By
Logiks Lab
Published on
August 9, 2026
Updated on
August 13, 2026

NIS2 for SMEs: 2026 compliance guide to move forward without suffering

This guide links NIS2 for SMEs: 2026 compliance guide to the decisions, evidence, risks and steps necessary to act within a controlled scope.

Work computer, illustrating ransomware protection for an SME.
Type
Practical guide
Level
Expert
Reading time
13
Progress0 %

NIS2 does not ask SMEs to become administrations.
It asks them to prove that cyber risks are governed, measured and addressed.

1. Key figures

NumberSource, date and scopeInterpretation for an SME
17 October 2024Directive (EU) 2022/2555, article 41: deadline for adoption and publication of national transposition measures.The European calendar has already passed; an SME can no longer treat NIS2 as a distant subject.
18 October 2024Directive NIS2: application of national measures from October 18 2024.The obligations become operational through national transpositions.
Medium businessArticle 2: entities in Annexes I and II qualifying as medium-sized enterprises or exceeding these ceilings. The European SME recommendation sets in particular the threshold of 50 salaries and 10 M EUR.The SME "too small to be critical" is no longer always off-screen.
10 M EUR or 2 %Article 34: maximum minimum ceiling for essential entities in the event of violation of articles 21 or 23.The sanction mainly targets serious cases, but it imposes management governance.
7 M EUR or 1,4 %Item 34: Maximum minimum cap for large entities.A significant entity remains exposed to a structuring level of sanction.
17 March 2026ANSSI indicates that it has shared the ReCyF, the Cyber France benchmark, as a working document linked to the Resilience bill.In France, SMEs must follow ANSSI and not wait until the last moment.
2 weeksArticle 3: notification of changes to information submitted to the authorities within two weeks.Compliance involves a living update, not a fixed record.

2. Introduction

An SME hears "NIS2" and often thinks: large account, critical operator, European jargon, expensive audit, consultant, compliance spreadsheet. Then a strategic client requests cyber proof, an insurer requests a backup policy, a cloud provider imposes MFA, a call for tenders adds an incident clause, a manager discovers that his sector is included in an annex.

The verdict: NIS2 transforms cybersecurity into a governance obligation.

It does not replace RGPD, ISO 27001, contractual requirements or ANSSI best practices. It organizes a European requirement for resilience: risks, measures, incidents, responsibility, supervision, proof. The right angle, on the SME side, is not to certify everything at once. It consists of proving that the critical risks are known, reduced and controlled.

3. Actors of the device NIS2

ActorRoleWhat the SME must understand
European UnionNIS2 framework, annexes, obligations and minimum sanctions.The source text remains the legal reference.
French stateNational transposition, Resilience bill, designation of authorities.The practical arrangements depend on French law.
ANSSINational cyber authority, support, benchmarks, control according to perimeter.ANSSI publications structure anticipation.
General managementCyber ​​policy approval, prioritization and accountability.NIS2 cannot be fully delegated to IT.
Internal or external DSI/CISOMapping, technical measures, incidents, evidence.Piloting must be documented.
ProfessionsOwners of critical services.The impacts are not only technical.
Suppliers and customersSupply chain, clauses, subcontracting, contractual requirements.Even outside the direct scope, an SME can be impacted by its clients.
Cyber insurer and legal adviceRisk assessment, exclusions, contracts, responsibilities.Guarantees often depend on concrete evidence.

NIS2 compliance is not earned in a single department. It is orchestrated between management, IT, operations, legal and suppliers.

4. Definition

NIS2 is the European directive 2022/2555 which imposes a high common level of cybersecurity on essential and important entities in sectors listed in Annexes I and II. It covers in particular risk management, incident notification obligations, governance, supervision and sanctions.

SME rating, NIS2 becomes a question of perimeter. The company may be affected directly by its sector and its size, indirectly by its role in a critical chain, or contractually by the requirements of customers already subject to it.

5. Why the subject becomes priority in 2026

The European text has set the transposition to 17 October 2024 and the application from 18 October 2024. In France, ANSSI communicates on the directive at the pace of national transposition and has published 17 March 2026 ReCyF as a working document linked to the Resilience bill.

This situation creates an uncomfortable period: managers know that the requirement is coming, but the final terms can still evolve. Waiting for the final version to commit to a base, however, amounts to wasting time. NIS2 measures overlap with already defensible fundamentals: risk analysis, security policies, incident management, continuity, backups, MFA, supply chain security, cyber hygiene, training, encryption, access control.

The real subject 2026 is therefore not "is everything finalized?"
The right question is: "what evidence can we already produce?"

6. SEO/GEO cyber

For an article or internal documentation on NIS2, SEO responds to the search intent: "who is concerned", "what sanctions", "what to do in SMEs", "France calendar". GEO asks for more: self-contained definitions, dates, referenced articles, tables and explicit boundaries.

In a changing regulatory context, citability is based on three elements: citing the European text, distinguishing France and the European Union, then separating certain obligation and prudent recommendation.

An SME needs actionable information, not anxiety-inducing paraphrase.

7. Recommended method

This method uses cyber compliance best practices, NIS2 requirements and ANSSI logic. It is not a proprietary method Logiks.

7.1. Qualify the perimeter

Start with Annexes I and II, sector, services provided, countries served, size, turnover, balance sheet and exceptions. Distinguish between essential entity, important entity, critical supplier and simple subcontractor.

7.2. Identify critical services

A critical service is not always the most visible application. This could be production, logistics, billing, reservation, supervision, support, identity, messaging or customer API. Without business mapping, security remains abstract.

7.3. Map the IS and dependencies

List applications, hosts, cloud, providers, flows, sensitive data, privileged accounts, external connections, backups and detection tools. The supply chain becomes a central point.

7.4. Assess the risks

For each service, combine likelihood, impact, exposure, supplier dependency and recovery capacity. Scoring does not need to be perfect from the start. It must be coherent and revisable.

7.5. Implement basic measures

MFA, rights management, tested backups, patches, segmentation, inventory, logging, EDR or managed antivirus, awareness, password policy, cloud security, employee departure procedure.

7.6. Formalize incident management

Name the contacts, thresholds, reflexes, evidence, providers, crisis channels and notification process. The incident should not be discovered at the same time as the plan.

7.7. Supervise suppliers

Integrate security clauses, notification deadlines, localization, MFA requirements, safeguards, subcontracting, reasonable audit rights and commitment to cooperation. NIS2 draws cyber towards the contractual relationship.

7.8. Produce evidence

SSI policy, asset register, risk matrix, committee reports, MFA evidence, backup reports, restoration tests, training, scans, action plans, contracts, access review.

7.9. Organize governance

Management must validate accepted risks, finance priorities and review progress. A short quarterly committee is better than a large document that is never proofread.

8. Tips Logiks

We recommend avoiding two extremes: passive waiting and total construction. An SME must start from evidence that is already useful for its customers, its insurer and its management.

Priority 1: perimeter and critical services. As long as you do not know whether you are affected, directly or by contract, each action lacks direction.

Priority 2: incidents and backups. Notification and resilience obligations make the detection-recovery duo essential. An untested backup remains a promise.

Priority 3: suppliers. Many SMEs will be driven by their principals. A well-prepared cyber questionnaire can become a commercial advantage.

Finally, we advise documenting soberly. A binder of 80 pages does not protect better than a clear architecture. The evidence must be short, dated, attributed, linked to a risk.

9. Decision grid

LocationIndexPriority action
Likely direct concernAnnex I/II sector, medium or large size, service in the EU.Legal analysis + mapping NIS2 complete.
Probably indirect concernSupplier of a critical entity, customer IS access, sensitive digital service.Cyber questionnaire, clauses, basic evidence.
Contractual concernsCustomer imposes NIS2 requirements in an RFP.Evidence file, improvement plan, standard responses.
Out of visible fieldSmall structure without critical sector.ANSSI cyber base and annual monitoring.

The qualification must be reviewed in the event of croissance, acquisition, new country, new service or new critical customer.

10. Common errors

First mistake: to believe that NIS2 concerns only large companies. The directive also refers to medium-sized entities according to sector and service.

Second error: confusing conformity and ISO certification 27001. ISO 27001 can help, but NIS2 remains a specific legal framework.

Third error: wait for definitive French law to correct the fundamentals. MFA, backups, incidents, suppliers and mapping are already useful.

Fourth mistake: delegate the entire subject to IT. Management validates risks, budgets and arbitrages.

Fifth mistake: producing policies without technical proof. Control will require traces, not just intentions.

Last mistake: forgetting the suppliers. An uncontrolled service provider can fraguse the entire chain.

11. Action plan 30 / 60 / 90 days

11.1. Within 30 days

  • qualify sector, size and country;
  • identify critical services;
  • list the major applications and suppliers;
  • enable MFA on email, VPN, cloud and admin;
  • check backups;
  • name a driver NIS2;
  • open an evidence register.

We place the base.

11.2. Within 60 days

  • formalize a simple risk analysis;
  • document existing measures;
  • create an incident procedure;
  • test a restoration;
  • review privileged access;
  • integrate cyber clauses into new contracts;
  • prepare a customer questionnaire.

The SME becomes defensible.

11.3. Within 90 days

  • organize a management committee;
  • prioritize gaps by impact;
  • launch phishing and hygiene training;
  • plan scans and fixes;
  • simulate an incident;
  • publish a monthly cyber dashboard;
  • update the evidence file.

Compliance becomes management.

12. FAQ

12.1. Are all SMEs affected by NIS2?

No. The scope depends on the sector, the size, the service provided and certain special cases. On the other hand, many SMEs will be affected indirectly via liable customers or suppliers.

12.2. Is a company with less than 50 employees still out of scope?

Not always. Exceptions exist for certain types of entities or services. It is necessary to analyze the text, the national transposition and the concrete role of the company.

12.3. What should you do first?

Qualify the perimeter, map critical services and secure high-impact measures: MFA, tested backups, rights management, incidents, suppliers.

12.4. Does NIS2 impose ISO 27001?

No. ISO 27001 can provide a structuring framework, but NIS2 does not automatically impose ISO 27001 certification on all entities.

12.5. What is the difference between essential and important entity?

Essential entities are subject to more proactive supervision and a higher minimum maximum sanction cap. Large entities remain subject to strong obligations, with more reactive supervision.

13. Conclusion

NIS2 should not be approached as a documentary mountain. In an SME, it becomes a maturity grid: knowing what is critical, protecting what matters, detecting what goes wrong, restoring what falls, proving what has been done.

Meaningful compliance begins before sanction. It clarifies responsibility, strengthens customer trust and gives management a common language with IT.

It is no longer an isolated cyber obligation.
It is a discipline of resilience.

14. Main sources