Blog · Cybersecurity & compliance

NIS2 checklist for mid-sized businesses: am I in scope – and what needs to be done?

With the NIS2 directive, the EU is significantly tightening its cybersecurity requirements – and bringing far more companies into scope than its predecessor. This checklist helps you assess whether you are affected and take the right steps.

Many mid-sized businesses that never considered themselves affected will in future fall under the obligations of the NIS2 directive. Read on to learn how to assess in minutes whether you are in scope – and which 8 steps matter now.

What is NIS2 – in brief

NIS2 is an EU directive on network and information security. It replaces the first NIS directive and raises the required level of security across Europe. The core idea: companies that play an important role for the economy and society must demonstrably bring their IT security up to an appropriate level – and report security incidents.

What matters most for mid-sized businesses is the significantly expanded scope: whereas previously it was mainly large operators of “critical infrastructure” (KRITIS) that were affected, NIS2 now covers a broad range of sectors and applies to companies from medium size upwards.

Am I in scope? The two screening questions

Whether your company falls under NIS2 essentially depends on two factors: sector and company size.

1. Are you in an affected sector?

NIS2 distinguishes between “essential” and “important” entities across a total of 18 sectors. These include energy, transport, banking, health, drinking water and waste water, digital infrastructure, IT services, public administration, postal and courier services, waste management, chemicals, food, manufacturing (including mechanical engineering, electronics and vehicle construction) and providers of digital services.

2. Do you meet the size thresholds?

As a rough guide, companies with around 50 employees or 10 million euros in annual turnover or more are considered potentially in scope. Larger companies (from around 250 employees or 50 million euros in turnover) fall into the stricter “essential entities” category. For certain critical services, the obligations can apply regardless of size.

In short: If you operate in one of these sectors and meet the size thresholds, you should assume you are in scope – and start preparing.

The NIS2 checklist: 8 steps to prepare

Regardless of whether you are formally in scope: the following measures strengthen the security of any company. For businesses subject to NIS2, they are largely mandatory.

  • Clarify whether you are in scope. Check your sector and size – with expert support if in doubt – and document the result.
  • Analyse your risks. Record your most important IT systems and the risks they are exposed to (risk management as the foundation).
  • Implement technical safeguards. Firewall, endpoint protection, email security, multi-factor authentication and regular updates are part of the mandatory baseline.
  • Secure access. Clear rules on who may access which systems (identity & access management) significantly reduce the attack surface.
  • Establish a backup and contingency plan. Regular, tested backups and a recovery plan safeguard business continuity in an emergency.
  • Set up reporting processes. NIS2 requires significant security incidents to be reported within short deadlines. Define who takes this on, and when.
  • Train your staff. People remain the most common way in. Regular awareness training – on phishing, for example – is mandatory and effective.
  • Monitor continuously. Security is a continuous operation: ongoing monitoring detects attacks early and provides evidence of your due diligence.

What are the consequences of non-compliance?

NIS2 provides for substantial sanctions – depending on the category, fines can run into the millions. On top of that, executive management is held more strongly to account and is liable for the implementation of the security measures. Beyond the financial risk, an incident also puts your reputation on the line.

Frequently asked questions about NIS2

When does NIS2 apply?

As an EU directive, NIS2 is already in force and is currently being transposed into national law. Companies should not wait until the last possible date but start preparing early – building robust security processes takes time.

We are a small business – does this still affect us?

Possibly indirectly: even if you are not obligated yourself, customers who are in scope increasingly demand security evidence from their suppliers and service providers. Good IT security thus becomes a competitive advantage.

What is the best way to start?

With a structured stocktake. An assessment or a compact IT health check shows where you stand today and which measures will have the greatest impact in your situation.

Conclusion: acting early pays off

NIS2 is no reason to panic, but it is a clear call to action. If you check whether you are in scope, know your risks and implement the eight steps, you will not only meet the requirements but also make your company more resilient overall. The most important advice: do not wait until the final deadline.

Not sure whether and how NIS2 affects you? In our Cyber Security Assessment Workshops we analyse your starting position and draw up a prioritised action plan. Ongoing protection is then provided by our Cybersecurity Managed Services.

Note: this article is for general information and does not replace individual legal advice. For a binding assessment of your NIS2 obligations, please seek qualified professional advice.

Getting NIS2-ready – together

Let us clarify in a no-obligation conversation where your company stands and which steps make sense for you.

Free IT health check

Where does your IT really stand? Our structured IT health check reveals risks, gaps and opportunities – concise, clear and with no strings attached.

Go to the IT health check →