NIS2 for SMEs: What Changes and How to Become Compliant
NIS2 for SMEs: who is in scope, the security obligations, deadlines and fines. A practical guide to what you need to do now, without the scaremongering.

In this article
The NIS2 Directive extends cybersecurity obligations to many small and medium-sized businesses that were previously out of scope. In short, if you have at least 50 employees or a turnover above 10 million euro and operate in an "important" sector (such as manufacturing, food, logistics or digital services), you must register, manage your cyber risks and report serious incidents within tight deadlines. Fines run into the millions.
What NIS2 Is and Why It Also Affects Smaller Companies
NIS2 (EU Directive 2022/2555) is the European law on the security of network and information systems. It replaces the original 2016 NIS Directive and, in Italy, was transposed through Legislative Decree 138/2024, which came into force on 16 October 2024. The competent authority is the ACN — the National Cybersecurity Agency.
The shift from the previous regime is stark. The first NIS Directive covered almost exclusively large operators of critical infrastructure (energy, banking, healthcare). NIS2 widens the perimeter enormously: many SMEs that have never dealt with security compliance now fall among the obligated entities. In our hands-on experience with businesses across the region, this is precisely the point that catches most owners off guard.
The logic is straightforward. Supply chains are built on small and medium-sized firms. Attacking a supplier to reach a larger customer is the favourite tactic of ransomware groups. That is why the directive asks the entire chain to maintain a minimum level of cyber hygiene.
Which SMEs Fall Under NIS2
Not every SME is affected. NIS2 applies two combined criteria: the size of the company and its sector of activity.
The Size Criterion
As a rule, "medium" and "large" enterprises are in scope, meaning those with:
- at least 50 employees, or
- an annual turnover or balance sheet total above 10 million euro.
Micro and small enterprises below these thresholds are generally excluded, except for entities considered critical regardless of size (for example trust service providers, domain name registries and certain digital infrastructure).
The Sector Criterion
Your sector must appear among those listed in the directive's annexes, which are split into:
- Sectors of high criticality ("essential" entities): energy, transport, banking, financial market infrastructure, healthcare, drinking and waste water, digital infrastructure, public administration, space.
- Other critical sectors ("important" entities): postal services, waste management, the manufacture and distribution of chemicals, food production, manufacturing (medical devices, electronics, machinery, motor vehicles), digital service providers (marketplaces, search engines, social platforms) and research.
It is precisely in manufacturing, logistics and agri-food that we find most of the businesses now brought into scope. If you are unsure about your position, we are happy to talk it through: get in touch for a free preliminary assessment.
What Actually Changes: The New Obligations
Anyone within scope has to meet three groups of requirements.
1. Registration with the ACN
Obligated entities must register on the National Cybersecurity Agency platform, providing their details and keeping them up to date. The registration windows are set by the ACN with firm deadlines: failing to register does not exempt you from the law, and it exposes you to penalties for the missed notification.
2. Risk Management Measures
This is the heart of NIS2. The directive requires an "all-hazards" approach with proportionate technical and organisational measures. In practice, you need to cover at least:
- Risk analysis and management and information system security policies.
- Incident handling (detection, response, recovery).
- Business continuity: backup, disaster recovery and crisis management. This is where reliable architecture comes in — from redundant business servers to data replication and immutable offline backups.
- Supply chain security, assessing your direct suppliers.
- Security in the acquisition, development and maintenance of networks and systems, including vulnerability management.
- Basic cyber hygiene and staff training.
- Cryptography and encryption where appropriate.
- Access control and asset management.
- Multi-factor authentication (MFA) and secure communications.
One detail that is often overlooked: NIS2 introduces the direct accountability of management bodies. Directors and senior managers must approve the measures, oversee their implementation and complete specific training. It is no longer just an IT department problem.
3. Incident Reporting
When a significant incident occurs, strict timelines kick in towards the Italian CSIRT:
- within 24 hours: an early warning;
- within 72 hours: a notification with an initial assessment of the incident;
- within one month: a final report with a detailed analysis.
Having detection procedures and centralised logs is not a luxury: without monitoring, you simply will not spot the incident in time to meet the 24-hour window.
The Fines: What an SME Actually Risks
NIS2 has real teeth on the financial side too. Legislative Decree 138/2024 sets out tiered administrative fines:
- for essential entities, up to 10 million euro or 2% of annual worldwide turnover, whichever is higher;
- for important entities, up to 7 million euro or 1.4% of annual worldwide turnover.
On top of that, measures can be taken against senior leadership. The message is clear: compliance is not a formality you can keep putting off.
How an SME Prepares: The Practical Steps
As a system integrator, we follow a five-stage path, calibrated to the real resources of a small or medium-sized business.
Step 1 — Applicability Check
First, establish whether and how you are in scope: size, sector, and classification as essential or important. This is a desk analysis that stops you both from underestimating your obligations and from spending on requirements that do not apply to you.
Step 2 — Gap Analysis
Here we compare the current state of your security with what NIS2 requires. The gaps surface: no MFA? Backups never tested? No incident response plan? The outcome is an honest snapshot of where you stand.
Step 3 — Remediation Plan
From those gaps comes a plan with priorities, timelines and budget. Companies that already hold an ISO 27001 certification start with an advantage, because many NIS2 measures overlap with an Information Security Management System. At TN Solutions we are certified to ISO 9001 and ISO 27001, and we know that overlap well.
Step 4 — Technical Implementation
This is where we work on the infrastructure: network segmentation, MFA, 3-2-1 backups with an immutable copy, server hardening, and monitoring and logging systems. We go into the concrete solutions on our dedicated page on cybersecurity for businesses, which also covers business continuity and server protection.
Step 5 — Governance and Ongoing Training
Security is not a project with an end date: it is a process. It calls for periodic risk reviews, updated procedures and staff training, from directors down to day-to-day operators.
NIS2 and Intelligent Monitoring
One of the hardest challenges for an SME is spotting the incident in time. With lean IT teams, checking logs by hand is impractical. That is why we developed Hector, our AI-based monitoring platform that watches over servers and infrastructure, identifies anomalies and flags suspicious behaviour before it turns into a serious incident. It is practical support exactly where NIS2 demands timely detection and business continuity.
Get NIS2 Compliant with a Local Partner
NIS2 is not a piece of red tape to endure, but a chance to make your business genuinely resilient. For over 25 years we have supported SMEs in Melzo and across Lombardy in protecting their servers and infrastructure, with the pragmatism of a team that works in the field (Google 4.7/5 from 37 reviews).
Call TN Solutions on 02 9517550 for a NIS2 applicability check and a gap analysis of your infrastructure, or contact us via our contact page. We will tell you plainly what you need to do — and what you don't.
Frequently asked questions
My company has fewer than 50 employees: am I still affected?
Generally no: below the thresholds of 50 employees and 10 million euro in turnover, you are excluded. There are, however, exceptions for critical entities regardless of size (for example specific digital service providers or strategic infrastructure). A case-by-case check is always worthwhile.
What is the difference between "essential" and "important" entities?
The distinction depends on sector and size. Essential entities operate in areas of high criticality and face stricter supervision and heavier penalties; important entities have similar obligations but with ex-post supervision and lower maximum fines.
If I already have ISO 27001, am I fine for NIS2?
No, but you are well ahead. ISO 27001 covers a large part of the required risk management measures, yet NIS2 adds specific obligations such as ACN registration and the 24/72-hour notifications. A targeted alignment is still needed.
By when do I have to report an incident?
An early warning within 24 hours, a notification with an assessment within 72 hours, and a final report within one month of the significant incident, all through the Italian CSIRT.
How much does NIS2 compliance cost?
It depends on your starting point. A company with a well-ordered infrastructure and tested backups invests little; one starting from scratch has to budget for work on the network, backups and monitoring. The gap analysis exists precisely to estimate the real effort involved.
Technology partners
Want to discuss it with our team?
We analyse your infrastructure for free and propose the most suitable solution.







