In short: NIS2 (Directive (EU) 2022/2555) covers medium and large organizations in 18 sectors across the EU — in principle from 50 employees, or €10M in turnover and balance sheet. Entities are essential or important depending on their sector and size. Article 21 requires 10 families of measures; significant incidents must be reported within 24 h / 72 h / 1 month; fines reach €10M or 2% of worldwide turnover for essential entities, and management bodies are accountable. In France, the directive is still not transposed as of October 2026, but ANSSI has published its ReCyF framework and targets full compliance by the end of 2028. Cost for an SMB: €5,000 to €150,000 excl. VAT depending on the starting point.
Why so many SMBs are discovering NIS2 now
NIS2 was adopted at the end of 2022 and member states had to transpose it by 17 October 2024. It massively widens the scope of the former NIS1 directive: where NIS1 targeted a limited set of "operators of essential services", NIS2 covers 18 sectors and reaches down to medium-sized companies.
Many SMB owners therefore find out they're in scope even though they never saw themselves as "critical infrastructure". This article answers the questions they ask us most often.
Am I in scope?
Criterion 1: size
NIS2 applies in principle to medium and large enterprises as defined by Recommendation 2003/361/EC:
- medium-sized enterprise: 50 or more employees, or annual turnover and balance sheet total above €10M;
- large enterprise: 250 or more employees, or turnover above €50M and balance sheet above €43M.
Some entities are in scope regardless of size: top-level domain name registries, DNS service providers, qualified trust service providers, providers of public electronic communications networks or services, entities designated as the sole provider of an essential service, certain public administration bodies.
Criterion 2: sector
Annex I — sectors of high criticality (11)
- Energy (electricity, district heating and cooling, oil, gas, hydrogen)
- Transport (air, rail, water, road)
- Banking
- Financial market infrastructures
- Health (healthcare providers, labs, manufacturers of pharmaceuticals and critical medical devices…)
- Drinking water
- Waste water
- Digital infrastructure (internet exchange points, DNS, TLD registries, cloud computing, data centres, content delivery networks, trust services, electronic communications)
- ICT service management, business-to-business (managed service providers and managed security service providers)
- Public administration
- Space
Annex II — other critical sectors (7)
- Postal and courier services
- Waste management
- Manufacture, production and distribution of chemicals
- Production, processing and distribution of food
- Manufacturing (medical devices, computer and electronic products, electrical equipment, machinery, motor vehicles and other transport equipment)
- Digital providers (online marketplaces, search engines, social networking platforms)
- Research
Essential or important entity?
| Size | Annex I sector | Annex II sector |
|---|---|---|
| Large enterprise | Essential | Important |
| Medium-sized enterprise | Important | Important |
| Small enterprise | Out of scope, with exceptions | Out of scope, with exceptions |
Security obligations are very similar for both. What changes is the intensity of supervision (ex ante checks possible for essential entities, ex post for important ones) and the fine ceilings.
Practical examples
- Chain of dental clinics, 80 employees: health, Annex I, medium-sized → important entity.
- Managed IT provider, 60 employees, running its clients' systems: B2B ICT service management, Annex I, medium-sized → important entity.
- Chemicals SMB, 120 employees: Annex II → important entity.
- Accounting firm, 70 employees: accounting is not a NIS2 sector → normally out of scope (to be reviewed if it provides managed IT services to clients).
- B2C e-commerce, 60 employees, selling its own products: normally out of scope — unless it runs an online marketplace open to third-party sellers.
What are the 10 measures of Article 21?
Article 21 lists the technical, operational and organisational measures to implement, proportionate to the risks:
| # | Measure | What to do in practice |
|---|---|---|
| 1 | Risk analysis and IS security policies | Written document, approved by management, reviewed yearly |
| 2 | Incident handling | Documented procedure, named owners, tracking tool |
| 3 | Business continuity, backups, disaster recovery, crisis management | Regularly tested backups, written recovery plan, yearly exercise |
| 4 | Supply chain security | Map of critical suppliers, cyber clauses in contracts |
| 5 | Security in acquisition, development and maintenance | Secure development, code review, vulnerability handling, pre-production testing |
| 6 | Assessing the effectiveness of measures | Periodic internal audit, metrics (detection and remediation times, endpoint coverage…) |
| 7 | Basic cyber hygiene and training | Regular awareness for everyone, dedicated training for management |
| 8 | Cryptography and encryption | Encryption at rest and in transit, key and certificate management |
| 9 | HR security, access control, asset management | Documented joiners/leavers, least privilege, up-to-date inventory |
| 10 | Multi-factor authentication, secured communications | MFA on all admin and remote access, encrypted communications |
If you already follow recognized frameworks such as the CIS Controls, ISO 27001 or, in France, ANSSI's hygiene guide and ReCyF, you've covered a good part of the way; what usually remains is formal documentation, governance and the supply chain.
What are the incident reporting deadlines?
Article 23 sets three deadlines for any significant incident:
Within 24 hours: early warning
Report the incident, indicating whether it may be caused by malicious acts or have a cross-border impact.
Within 72 hours: incident notification
Initial assessment: severity, impact, available indicators of compromise.
Within one month: final report
Detailed description, likely root cause, mitigation measures, cross-border impact if any. A progress report if the incident is still ongoing.
Reports go to the national CSIRT or competent authority each member state designates. Operational tip: prepare a notification template in your incident response plan now — on the day, you won't have time to write it.
What are the fines?
Essential entities
- Administrative fines up to €10M or 2% of worldwide annual turnover (whichever is higher) — the minimum ceiling the directive requires.
- Possible temporary ban from managerial functions for the person responsible, in case of persistent breaches.
Important entities
- Administrative fines up to €7M or 1.4% of worldwide annual turnover.
What really changes: management accountability
Article 20 requires the management bodies of both essential and important entities to approve cybersecurity risk-management measures, oversee their implementation and follow training. They can be held liable for infringements. Cybersecurity becomes a board-level topic, not just an IT one.
Where does France stand? (October 2026)
The obligations are therefore not yet legally applicable in France, but the direction is clear:
- ANSSI published ReCyF (France's cyber framework) on 17 March 2026: 20 security objectives, the first 15 applying to all entities and the last 5 to essential entities only;
- voluntary pre-registration with ANSSI has been open since 24 November 2025;
- ANSSI's director general said on 1 October 2026 that the agency envisages requiring full compliance by the end of 2028;
- large customers already subject to NIS2 elsewhere in Europe are sending supplier security questionnaires today.
A serious compliance effort takes 6 to 18 months: starting in 2026 isn't premature.
How much does NIS2 compliance cost?
Orders of magnitude we observe, depending on starting maturity:
Case 1: an already well-equipped SMB
MFA everywhere, EDR, tested backups, written incident plan, yearly awareness training. Cost: €5,000 to €15,000 excl. VAT — formal documentation, supply chain, incident plan aligned with NIS2 deadlines. Lead time: 2 to 4 months.
Case 2: an equipped SMB without governance
Basic antivirus, never-tested backups, no incident plan, no training. Cost: €20,000 to €50,000 excl. VAT — audit, 12-month roadmap, essential tooling (EDR, MFA, device management), training, documentation. Lead time: 6 to 9 months.
Case 3: an SMB starting from scratch
No cyber processes, shared admin accounts, no documentation. Cost: €60,000 to €150,000 excl. VAT over 12 to 18 months — audit, tooling, part-time CISO support, training, access overhaul, crisis exercises.
Beyond compliance, a documented cyber posture makes cyber insurance easier to obtain and answers the security questionnaires of your large customers.
Where to start in practice
1. Confirm scope (1 day)
Size, sector, group membership, activities. Keep a written record. Consider voluntary pre-registration with your national authority.
2. Assess yourself against Article 21 (2 weeks)
Identify critical gaps measure by measure. At MAG&Cie, our free self-assessment (20 minutes online, maturity report within 48 hours, questionnaire in French) gives a first snapshot; the full posture audit (€3,500 to €4,500 excl. VAT) delivers a detailed diagnosis and action plan.
3. Build a prioritized roadmap (2 weeks)
- P0, within 30 days: MFA everywhere, backup restore test, minimal incident plan.
- P1, within 90 days: EDR, awareness training, device management, supplier mapping.
- P2, within 12 months: centralized monitoring, crisis exercises, possibly ISO 27001 certification.
4. Document measure by measure (1 month)
For each of the 10 measures: an owner, documentary evidence, operational evidence. That's your compliance file.
5. Maintain it over time
Quarterly policy review, yearly penetration test and crisis exercise. Compliance is a cycle, not a finish line.
Conclusion
NIS2 targets medium and large organizations in 18 sectors. The obligations — 10 measures (Article 21), 24 h / 72 h / 1 month reporting, management accountability — are known; in France only the application date is still pending the Resilience bill, with ANSSI targeting full compliance by the end of 2028.
👉 Start with our free cybersecurity self-assessment (20 minutes online, 8 domains, maturity report within 48 hours), available from the Cybersecurity posture audit page.
For a full audit led by a consultant — per-domain scoring, prioritized action plan, NIS2 Article 21 reading — see the MAG&Cie cybersecurity posture audit, €3,500 to €4,500 excl. VAT depending on scope.
Sources: Directive (EU) 2022/2555 "NIS2", Recommendation 2003/361/EC on the SME definition, French transposition status as of 10 October 2026 (AOCSI, NIS Solutions).