TL;DR
NIS2 officially does not apply to micro enterprises (<10 employees, <ā¬2M) and small enterprises (<50 employees, <ā¬10M). But: certain sectors have size-threshold exceptions, and as a supplier to an Essential Entity, you may be indirectly affected. This guide explains what to do.
For small and medium enterprises (SMEs), NIS2 applicability is often unclear. Many SMEs hear about NIS2 but do not know whether it applies to them. This guide explains precisely when NIS2 applies, what exceptions exist, what SMEs as suppliers should do, and how much a baseline NIS2 compliance implementation costs.
The NIS2 Size Thresholds
| Enterprise size | Employees | Turnover / Balance | NIS2 status |
|---|---|---|---|
| Micro enterprise | < 10 | < ā¬2M | Exempt ā |
| Small enterprise | < 50 | < ā¬10M | Exempt ā |
| Medium enterprise | 50ā249 | ā¬10ā50M | Potentially in scope ā |
| Large enterprise | ā„ 250 | > ā¬50M | In scope ā |
* Size is assessed on BOTH criteria. A medium enterprise must meet both the employee AND the turnover threshold.
Size-Rule Exceptions: These SMEs Are in Scope Regardless
NIS2 Article 2(2) lists entity types that fall in scope regardless of size. If your company operates in one of these categories, the headcount is irrelevant:
Indirect Impact: SMEs as Suppliers
Even if your company is not directly in scope, you may be indirectly affected if you act as a supplier or service provider to an Essential or Important Entity.
Find out if your company is in scope
Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?
ā ļø Supply chain duty under Article 21(2)(d)
NIS2-affected entities must assess the security practices of their suppliers. This means: if you have a NIS2-affected customer, they will likely require security questionnaires, audit access, or contractual cybersecurity clauses from you, even if you are not directly in scope yourself.
When You Grow Past the Thresholds
Many growing companies miss that NIS2 applies from the moment they cross the thresholds, not when the authority informs them. NIS2 Article 3(3) requires entities to self-register with the competent authority as soon as they meet the thresholds.
In practice, this means: if your company grows during the year to 55 employees and ā¬12 million in turnover and operates in a NIS2 sector, you must register and begin implementation, even if you had no prior knowledge of NIS2.
ā¹ļø Recommendation for growing companies
Check annually whether you have met the NIS2 thresholds. Start preparing early if you are approaching the thresholds. Registration and initial compliance measures take time you do not have once you have already crossed the threshold.
Cost of a Baseline NIS2 Implementation for SMEs
A common question is: what does NIS2 compliance cost for a medium-sized company? Costs vary considerably depending on the existing security baseline. Companies with no existing security structure pay considerably more than those that have already implemented ISO 27001 or similar frameworks.
| Cost area | Starting point: no ISMS | Starting point: ISO 27001 |
|---|---|---|
| Initial assessment / gap analysis | ā¬5,000ā15,000 | ā¬2,000ā5,000 |
| Policies and documentation | ā¬10,000ā25,000 | ā¬2,000ā5,000 |
| Technical measures (MFA, EDR, backup, SIEM) | ā¬30,000ā80,000 | ā¬5,000ā20,000 |
| Management training | ā¬2,000ā5,000 | ā¬2,000ā5,000 |
| Incident response plan and exercises | ā¬5,000ā15,000 | ā¬2,000ā5,000 |
| Supply chain assessment | ā¬5,000ā15,000 | ā¬3,000ā8,000 |
| Annual ongoing costs (audits, training, updates) | ā¬15,000ā40,000 | ā¬8,000ā20,000 |
Indicative figures for a medium-sized enterprise (50ā249 employees). Individual costs depend heavily on existing infrastructure, sector requirements, and the choice between internal implementation and external consultancy.
National Support Programmes for SMEs
Several EU member states have developed programmes to support SMEs with cybersecurity:
BSI offers free guidance documents and the IT-Grundschutz Compendium, which is specifically designed with SMEs in mind. BSI IT-Grundschutz certification is recognised by authorities as NIS2 evidence.
The CyberFundamentals Framework (CFF) has a 'Basic' level explicitly designed for SMEs that requires considerably less effort than ISO 27001. The CCB provides free guides and self-assessment tools.
The Digital Trust Centre offers SME-oriented advisory services and a free Cyber Security Assessment Tool.
ENISA regularly publishes SME-specific cybersecurity guides and runs the European Cyber Security Month (ECSM) with resources for smaller organisations.