What NIS2 is trying to improve
NIS2 raises the baseline for cybersecurity across critical and important services in the European Union. It is meant to make organizations more resilient and make incident reporting more consistent across Member States.
For a small or mid-sized business, the practical result is usually more structure: clearer risk decisions, security policies, incident response steps, supplier checks, evidence, and management accountability.
Who may be affected?
NIS2 does not cover every company in Europe in the same way. Scope depends on the sector, service, organization size, and how each Member State has implemented the directive. The European Commission describes a size-based approach for medium and large entities in covered sectors, while national guidance explains local details and exceptions.
In the Netherlands, NCSC guidance says scope depends mainly on sector and size, with critical sectors and specific services treated carefully. The Cyberbeveiligingswet applies from 15 August 2026, so Dutch organizations should check official guidance rather than relying on old assumptions.
- You may be directly in scope if you operate in a covered sector and meet the relevant size or service criteria.
- You may be indirectly affected if you supply a customer that is in scope.
- You may be asked for evidence even if the law does not directly apply to you.
- You should check national guidance because the practical route differs by country.
Why customers may start asking more questions
NIS2 includes supply-chain security as one of the areas covered organizations need to address. That means larger customers may look more closely at the vendors, SaaS providers, MSPs, consultants, processors, and operational partners they depend on.
For an SMB, this can show up as a customer security questionnaire, a contract clause, a vendor review, a request for policies, or a question about incident notification timelines. The customer may not be asking you to become certified overnight. They are usually trying to understand whether your security practices are organized enough to trust.
Practical security steps SMBs should take first
The first step is not to write the longest policy library possible. It is to build a clear security baseline that matches the business.
Check scope and customer pressure
Confirm whether NIS2 or the national implementation applies directly, then list customers or sectors likely to ask for assurance.
Write down security ownership
Name who owns security decisions, incident coordination, supplier reviews, access approvals, backups, and policy review.
Create a practical policy set
Start with information security, access control, incident response, backup and recovery, supplier security, data handling, and acceptable use.
Map controls to evidence
For each important control, define the policy, owner, implementation action, evidence source, and review frequency.
Prepare incident records
Make sure incidents can be logged with time detected, affected assets, impact, actions, decisions, evidence, and owner updates.
Where Framework-Pro helps
Framework-Pro can help SMBs turn framework and customer pressure into tailored policy drafts and supporting readiness documents. The product uses questionnaire answers and business context to help choose a practical framework path, identify relevant controls, and generate editable documents.
That can be useful for NIS2 readiness because many teams need a structured starting point for policies, controls, owners, and evidence. Framework-Pro does not make a legal determination that NIS2 applies or certify compliance. It gives the team reviewable outputs that still need approval, implementation, and human judgement.
Quick FAQ
Does NIS2 apply to small businesses?
Sometimes, but not always. Scope depends on sector, size, service type, national law, and exceptions. Small suppliers may also be indirectly affected through customer requirements.
What should an SMB do first for NIS2 readiness?
Check scope, define owners, create core policies, map controls to evidence, prepare incident response records, and review supplier risk.
Is NIS2 only about incident reporting?
No. Incident reporting is important, but NIS2 also covers risk management, incident handling, continuity, supply chain security, vulnerability handling, cyber hygiene, access control, assets, and management responsibility.
Can Framework-Pro replace legal advice?
No. Framework-Pro helps generate tailored policy drafts and readiness documents. Legal scope and compliance duties should be confirmed with qualified advisers or the relevant authority.
Official sources used
These pages were used for factual grounding. aneo summarizes them in original wording and does not provide legal advice.
