NIS2 is the most significant cybersecurity regulation the EU has passed. It covers energy, transport, banking, health, digital infrastructure, and public administration. The fines run to €10 million or 2% of global turnover. The compliance deadlines have passed.
And if you are a 20-person SaaS company in London or Warsaw, there is a good chance it does not directly apply to you.
That is not the end of the story. It is the beginning.
At Metaluxo we advise SMEs on EU cybersecurity regulation across the UK, Poland, and the wider EU. The question we hear most often is not “how do we comply with NIS2?” It is “do we need to comply with NIS2?” The answer is usually no — followed by a much more important yes.
Who is actually in scope
NIS2 divides in-scope entities into two categories: essential entities and important entities.
Essential entities include energy suppliers, transport operators, banks, financial market infrastructures, health sector bodies, drinking water and wastewater utilities, digital infrastructure providers, public administration entities, and space sector operators.
Important entities include postal and courier services, waste management, chemicals manufacturers, food production, manufacturing of medical devices, computers and electronics, machinery, motor vehicles, and digital providers such as online marketplaces, search engines, and social networking platforms.
The critical threshold is size. NIS2 applies to entities that meet both the sector criteria and the size criteria: typically more than 50 employees or an annual turnover exceeding €10 million. Smaller entities are only in scope if they are the sole provider of a critical service or if a member state designates them as nationally significant.
For the typical SME — a 15-person fintech, a 30-person healthtech platform, a 10-person SaaS tool — NIS2 does not impose direct legal obligations.
But here is what most founders miss: NIS2 imposes obligations on your customers, and those obligations flow downhill.
The supply-chain effect
Article 21 of NIS2 requires in-scope entities to address supply-chain security in their risk-management measures. Article 23 requires them to report incidents that affect the security of their network and information systems — including incidents at their suppliers.
This means that a bank in scope for NIS2 must:
- Assess the cybersecurity risk of its suppliers
- Include security requirements in procurement contracts
- Monitor the security practices of critical suppliers
- Report incidents that originate at suppliers
The bank does not want to report a supplier incident to its regulator. The bank does not want to explain why its customer data was compromised by a SaaS vendor with no incident response plan. So the bank asks every supplier — including the 20-person SaaS company — for security documentation.
The questionnaire will ask for:
- An information security policy
- Evidence of access control and multi-factor authentication
- Encryption standards for data at rest and in transit
- Incident response procedures and contact details
- Business continuity and backup arrangements
- Patch management and vulnerability disclosure processes
These are not exotic requirements. They are the baseline of reasonable security. But many SMEs have never written them down.
What “adequate security” means for a small company
NIS2 does not mandate specific technical standards. It requires “appropriate and proportionate” technical and organisational measures. For a small company, proportionality is your friend.
You do not need a Security Operations Centre. You do not need a dedicated CISO. You do not need ISO 27001 certification — though it helps enormously. You need evidence that you have thought about risk and taken reasonable steps to address it.
For a company under 50 people, reasonable security usually means:
- A named person responsible for security — even if that person is the CTO with ten other jobs.
- A risk assessment — a document that lists your top risks, scores them, and says what you are doing about them.
- Basic access control — multi-factor authentication on all admin accounts, unique passwords, and a process for removing access when someone leaves.
- Encryption — data encrypted in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
- Backups — tested backups, stored separately from production, with a documented recovery process.
- An incident response plan — who to call, in what order, and what to do in the first 24 hours.
- Patching — a process for applying security updates within a defined timeframe, typically 30 days for critical patches.
- A data-processing agreement — if you process personal data, a signed DPA with every customer and every sub-processor.
If you can produce these eight items, you can answer 90% of supply-chain security questionnaires. If you cannot, you will lose deals to competitors who can.
The overlap with ISO 27001
ISO 27001 and NIS2 are not the same, but they overlap heavily. NIS2 Article 21 lists ten risk-management areas — risk analysis, incident handling, business continuity, supply-chain security, security in network acquisition, vulnerability handling, encryption, access control, multi-factor authentication, and security training. Every one of these is covered by Annex A of ISO 27001.
For an SME, the most efficient path is often to implement ISO 27001 as your security baseline and use it to answer NIS2-related questions from customers. The certification is not required, but the framework is.
If you are not ready for full certification, a gap assessment against ISO 27001 will produce most of the documentation you need for supply-chain assurance. At Metaluxo we run these assessments in about four weeks, delivering a risk register, a treatment plan, and a set of policies that map to both ISO 27001 and NIS2 requirements.
Timeline and next steps
If you are an SME that sells to enterprise customers in the EU, here is what to do in the next 90 days:
Week 1–2: Identify your customers that are in scope for NIS2. These are typically banks, insurers, health systems, utilities, and government bodies. Review your contracts for any new security clauses they have added.
Week 3–4: Map your current security documentation against the eight-item list above. Mark what you have, what is partial, and what is missing.
Week 5–8: Close the gaps. Write the missing policies. Collect evidence for the controls you already have. Name the roles and document the assignments.
Week 9–12: Test your documentation. Ask a friendly customer or a consultant to review it as if they were auditing a supplier. Fix anything that is unclear, inconsistent, or missing.
After 90 days, you should have a security documentation pack that answers supply-chain questionnaires in hours, not weeks.
When to bring in help
A founder with a technical background can close most of these gaps without external help. The value of a partner is in:
- Knowing which questions enterprise customers actually ask — not the theoretical compliance checklist, but the real procurement questionnaire
- Mapping one set of policies to multiple frameworks — ISO 27001, NIS2, SOC 2, and GDPR — so you do not write four parallel documents
- Keeping the timeline to 90 days instead of letting it drift into the next quarter
At Metaluxo we run NIS2 and ISO 27001 readiness programmes for SMEs across the EU and UK. If your customers are asking for security documentation and you are not sure what they need, book a free 30-minute consultation and we will tell you exactly what to produce.
NIS2 may not apply to you directly. But your customers’ obligations now apply to you by contract. The SMEs that win enterprise deals in 2025 and 2026 will be the ones that saw this coming and prepared before the questionnaire arrived.
Common questions
What is the deadline for NIS2 compliance?
Member states were required to transpose NIS2 into national law by 17 October 2024. The rules are now in effect across the EU, with enforcement beginning in 2025.
Does NIS2 apply to UK companies?
NIS2 is EU law and does not directly apply to the UK. However, UK companies that provide services to EU entities in scope may be contractually required to meet equivalent standards. The UK has its own NIS regulations, which are being reviewed for alignment.
What happens if an SME ignores a customer's NIS2 security request?
The customer will likely switch to a supplier that can provide the documentation. For an SME, losing one enterprise contract because of missing security evidence is often more expensive than producing the documentation.