HomeBlogNIS2
NIS2

NIS2 Compliance for SMEs: What You Actually Need to Do by October 2024

The NIS2 Directive is live. Most SMEs still don't know if they're in scope — or what Article 21 actually requires. This is the practical guide.

AvailixOps Engineering·1 September 2025·8 min read

The NIS2 Directive (EU 2022/2555) became enforceable in October 2024. If your organisation is based in the EU and operates in one of the 18 sectors covered, you may now be legally required to implement specific cybersecurity measures and report incidents to your national competent authority within 24 hours.

Are you in scope?

NIS2 applies to organisations that meet two criteria: they operate in a covered sector, and they meet the size threshold. The threshold is lower than most people expect — it catches "medium-sized" entities, defined as 50 or more employees or €10M or more in annual turnover.

The 18 covered sectors split into "essential" and "important." Essential sectors include energy, transport, banking, healthcare, and digital infrastructure. Important sectors include postal services, waste management, manufacturing (food, chemicals, medical devices), and digital providers.

Key rule of thumb

If you run critical infrastructure, supply critical infrastructure, or process data for organisations that do — assume you are in scope and verify. Getting this wrong has consequences: fines up to €10M or 2% of global turnover for essential entities.

Article 21: The 10 measures you must implement

Article 21 is the operational core of NIS2. It requires organisations to implement "appropriate and proportionate technical, operational and organisational measures" across 10 specific areas. Here is what each means in practice:

  • Risk analysis and information system security policies — a documented risk assessment and a written security policy, reviewed annually
  • Incident handling — a documented incident response plan with defined roles, escalation paths, and notification procedures
  • Business continuity and disaster recovery — tested backup procedures and recovery time objectives (RTOs) in writing
  • Supply chain security — due diligence on your IT vendors and subprocessors, including their security posture
  • Security in network and information system acquisition — secure-by-design requirements when buying or building systems
  • Policies and procedures to assess the effectiveness of security measures — regular testing, including penetration testing
  • Basic cyber hygiene and cybersecurity training — annual security awareness training for all staff
  • Policies on cryptography and encryption — defined and enforced encryption standards for data in transit and at rest
  • Human resources security, access control and asset management — joiners/movers/leavers procedures and privileged access controls
  • Use of multi-factor authentication and secure communications — MFA required for all administrative access

The incident notification timeline

This is the part that catches organisations off guard. NIS2 introduces a three-stage notification requirement for significant incidents:

  • Within 24 hours: early warning to your national CSIRT or competent authority
  • Within 72 hours: incident notification with initial assessment, severity, and indicators of compromise
  • Within 1 month: final report with root cause, impact assessment, and corrective measures taken

A "significant incident" is one that has caused or is capable of causing severe operational disruption or financial loss, or has affected other organisations. The threshold is deliberately broad.

What managed services can cover

The gap most SMEs face is not intent — it is operational capacity. You can have a written policy for everything Article 21 requires, but if you lack the tooling and staff to actually operate those controls 24/7, the policy is just paper.

A managed security service can provide the operational layer: continuous monitoring (satisfying the "effectiveness" requirement), managed EDR (endpoint security), documented incident response with the right notification timelines built in, and the monthly/quarterly compliance reports you'll need for audit.

Need help with NIS2 readiness?

We run NIS2 gap assessments and provide managed compliance reporting as part of our Premium tier. Book a call and we will tell you exactly where you stand.

Need help with NIS2 compliance?

Book a call and we'll give you a straight assessment of where you stand.

Talk to an engineer
← All articles