Start/Blog/NIS2 from 2026: These obligations are coming for SMEs.
NIS2

NIS2 from 2026: These obligations are coming for SMEs.

The NIS2 Directive (EU 2022/2555) is the European Union's most far-reaching cybersecurity regulation to date - and it affects significantly more companies than its predecessor. Many SMEs still assume that ‘cybersecurity obligations’ apply only to large corporations or critical infrastructure. That misconception can be costly. As transposition into national law is taking effect gradually in several Member States, 2026 will be the year of practical application for many companies. Those who do not start now will come under time pressure. This article summarises who is affected, which obligations apply and where management bears personal responsibility.

06. März 2024 · Peter Schubö · 7 min read

Who is affected by NIS2?

NIS2 distinguishes between ‘essential’ and ‘important’ entities. The relevant factors are the sector and the size of the company. As a rule of thumb, medium-sized companies with at least 50 employees or annual turnover exceeding €10 million that operate in one of the covered sectors generally fall within its scope.

The covered sectors include:

- Energy, transport, banking and financial market infrastructure

- Healthcare, drinking water and wastewater

- Digital infrastructure, IT service providers and data centres

- Manufacturing (including machinery, vehicles and medical devices)

- Postal and courier services, waste management, chemicals and food

Important: even companies not directly subject to NIS2 may face obligations through the supply chain. Affected companies must assess the security of their suppliers and pass the corresponding requirements on.

The key obligations under Art. 21

Article 21 is at the heart of NIS2: affected entities must take ‘appropriate and proportionate technical, operational and organisational measures’ to manage risks to their network and information systems. Specifically, the Directive requires measures including:

- Policies on risk analysis and information system security

- Procedures for handling security incidents (incident response)

- Business continuity, backup management and crisis management

- Supply-chain and service-provider security

- Security in the acquisition, development and maintenance of systems, plus vulnerability management

- Procedures for assessing the effectiveness of measures

- Training, cyber hygiene and the use of cryptography and encryption

- Access control, asset management and multi-factor authentication

The risk-based approach is crucial: measures must match the company's actual risk. An off-the-shelf standard package will generally not meet the requirements.

Reporting and registration obligations

NIS2 introduces tight reporting deadlines for significant security incidents. They are staggered:

- Within 24 hours: an initial early warning to the competent authority or CSIRT;

- Within 72 hours: a more complete incident notification with an initial assessment;

- Within one month: a final report covering causes, measures and impact.

There is also a registration obligation: affected entities must register with the competent national body and keep their contact details up to date. Ignoring these obligations risks sanctions, regardless of whether an incident has occurred.

Management liability

One of the most important changes is that NIS2 expressly holds management accountable. Management must approve the risk-management measures, oversee their implementation and may be held personally responsible for infringements. Regular training for management bodies is also required.

The fines are substantial: essential entities face up to €10 million or 2% of worldwide annual turnover, while important entities face up to €7 million or 1.4%. There may also be reputational damage and, in serious cases, personal consequences for those responsible.

What you should do now

Although national implementation varies from country to country, there is no reason to wait. These steps will move you forward regardless of the exact effective date:

- Clarify applicability: use your sector and company size to determine whether and how NIS2 applies to you.

- Assess the current state: a gap analysis shows which Art. 21 measures are already in place and where gaps remain.

- Create a roadmap: prioritise measures by risk and effort instead of tackling everything at once.

- Establish processes: incident response, reporting channels and backup strategies must be documented and rehearsed.

- Involve management: obtain the necessary management decisions and training.

Conclusion

NIS2 is not a bureaucratic nuisance, but a justified response to a real threat. For SMEs, the key is to start early, proceed methodically and implement security technically rather than merely documenting it. Starting early spreads the workload, avoids costly last-minute projects and ensures the company can act effectively when an incident occurs.

Weiterlesen

Verwandte Artikel

01
AI Regulation · 01. August 2026 · 7 min read

How to label AI content correctly: A practical guide for websites and social media

Since 2 August 2026, the transparency obligations under Article 50 of the EU AI Act have applied. Anyone using chatbots, AI images, AI voices or AI-generated text has since been asking: Do I now have to label all of it? The short answer is no. The AI Act does not require companies to label every piece of AI-generated content—the obligations apply to clearly defined situations, not every use of an AI tool. This is precisely where the practical problem arises: some companies label everything out of uncertainty and therefore appear unprofessional. Others label too little and risk a violation. This article explains the four cases governed by Article 50, the applicable exceptions and exactly how to label content on websites and social media.

02
AI Regulation · 02. Februar 2026 · 4 min read

ISO 42001 & AI policy template: Your guide through the EU AI Act—pragmatic and efficient

The EU AI Act requires companies to establish systematic governance structures for the legally compliant use of artificial intelligence. But where do you start? How can these complex requirements be implemented in practice without bringing business operations to a standstill? ISO 42001 is the first international standard for AI management systems and translates many abstract AI Act requirements into 38 concrete controls—a field-tested blueprint that helps you: In this article, we show you how to use the structure of ISO 42001 to comply with the AI Act pragmatically—and implement it efficiently with our policy template. This integrated approach not only saves time but also significantly reduces your AI compliance costs.

03
Whistleblowing · 24. Februar 2022 · 7 min read

The new Whistleblower Directive – what companies should do now

With the new EU Whistleblower Directive, Brussels aims to regulate and harmonize whistleblowing across the EU for the first time. Its stated objective is better protection for whistleblowers. Anyone who reports breaches of Union law or unethical conduct in or by a company should not have to fear sanctions. To achieve this, companies must create appropriate structures and preserve whistleblowers’ anonymity. We explain what this means for companies and how they can overcome the challenges.