|10 min read|Yvann Lièvre

NIS2: A Practical Compliance Guide for SMBs in 2026

The 10 measures of Art.21, notification deadlines, penalties, and how to automate your NIS2 compliance without blowing your budget.

NIS2PME

Since October 2024, the NIS2 directive (EU 2022/2555) applies to a much broader scope than NIS1. We're talking about 160,000 entities across Europe, most of them SMBs that never had to deal with cyber regulation before. If you're a CISO or executive at a 50-250 person company in a covered sector, this guide is for you.

Who falls under NIS2?

NIS2 distinguishes two categories. Essential entities (energy, transport, health, water, digital infrastructure, space, public administration) and important entities (postal services, waste management, chemicals, food, manufacturing, digital providers). The size criterion is straightforward: more than 50 employees or more than EUR 10M in revenue. But some DNS operators, TLD registries, and trust service providers are covered regardless of size.

The 10 Measures of Article 21

Art.21 mandates an "all-hazards" approach. Here are the 10 measures your organization must implement:

  • Risk analysis policies and information system security

  • Incident handling, detection, response, notification

  • Business continuity, backups, disaster recovery, crisis management

  • Supply chain security, your vendors and service providers

  • Security in acquisition, development and maintenance of network and information systems, including vulnerability handling

  • Assessment of effectiveness of risk management measures (auditing)

  • Basic cyber hygiene practices and training

  • Cryptography policies and, where appropriate, encryption

  • Human resources security, access control, asset management

  • Multi-factor authentication (MFA) and secured communications

The key point: NIS2 doesn't demand perfection. It demands proportionality between measures and risk. A 60-person SMB won't have the same obligations as a critical infrastructure operator. But it must prove it assessed its risks and took appropriate measures.

The deadline: 24h / 72h notification

Art.23 is the one that makes CISOs sweat. In case of a significant incident:

  • 24 hours: early warning to the national CSIRT

  • 72 hours: full notification with initial severity assessment, impact evaluation, and indicators of compromise

  • 1 month: detailed final report including root cause, measures taken, and any cross-border impact

When you consider that the average breach detection time is 194 days according to IBM's Cost of a Data Breach Report 2025, hitting the 24-hour mark for the early warning is a major challenge. Without continuous monitoring, it's simply impossible.

Penalties: no bluffing

NIS2 aligned its penalty regime with GDPR. For essential entities: up to EUR 10M or 2% of global revenue, whichever is higher. For important entities: up to EUR 7M or 1.4% of revenue. And the directive introduces personal liability for management, a game-changer in boardrooms.

How ThreatClaw automates NIS2 compliance

The problem isn't understanding NIS2. It's operationalizing it with limited resources. Here's how an autonomous agent like ThreatClaw addresses each requirement:

  • Risk analysis: continuous infrastructure scanning, automated asset mapping, vulnerability scoring via EPSS and CVSS

  • Incident handling: real-time detection, event correlation, automatic incident report generation in the required format

  • Continuous auditing: ThreatClaw's 57 skills cover Lynis, Trivy, OWASP ZAP, CIS Benchmarks and more

  • Art.23 notification: the preliminary report is generated in under 15 minutes after detection, including IoCs, affected scope, and severity assessment

  • Traceability: every agent action is logged, timestamped, and exportable, exactly what an auditor requires

Sentinel mode monitors and alerts. Hybrid mode proposes remediations for your approval. Autonomous mode contains threats in real time. The choice depends on your maturity and risk appetite, but all three modes generate compliance documentation.

Where to start?

If you're starting from scratch, here's a realistic 6-month action plan:

  • Month 1-2: asset inventory, initial risk analysis, NIS2 gap analysis

  • Month 3-4: deploy continuous monitoring, set up incident management, train teams

  • Month 5-6: business continuity testing, supply chain audit, Art.23 notification drill

ThreatClaw deploys in under 48 hours and immediately covers detection, incident management, and continuous auditing. It's the most realistic shortcut for an SMB that needs compliance without hiring a full SOC team.

FAQ

Is my 45-person company covered by NIS2?

In principle, no, the threshold is 50 employees or EUR 10M in revenue. But if you're a DNS provider, TLD registry, trust service provider, or a critical supplier to a covered entity, you may be in scope regardless of size. Check your sector classification against Annex I and II of the directive.

What's the difference between NIS2 and GDPR?

GDPR protects personal data. NIS2 protects the security of network and information systems. They overlap during a data breach: you must notify the DPA within 72 hours (GDPR Art.33) AND the CSIRT within 24 hours (NIS2 Art.23). Learn more about GDPR breach notification.

How much does NIS2 compliance cost for an SMB?

According to ENISA, the average cost for an SMB ranges from EUR 30,000 to EUR 150,000 over 2 years, depending on initial maturity. Automation through an agent like ThreatClaw significantly reduces the operational cost (monitoring, auditing, reporting), letting you focus your budget on governance and training.

Does NIS2 apply to companies outside the EU?

Yes, if the company provides services within the EU in a covered sector. It must then designate a representative in a Member State. The mechanism is similar to GDPR.

Related articles