under some national regimes, personal liability for serious non-compliance.

In practice, this turns cybersecurity into a board-level agenda item, with at least one documented periodic review, rather than a folder the technical team opens once a year before an audit.

  • Appoint an owner — internal or external — who reports directly to management.
  • Provide specific cyber risk management training for members of the management body: the directive mentions it explicitly.
  • Document every material risk decision: what was accepted, what was mitigated, and why.

The ten minimum technical measures under Article 21

Article 21 of the directive details ten domains of minimum risk-management measures. It isn't a shopping list of products — it's a management framework that each company adapts to its size and actual exposure.

  • Risk analysis and information system security policy.
  • Incident handling: detection, response, and communication.
  • Business continuity: backup management, disaster recovery, and crisis management.
  • Supply-chain security, including the relationship with each direct supplier.
  • Security in the acquisition, development, and maintenance of systems, including vulnerability management.
  • Policies to assess the effectiveness of risk-management measures.
  • Basic cyber hygiene practices and security training for all staff.
  • Policies on the use of cryptography and, where relevant, encryption.
  • Human resources security, access control, and asset management.
  • Multi-factor or continuous authentication, secure voice/video/text communications, and secure emergency communication systems within the organization when needed.

None of these ten domains is exotic: they are, in essence, good managed infrastructure and security practices we already recommend to any SMB, whether or not it's formally in scope of NIS2. The difference is that now there's an obligation to document them and be able to show them.

What happens if you don't comply

Financial penalties for non-compliance are serious and scale with company size. For essential entities, administrative fines can reach up to €10 million or 2% of global annual turnover, whichever is higher. For important entities, the ceiling is €7 million or 1.4% of global turnover.

But the real cost is almost never the fine. It's losing the contract with the client who asked for compliance evidence you didn't have, being excluded from a public tender, or the reputational cost of reporting an incident late after it already leaked to the press before reaching the right authority.

90-day checklist to get started

You don't need to solve all ten Article 21 domains in one weekend. A realistic 90-day plan prioritizes what reduces the most risk first, not what looks best in a slide.

  • Weeks 1-2: map which data, systems, and vendors are critical. Without this inventory, every later measure is a guess.
  • Weeks 3-4: define the incident reporting process — who decides, who gets notified, on what timeline — and test it with a simple tabletop exercise.
  • Weeks 5-8: close the most urgent technical gaps: MFA on all critical access points, verified 3-2-1 backups (not just configured), and basic network segmentation.
  • Weeks 9-12: document the risk management policy, train the leadership team, and put together the first status report for the board.
The goal of the 90 days isn't 'being certified' — it's having documented evidence that the process exists and works. That's the first thing a client, an auditor, or an insurer will ask for.

How we approach it at DITAP

At DITAP we don't sell certifications we don't hold. Our stance on NIS2 and ISO 27001 is progressive alignment: we design managed infrastructure and security processes — managed firewall, 24/7 monitoring, 3-2-1 backup, network segmentation, MFA — that cover a substantial part of the ten technical domains in Article 21, documented so your company can show real evidence to a client or an auditor.

If you're assessing how exposed your operation is, the first step is a technical audit that maps your current infrastructure against Article 21, with concrete, prioritized findings — no smoke, no generic checklist.

Would rather do it with us?

This guide is the general framework. Every operation has its own specifics — in 45 minutes we review yours and tell you exactly where you stand.

Or join the newsletter to get the next guide the moment it's out:

Stay updated

One email per month with technical insights and infrastructure tips.

More guides