Skip to content
PolicyForge
All posts
By Vyrhak SATH · Founder, NAGASHIELD SECURITY10 minReviewed

NIS2 compliance for SMEs: a 10-step guide for 2026

A practical, step-by-step path to NIS2 compliance for small and mid-sized companies — scope, risk analysis, the documents you need and how to prove it before enforcement begins.

Why NIS2 matters for SMEs

NIS2 (Directive (EU) 2022/2555) replaces the original 2016 NIS directive and widens the net dramatically: more than 15,000 entities in France are now in scope, including mid-sized companies, subcontractors and digital service providers in strategic sectors. France's transposition law is still before Parliament (as of mid-2026 — see our dedicated guide to NIS2 in France), but the direction is set: penalties up to €10M or 2% of global turnover for essential entities — and personal liability for executives. ANSSI advises building compliance now rather than waiting for the final text.

The good news: most of what NIS2 asks for is documented governance, not expensive technology. If you approach it methodically, an SME can get the core in place in weeks, not months.

The 10 steps

NIS2 compliance for an SME comes down to ten steps: confirm scope, appoint an owner, run a risk analysis, write your security policy, set up incident notification, plan continuity, secure your supply chain, cover the technical baseline, train your people and keep the evidence. Work them in order — each one feeds the next.

1. Confirm whether you are in scope

You are likely in scope if you have more than 50 employees or €10M turnover and operate in a strategic sector (energy, transport, health, digital infrastructure, public administration, manufacturing, etc.). Even smaller SMEs can be indirectly affected: essential and important entities must secure their supply chain, so a subcontractor providing a critical digital service will be assessed against NIS2 criteria.

2. Appoint an accountable owner

NIS2 makes management bodies responsible. Name a person accountable for the programme and have leadership formally approve it — that sign-off is itself evidence.

3. Run a risk analysis

Identify your assets, the threats against them and the measures that reduce the risk. This drives everything else: NIS2 expects measures that are proportionate to your risk.

4. Write your information security policy (ISSP)

The top-level document that states your security objectives and commitment. It anchors every other policy.

5. Set up incident handling and notification

NIS2 imposes tight notification timelines (an early warning within 24 hours, a fuller notification within 72 hours). You need a documented incident response process before an incident — not during one.

6. Plan business continuity and recovery

Document a business continuity plan (BCP) and a disaster recovery plan (DRP) — see our guide to writing a business continuity policy. Test the restore.

7. Secure your supply chain

This is one of NIS2's biggest changes. Assess your suppliers, add security clauses to contracts, and keep a vendor security policy.

8. Cover the technical baseline

Access control, multi-factor authentication, vulnerability management, logging and encryption. Each should be a short, approved, communicated policy — not tribal knowledge.

9. Train people (including leadership)

NIS2 explicitly requires cyber-hygiene training and management awareness. Document the programme and keep attendance records.

10. Keep the evidence

For every measure, be ready to show approval, communication and review. Auditors and regulators care less about perfect prose than about proof that the measure is real, known and maintained.

Primary sources

How PolicyForge accelerates NIS2

The NIS2 policy generator maps each required document — ISSP, risk management, incident response, continuity, supply chain, access control, vulnerability management, awareness — to a structured, bilingual template with an approval block, communication notes and a review date. You generate the documentary core in an afternoon and walk into your assessment with the evidence already in shape.

Start free → · See the NIS2 policies

Frequently asked questions

When does NIS2 apply to SMEs in France?

The EU deadline for member states to transpose NIS2 was 17 October 2024. France’s transposition law (the “resilience” bill) is still before Parliament as of mid-2026, so French obligations will phase in once it passes. ANSSI advises in-scope companies to prepare now: the requirements are known, and its ReCyF framework (March 2026) already describes the expected measures.

Which companies are in scope for NIS2?

You are likely in scope if you have more than 50 employees or €10M turnover and operate in a strategic sector such as energy, transport, health, digital infrastructure, public administration or manufacturing. Smaller SMEs can be indirectly in scope when they supply a critical service to an essential or important entity.

What are the penalties for NIS2 non-compliance?

For essential entities, fines can reach €10M or 2% of global annual turnover, whichever is higher. NIS2 also introduces personal accountability for management bodies, which must approve and oversee the security measures.

What documents does NIS2 require?

NIS2 is largely about documented governance: an information security policy, a risk analysis, an incident response process, business continuity and disaster recovery plans, supply-chain security, access control, vulnerability management and security awareness training — each approved, communicated and reviewed.

How fast must I report a security incident under NIS2?

NIS2 imposes tight timelines: an early warning within 24 hours of becoming aware of a significant incident, followed by a fuller notification within 72 hours. You need a documented incident response process in place before an incident occurs.