Skip to main content
MAG&Cie
Aller au contenu

§ cybersecurity·9 min read·

NIS2 for SMBs: am I in scope, what must I do and what does it cost?

NIS2 covers medium and large organizations in 18 sectors across the EU, from 50 employees or €10M in turnover and balance sheet. Who is in scope, essential vs important entities, the 10 Article 21 measures, incident reporting, fines, real costs — and where France stands in October 2026.

By MAG&CieNIS2SMBmid-size companiescybersecurity
§ Sommaire
  1. § 01Why so many SMBs are discovering NIS2 now
  2. § 02Am I in scope?
  3. § 03What are the 10 measures of Article 21?
  4. § 04What are the incident reporting deadlines?
  5. § 05What are the fines?
  6. § 06Where does France stand? (October 2026)
  7. § 07How much does NIS2 compliance cost?
  8. § 08Where to start in practice
  9. § 09Conclusion

In short: NIS2 (Directive (EU) 2022/2555) covers medium and large organizations in 18 sectors across the EU — in principle from 50 employees, or €10M in turnover and balance sheet. Entities are essential or important depending on their sector and size. Article 21 requires 10 families of measures; significant incidents must be reported within 24 h / 72 h / 1 month; fines reach €10M or 2% of worldwide turnover for essential entities, and management bodies are accountable. In France, the directive is still not transposed as of October 2026, but ANSSI has published its ReCyF framework and targets full compliance by the end of 2028. Cost for an SMB: €5,000 to €150,000 excl. VAT depending on the starting point.

Why so many SMBs are discovering NIS2 now

NIS2 was adopted at the end of 2022 and member states had to transpose it by 17 October 2024. It massively widens the scope of the former NIS1 directive: where NIS1 targeted a limited set of "operators of essential services", NIS2 covers 18 sectors and reaches down to medium-sized companies.

Many SMB owners therefore find out they're in scope even though they never saw themselves as "critical infrastructure". This article answers the questions they ask us most often.

Am I in scope?

Criterion 1: size

NIS2 applies in principle to medium and large enterprises as defined by Recommendation 2003/361/EC:

  • medium-sized enterprise: 50 or more employees, or annual turnover and balance sheet total above €10M;
  • large enterprise: 250 or more employees, or turnover above €50M and balance sheet above €43M.

Some entities are in scope regardless of size: top-level domain name registries, DNS service providers, qualified trust service providers, providers of public electronic communications networks or services, entities designated as the sole provider of an essential service, certain public administration bodies.

Criterion 2: sector

Annex I — sectors of high criticality (11)

  1. Energy (electricity, district heating and cooling, oil, gas, hydrogen)
  2. Transport (air, rail, water, road)
  3. Banking
  4. Financial market infrastructures
  5. Health (healthcare providers, labs, manufacturers of pharmaceuticals and critical medical devices…)
  6. Drinking water
  7. Waste water
  8. Digital infrastructure (internet exchange points, DNS, TLD registries, cloud computing, data centres, content delivery networks, trust services, electronic communications)
  9. ICT service management, business-to-business (managed service providers and managed security service providers)
  10. Public administration
  11. Space

Annex II — other critical sectors (7)

  1. Postal and courier services
  2. Waste management
  3. Manufacture, production and distribution of chemicals
  4. Production, processing and distribution of food
  5. Manufacturing (medical devices, computer and electronic products, electrical equipment, machinery, motor vehicles and other transport equipment)
  6. Digital providers (online marketplaces, search engines, social networking platforms)
  7. Research

Essential or important entity?

SizeAnnex I sectorAnnex II sector
Large enterpriseEssentialImportant
Medium-sized enterpriseImportantImportant
Small enterpriseOut of scope, with exceptionsOut of scope, with exceptions

Security obligations are very similar for both. What changes is the intensity of supervision (ex ante checks possible for essential entities, ex post for important ones) and the fine ceilings.

Practical examples

  • Chain of dental clinics, 80 employees: health, Annex I, medium-sized → important entity.
  • Managed IT provider, 60 employees, running its clients' systems: B2B ICT service management, Annex I, medium-sized → important entity.
  • Chemicals SMB, 120 employees: Annex II → important entity.
  • Accounting firm, 70 employees: accounting is not a NIS2 sector → normally out of scope (to be reviewed if it provides managed IT services to clients).
  • B2C e-commerce, 60 employees, selling its own products: normally out of scope — unless it runs an online marketplace open to third-party sellers.

What are the 10 measures of Article 21?

Article 21 lists the technical, operational and organisational measures to implement, proportionate to the risks:

#MeasureWhat to do in practice
1Risk analysis and IS security policiesWritten document, approved by management, reviewed yearly
2Incident handlingDocumented procedure, named owners, tracking tool
3Business continuity, backups, disaster recovery, crisis managementRegularly tested backups, written recovery plan, yearly exercise
4Supply chain securityMap of critical suppliers, cyber clauses in contracts
5Security in acquisition, development and maintenanceSecure development, code review, vulnerability handling, pre-production testing
6Assessing the effectiveness of measuresPeriodic internal audit, metrics (detection and remediation times, endpoint coverage…)
7Basic cyber hygiene and trainingRegular awareness for everyone, dedicated training for management
8Cryptography and encryptionEncryption at rest and in transit, key and certificate management
9HR security, access control, asset managementDocumented joiners/leavers, least privilege, up-to-date inventory
10Multi-factor authentication, secured communicationsMFA on all admin and remote access, encrypted communications

If you already follow recognized frameworks such as the CIS Controls, ISO 27001 or, in France, ANSSI's hygiene guide and ReCyF, you've covered a good part of the way; what usually remains is formal documentation, governance and the supply chain.

What are the incident reporting deadlines?

Article 23 sets three deadlines for any significant incident:

1

Within 24 hours: early warning

Report the incident, indicating whether it may be caused by malicious acts or have a cross-border impact.

2

Within 72 hours: incident notification

Initial assessment: severity, impact, available indicators of compromise.

3

Within one month: final report

Detailed description, likely root cause, mitigation measures, cross-border impact if any. A progress report if the incident is still ongoing.

Reports go to the national CSIRT or competent authority each member state designates. Operational tip: prepare a notification template in your incident response plan now — on the day, you won't have time to write it.

What are the fines?

Essential entities

  • Administrative fines up to €10M or 2% of worldwide annual turnover (whichever is higher) — the minimum ceiling the directive requires.
  • Possible temporary ban from managerial functions for the person responsible, in case of persistent breaches.

Important entities

  • Administrative fines up to €7M or 1.4% of worldwide annual turnover.

What really changes: management accountability

Article 20 requires the management bodies of both essential and important entities to approve cybersecurity risk-management measures, oversee their implementation and follow training. They can be held liable for infringements. Cybersecurity becomes a board-level topic, not just an IT one.

Where does France stand? (October 2026)

The obligations are therefore not yet legally applicable in France, but the direction is clear:

  • ANSSI published ReCyF (France's cyber framework) on 17 March 2026: 20 security objectives, the first 15 applying to all entities and the last 5 to essential entities only;
  • voluntary pre-registration with ANSSI has been open since 24 November 2025;
  • ANSSI's director general said on 1 October 2026 that the agency envisages requiring full compliance by the end of 2028;
  • large customers already subject to NIS2 elsewhere in Europe are sending supplier security questionnaires today.

A serious compliance effort takes 6 to 18 months: starting in 2026 isn't premature.

How much does NIS2 compliance cost?

Orders of magnitude we observe, depending on starting maturity:

Case 1: an already well-equipped SMB

MFA everywhere, EDR, tested backups, written incident plan, yearly awareness training. Cost: €5,000 to €15,000 excl. VAT — formal documentation, supply chain, incident plan aligned with NIS2 deadlines. Lead time: 2 to 4 months.

Case 2: an equipped SMB without governance

Basic antivirus, never-tested backups, no incident plan, no training. Cost: €20,000 to €50,000 excl. VAT — audit, 12-month roadmap, essential tooling (EDR, MFA, device management), training, documentation. Lead time: 6 to 9 months.

Case 3: an SMB starting from scratch

No cyber processes, shared admin accounts, no documentation. Cost: €60,000 to €150,000 excl. VAT over 12 to 18 months — audit, tooling, part-time CISO support, training, access overhaul, crisis exercises.

Beyond compliance, a documented cyber posture makes cyber insurance easier to obtain and answers the security questionnaires of your large customers.

Where to start in practice

1. Confirm scope (1 day)

Size, sector, group membership, activities. Keep a written record. Consider voluntary pre-registration with your national authority.

2. Assess yourself against Article 21 (2 weeks)

Identify critical gaps measure by measure. At MAG&Cie, our free self-assessment (20 minutes online, maturity report within 48 hours, questionnaire in French) gives a first snapshot; the full posture audit (€3,500 to €4,500 excl. VAT) delivers a detailed diagnosis and action plan.

3. Build a prioritized roadmap (2 weeks)

  • P0, within 30 days: MFA everywhere, backup restore test, minimal incident plan.
  • P1, within 90 days: EDR, awareness training, device management, supplier mapping.
  • P2, within 12 months: centralized monitoring, crisis exercises, possibly ISO 27001 certification.

4. Document measure by measure (1 month)

For each of the 10 measures: an owner, documentary evidence, operational evidence. That's your compliance file.

5. Maintain it over time

Quarterly policy review, yearly penetration test and crisis exercise. Compliance is a cycle, not a finish line.

Conclusion

NIS2 targets medium and large organizations in 18 sectors. The obligations — 10 measures (Article 21), 24 h / 72 h / 1 month reporting, management accountability — are known; in France only the application date is still pending the Resilience bill, with ANSSI targeting full compliance by the end of 2028.

👉 Start with our free cybersecurity self-assessment (20 minutes online, 8 domains, maturity report within 48 hours), available from the Cybersecurity posture audit page.

For a full audit led by a consultant — per-domain scoring, prioritized action plan, NIS2 Article 21 reading — see the MAG&Cie cybersecurity posture audit, €3,500 to €4,500 excl. VAT depending on scope.

Sources: Directive (EU) 2022/2555 "NIS2", Recommendation 2003/361/EC on the SME definition, French transposition status as of 10 October 2026 (AOCSI, NIS Solutions).

§ Tags

NIS2SMBmid-size companiescybersecuritycomplianceANSSIFranceReCyF
Back to blog

§ FAQ

Questions frequentes

  • Is my SMB in scope of NIS2?
    Two main cumulative criteria: (1) size — at least a medium-sized enterprise under EU rules, i.e. 50 or more employees, or annual turnover AND balance sheet total above €10M; (2) sector — one of the 18 sectors in Annexes I and II of the directive (energy, transport, banking, health, water, digital infrastructure, B2B ICT service management, public administration, space, postal services, waste, chemicals, food, manufacturing, digital providers, research…). Some entities are in scope regardless of size (top-level domain registries, DNS providers, qualified trust service providers, etc.). A 30-employee e-commerce company is normally out of scope.
  • What's the difference between an essential and an important entity?
    It depends on sector AND size. A large enterprise (250+ employees, or over €50M turnover and €43M balance sheet) in an Annex I sector is normally essential. A medium-sized enterprise in Annex I, or any medium or large enterprise in Annex II, is normally important. Security obligations are close; what differs is the intensity of supervision (ex ante for essential entities, ex post for important ones) and the fine ceilings.
  • Has France transposed NIS2?
    As of 10 October 2026, no. The French 'Resilience' bill was adopted by the Senate on 12 March 2025 and in committee at the National Assembly on 10 September 2025, but its floor debate has been postponed several times. The European Commission referred France to the EU Court of Justice on 8 July 2026. Meanwhile ANSSI published its ReCyF framework on 17 March 2026, opened voluntary pre-registration, and its director general said on 1 October 2026 the agency envisages requiring full compliance by the end of 2028.
  • What are the 10 measures of NIS2 Article 21?
    (1) Risk analysis and information system security policies, (2) incident handling, (3) business continuity, backup management, disaster recovery and crisis management, (4) supply chain security, (5) security in acquisition, development and maintenance, including vulnerability handling, (6) policies to assess the effectiveness of measures, (7) basic cyber hygiene and training, (8) cryptography and encryption, (9) human resources security, access control and asset management, (10) multi-factor authentication and secured communications.
  • What are the NIS2 incident reporting deadlines?
    Three deadlines after becoming aware of a significant incident: early warning within 24 hours, incident notification within 72 hours, final report within one month. Reports go to the national CSIRT or competent authority designated by each member state.
  • What are the fines for NIS2 non-compliance?
    Member states must provide administrative fines with a maximum of at least €10M or 2% of worldwide annual turnover (whichever is higher) for essential entities, and at least €7M or 1.4% for important entities. Management bodies must approve cybersecurity measures, oversee their implementation and follow training, and can be held liable. For essential entities, a temporary ban from managerial functions is also possible.
  • How much does NIS2 compliance cost an SMB?
    Orders of magnitude we observe, depending on starting maturity: €5,000 to €15,000 excl. VAT for an already well-equipped SMB (mostly documentation and supply chain), €20,000 to €50,000 for an equipped SMB without cyber governance, €60,000 to €150,000 over 12 to 18 months for an SMB starting from scratch (audit, tooling, part-time CISO support, training).

§ Related articles

Related articles