Compliance guidance
NIS2 for Small Business
Quick answer
NIS2 creates cybersecurity and incident-reporting obligations for covered entities and sectors, with details shaped by national implementation and supply-chain context.
Who this is for: Organisations in covered sectors and suppliers whose customers require assurance.
What to do
- 01Check the sectors and entity-size tests in the relevant national implementation.
- 02Map important services, suppliers, access, and incident contacts.
- 03Build baseline controls for risk management, continuity, access, and reporting.
- 04Review the official text and qualified local guidance.
What this does not cover
This page does not determine scope, national deadlines, or reporting duties for a specific organisation.
This page is educational information, not legal advice or a professional security audit. Check the official requirements and get qualified help when your circumstances require it.
See how this applies to your businessContinue exploring