← All articles NIS2 Compliance

NIS2 Made Simple for Small Companies: Where to Start

NIS2 is often perceived as a concern for large critical infrastructure operators. In reality, the directive's scope expanded considerably compared to NIS1, and many mid-sized companies — and even small ones, in certain sectors — now fall within the categories of essential or important entities. If you are wondering where to begin, this article gives you a structure you can work through step by step, without getting stuck in legal interpretation.

Step one: determine whether it applies to you

Before investing in any technology, clarify whether the directive covers your organisation. The assessment rests on three criteria at once:

  • Your sector. NIS2 covers sectors of high criticality (energy, transport, health, drinking and waste water, digital infrastructure, public administration, space, banking, financial market infrastructures) and other critical sectors (postal and courier services, waste management, chemicals, food, manufacturing of medical devices and electronics, digital providers, research).
  • Company size. The general rule targets medium and large organisations. There are notable exceptions: some entities are covered regardless of size — providers of public electronic communications networks, domain name registries, or entities that are the sole provider of an essential service in a member state.
  • Your role in the supply chain. Even if you are not directly in scope, if you supply IT services, software or components to a regulated entity, the requirements will reach you through contracts. Many small companies discover NIS2 precisely this way: through a security questionnaire sent by a large customer.

In Romania, national implementation and the competent authority role sit with the National Cyber Security Directorate. Verifying your classification and registering the entity are obligations that fall on the company, not the authority.

What NIS2 actually requires

The directive does not mandate specific products or brands. Article 21 describes a set of technical, operational and organisational risk-management measures, proportionate to each entity's exposure. In practical terms, you must be able to demonstrate that you have:

  • risk analysis and information system security policies;
  • incident handling capability — detection, response, escalation;
  • business continuity: backup, disaster recovery, crisis management;
  • supply chain security, including the relationship with direct suppliers;
  • security in acquisition, development and maintenance of systems, with vulnerability handling;
  • policies to assess the effectiveness of the measures you adopt;
  • basic cyber hygiene practices and staff training;
  • policies on cryptography;
  • human resources security, access control and asset management;
  • multi-factor authentication, secured voice, video and text communications, and secured emergency communications.

On top of this come incident reporting obligations for significant incidents: an early warning within 24 hours, a full notification within 72 hours, and a final report within one month. One element that gets too little attention is management liability. Management bodies must approve risk-management measures, oversee their implementation and undergo relevant training. Compliance is no longer a purely technical matter delegated to the IT department.

Realistic first steps for a small company

1. Asset inventory

You cannot protect what you do not know you have. Start with a list of servers, workstations, network equipment, cloud applications, privileged accounts and the sensitive data you process. It is the least exciting stage and, at the same time, the one without which nothing else has a foundation.

2. A documented risk assessment

Identify plausible scenarios: ransomware, a compromised mailbox, an unavailable cloud provider, an administrator leaving with access still active. Assess likelihood and impact, then decide what you mitigate, what you transfer and what you accept. Importantly, the document matters as much as the analysis itself — it is the evidence you present during an audit.

3. Fundamentals before advanced controls

In most small companies, a handful of simple measures deliver the best ratio between effort and risk reduction: multi-factor authentication on every account, especially email and VPN; regular patching of operating systems and applications; network segmentation and a properly configured firewall; backups following the 3-2-1 rule, with at least one isolated copy and periodic restore testing; prompt removal of access when an employee leaves.

4. An incident response plan

Write a short document, a few pages long, that answers concrete questions: who decides, which channel we use if email is compromised, who we call, what we log, how and when we notify the authority. A two-page plan that has been rehearsed is worth more than a fifty-page manual nobody has opened.

5. Suppliers

List the suppliers with access to your systems or data and clarify contractually their security responsibilities, incident notification deadlines and service levels. This is the requirement small companies underestimate most often.

6. People

Annual training as a minimum, phishing simulations, and clear rules for passwords, mobile devices and remote work. Most incidents start with a human action, not an exotic vulnerability.

A progressive approach

NIS2 compliance is not achieved in a single month and does not mean replacing your entire infrastructure. Treat it as a 12–18 month programme with clear stages: scope assessment, gap analysis against Article 21 requirements, a prioritised remediation plan, implementation, and then annual review. The proportionality principle in the directive allows you to calibrate measures according to size, exposure and potential societal impact.

For many small companies, the obstacle is not budget but the absence of a clear starting point and of internal resources to sustain documentation, monitoring and reporting. A partner who understands both the directive's requirements and the operational reality of a company with a few dozen employees can turn an apparently overwhelming project into an ordered, manageable task list — and the first step is always an honest assessment of where you stand today.

← All articles