The application of the NIS2 Directive to SMEs is not universal and depends on several factors, including the sector, company size, and risk profile.
General rule: The directive primarily applies to medium and large enterprises in the sectors listed in Annexes I and II. This implies that small businesses generally do not fall within the scope of application, except for the specific exceptions listed below.
- Size threshold: The directive applies to entities considered “medium-sized enterprises” as defined in Recommendation 2003/361/EC or larger.
- Sectoral inclusion: SMEs operating in certain sectors are always covered by the NIS2 Directive, regardless of their size. These sectors include:
- Providers of public electronic communications networks or publicly available electronic communications services;
- Trust service providers;
- Entities providing domain name registration services.
- Critical infrastructure: SMEs identified as “critical entities” under the CER (Critical Entities Resilience) Directive are also covered by NIS2, regardless of their size. This underscores the interconnection between physical and cyber resilience for critical infrastructure.
- High-risk SMEs: Member States have the authority to identify smaller entities with a high-risk profile that must be subject to the directive’s obligations. This provision recognizes that size is not the only determining factor for cybersecurity risk.
Important note: Although SMEs may not fall directly within the scope of NIS2, the directive encourages them to adopt robust cybersecurity practices. For example, larger companies subject to NIS2 must address cybersecurity risks within their supply chains, indirectly influencing the cybersecurity posture of their SME suppliers. If your company is in a gray area or wants to precisely verify its perimeter, it may be useful to start a structured NIS2 compliance path with the support of experts.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
