NIS2: where should an SME start?
14 January 2026 · 6 min read
NIS2 is no longer just a concern for large groups or critical infrastructure operators. The directive widens its scope to a much larger set of entities, including many SMEs and mid-market companies that discover — often late — that they fall within scope, either directly or indirectly through their relationships with regulated customers.
The first mistake is treating NIS2 as an isolated IT project. NIS2 is, above all, a governance obligation: leadership needs to be trained, informed and accountable for security decisions. Without genuine leadership ownership, no compliance programme survives past its first year.
The second step is clarifying your exact status: are you an essential entity, an important entity, or in scope indirectly as a supplier to a regulated organisation? This qualification determines the level of rigour expected, and prevents both over-investment and under-preparation.
Once scope is clear, a structured gap assessment compares current practice — risk management, incident handling, business continuity, supply-chain security — against the directive's requirements. This diagnostic is what turns an abstract obligation into a concrete action plan.
For an SME, the key is not addressing everything at once, but prioritising: the measures that reduce the most real risk with the least implementation complexity should come first. A realistic 12-to-18-month roadmap beats an ambitious plan that never gets executed.
Finally, NIS2 should not be treated as an isolated compliance burden. Done well, it strengthens the organisation's genuine resilience against cyber incidents — a benefit that reaches far beyond regulatory compliance alone.
Discuss your cyber challenge
Let's discuss how this topic applies to your organisation.