NIS2 Implementation Guide for SMBs: 90-Day Roadmap to Full Compliance
The first SMB fines have landed in Germany and France. NIS2 enforcement is no longer a future concern — it is happening now. Here is an actionable 90-day roadmap covering every requirement, with real timelines and what it will actually cost you.
Marcus Weber
Senior Compliance Engineer · WebGuard Agency
1. NIS2 Enforcement Is Real — The First SMB Fines
For two years, NIS2 compliance felt like something businesses could safely defer. Transposition deadlines slipped in some member states, national authorities were still building their enforcement teams, and the general consensus among SMBs was: regulators will go after the big players first. That assumption died in Q1 2026.
A mid-size logistics company based in Bavaria — 87 employees, €22M in annual revenue — received a €285,000 penalty from the BSI (Germany's Federal Office for Information Security) for failing to maintain documented risk management procedures as required under Article 21. The company had no formal asset inventory, no written incident response plan, and no evidence of a cybersecurity risk assessment. When auditors asked for documentation, there was none to produce.
Three weeks later, a French IT services firm — 48 employees, €9M in revenue — was fined €140,000 by ANSSI for failing to report a security incident involving a compromised customer database within the mandatory 24-hour early warning window. The breach had occurred on a Tuesday; management notified the authority the following Monday, believing the issue was contained and internal. Under NIS2, the clock starts at detection, not at resolution.
These are not edge cases. They are the opening signal of a systematic enforcement wave. Both affected organisations believed they were either out of scope or had time to prepare. Neither assumption was correct.
2. Who NIS2 Actually Applies To: Essential vs Important Entities
The original NIS Directive (2016) covered a narrow set of operators of essential services. NIS2 dramatically expands that scope — and the expansion is where most SMBs are caught off guard.
NIS2 creates two tiers: essential entities and important entities. Essential entities face the highest scrutiny — proactive supervision, random audits, and fines up to €10M or 2% of global turnover. Important entities are subject to reactive supervision (triggered by incidents or complaints) and fines up to €7M or 1.4% of global turnover. Both tiers carry real risk; the difference is in audit frequency and maximum penalty levels.
Essential entity sectors include: energy (electricity, oil, gas, hydrogen), transport (air, rail, water, road), banking and financial market infrastructure, healthcare (hospitals, reference laboratories, pharmaceutical manufacturers), water and wastewater, digital infrastructure (cloud providers, data centres, CDN operators, DNS providers), ICT service management (managed service providers, managed security service providers), public administration, and space.
Important entity sectors include: postal and courier services, waste management, manufacture and distribution of chemicals, food production and distribution, manufacturing (medical devices, computers, electronics, machinery, motor vehicles), digital providers (online marketplaces, search engines, social media platforms), and research organisations.
The size threshold for NIS2 is organisations with 50 or more employees OR €10M or more in annual revenue in a covered sector. But size is not the only trigger. If your company acts as a supplier to an essential entity — providing software, IT services, logistics, or any component in their operational chain — you may be pulled into scope through contractual supply chain obligations even if you fall below the headcount and revenue thresholds. This downstream effect is one of the most misunderstood aspects of NIS2 and the primary reason SMBs outside the obvious sectors are getting caught.
3. The 5 Core Requirements You Must Meet
Article 21 of NIS2 defines the mandatory cybersecurity risk management measures. Translated from regulatory language into operational requirements, there are five areas every in-scope organisation must address.
-
01
Risk management policies and governance
You must have a documented cybersecurity risk assessment covering all systems, data, and processes that support your service delivery. This is not a one-time exercise — NIS2 requires ongoing risk management with regular reviews. Management bodies are personally accountable: directors and C-suite executives must approve the cybersecurity policies and can face personal liability if they demonstrably failed to oversee implementation. The documentation must be audit-ready at all times.
-
02
Incident reporting: 24-hour early warning, 72-hour notification
Any significant incident — defined as one that causes or is capable of causing severe operational disruption or financial loss, or that affects other organisations — must be reported in a strict sequence. Within 24 hours of becoming aware of the incident: an early warning to your national authority. Within 72 hours: a formal incident notification with impact assessment and initial analysis. Within one month: a final report with a full description, root cause analysis, and remediation steps. Your incident logging and escalation procedures must be in place before an incident occurs — you cannot build them under pressure.
-
03
Supply chain security
You are responsible for the cybersecurity practices of your direct suppliers. NIS2 requires you to assess and document the security posture of every third party with access to your systems or data. In practice, this means vendor risk questionnaires, contractual cybersecurity clauses, and an ongoing supplier monitoring process. If a supplier suffers a breach that propagates to you, "we did not know their security was inadequate" is not a defence — the obligation is to have conducted due diligence.
-
04
Access control and authentication
Multi-factor authentication must be implemented on all systems relevant to your essential or important service delivery — this is not optional. Privileged access must be managed and documented: who has administrative rights, why, and for how long. Zero-trust architecture principles apply: minimum necessary access, regular access reviews, immediate revocation on employee departure. Network security, encryption of data in transit and at rest, and vulnerability management (patching cadence) also fall under this pillar.
-
05
Business continuity and crisis management
You must have tested business continuity plans covering backup management, disaster recovery, and crisis response procedures. "Tested" is the operative word — a plan that exists only on paper and has never been exercised does not satisfy NIS2. Backups must be restorable; recovery time objectives must be documented and validated. The crisis management element extends to communication plans: who speaks to regulators, customers, and the media during an active incident — and in what sequence.
4. The 90-Day Implementation Roadmap
Ninety days is achievable for an SMB starting from scratch — provided the work is structured correctly and someone owns it. Here is the sequence that WebGuard Agency uses with clients across the manufacturing, logistics, and IT services sectors.
Days 1–30: Gap Assessment and Scoping
The first month is entirely analytical. The goal is not to fix anything yet — it is to understand precisely where you stand and what needs to change.
Start by confirming your NIS2 scope: which entity classification applies, which national authority has jurisdiction, and whether any sector-specific implementing acts impose additional requirements (healthcare and energy both have sector overlays in several member states). Appoint a compliance lead — ideally someone at CISO or Head of IT level with direct access to the board — and secure executive sponsorship with documented commitment.
Conduct a complete asset inventory covering all hardware, software, cloud services, and third-party integrations. Map every system that touches your essential or important service. Against each asset, assess the current control state against the five NIS2 pillars. The output is a gap register: a prioritised list of what is missing, how critical each gap is, and what remediation will require.
Also compile your supplier register during this phase. List every third party with system or data access — SaaS vendors, cloud providers, IT outsourcing partners, physical access controllers — and rate each by risk level. High-risk suppliers need immediate attention in Phase 2.
Days 31–60: Policy, Technical Controls, and Supplier Governance
This is the highest-effort phase. You are building the documentary and technical infrastructure that will underpin your NIS2 posture.
On the policy side: draft your cybersecurity risk management policy (the master document), an incident response plan (including the 24/72-hour notification procedure with named roles and contact numbers), an access control policy, a patch management policy, and a business continuity plan with documented recovery objectives. These documents must be approved by the management body — a board-level signature is not a formality, it is a legal requirement under NIS2.
On the technical side: deploy MFA across all external-facing systems and privileged accounts. If you do not have an EDR (endpoint detection and response) solution, implement one. Configure centralised logging — you cannot report an incident within 24 hours if your logs are scattered across systems with no correlation capability. Remediate the critical and high-severity gaps identified in Phase 1 in priority order.
On the supplier side: issue NIS2 security questionnaires to all high-risk vendors and incorporate cybersecurity obligations into their contracts. Key clauses to add: breach notification obligations (they must notify you within 24 hours), right to audit, minimum security control requirements, and data handling obligations. This will generate friction with some suppliers — start those conversations early.
Days 61–90: Training, Testing, and Registration
The final phase validates everything built in Phase 2 and prepares the organisation to operate under NIS2 on an ongoing basis.
Run your first tabletop incident response exercise. Take a realistic scenario — ransomware hitting your primary file server at 2pm on a Friday — and walk every stakeholder through the response. Who detects it? Who makes the call to invoke the incident response plan? Who drafts the 24-hour early warning? Who handles customer communication? Who calls external support? Gaps in the process will surface immediately; address them before you face a real incident.
Deliver employee cybersecurity awareness training covering phishing recognition, social engineering, safe handling of sensitive data, and what to do (and not do) during a suspected incident. NIS2 explicitly requires cybersecurity training for all staff — document attendance and content for your compliance record.
Verify your backups: perform a full restoration test and document the result. Register with your national authority if your jurisdiction requires it (Germany and France have mandatory registration for essential and important entities). Compile your compliance evidence pack — all policies, risk assessments, training records, and test results — into a format that could be handed to an auditor on day one of an inspection.
Not sure where your organisation stands on NIS2?
WebGuard Agency delivers a structured NIS2 gap assessment in 5 business days — covering all five Article 21 pillars, supplier obligations, and incident reporting readiness. You receive a gap register and a prioritised remediation plan, not a generic checklist.
Get your free NIS2 gap assessment — response within 24 hours →5. Real Cost Breakdown: €15k–€60k for Most SMBs
One of the first questions every SMB board asks is: what does this actually cost? The honest answer is: it depends on your starting point, your sector, and how much of the work you handle internally versus outsourcing. The range for a typical in-scope SMB (50–250 employees) is €15,000 to €60,000 for initial compliance, plus ongoing operational costs.
Here is a realistic breakdown across the main cost categories:
| Cost category | Low estimate | High estimate |
|---|---|---|
| External gap assessment / consultant | €5,000 | €20,000 |
| Technical controls (MFA, EDR, SIEM, logging) | €3,000/yr | €15,000/yr |
| Policy and legal documentation drafting | €2,000 | €8,000 |
| Employee training programme | €1,000 | €5,000 |
| Internal team time (100–200 hrs at fully loaded cost) | €6,000 | €15,000 |
| Total (year one) | €17,000 | €63,000 |
The wide range reflects the gap between an organisation that has already implemented ISO 27001 or GDPR controls (where NIS2 is largely additive) versus one starting from a minimal cybersecurity baseline. The single largest variable is internal team time — if you have a dedicated security or IT manager who can lead the effort, you compress the consultant cost significantly. If you have no internal capability, expect the external advisory figure to dominate.
Put these numbers next to the penalty exposure. A €285,000 fine — the figure issued to the Bavarian logistics company in Q1 2026 — plus remediation costs imposed under a corrective order plus reputational damage with enterprise customers typically exceeds €500,000 in total impact. The implementation cost is not a compliance burden; it is a risk management investment with a clear return.
6. Three Mistakes SMBs Make with NIS2
Mistake 1: Treating NIS2 like a checkbox exercise
The most common and most expensive mistake is approaching NIS2 as a documentation project — produce enough policy documents to satisfy an auditor, then continue operating exactly as before. National authorities are specifically trained to distinguish between paper compliance and operational compliance. During an inspection, they will ask to see your incident logs, your patching records, your access review history, your backup restoration test results, and your training attendance records. If your policies say you review access rights quarterly but your Active Directory shows accounts that have not been reviewed in two years, the policy is evidence of negligence, not compliance.
NIS2 requires a functioning security programme, not a filing cabinet. The distinction matters enormously when a regulator is deciding whether to issue a corrective order or a fine.
Mistake 2: Ignoring the supply chain obligation
Most SMBs focus NIS2 preparation entirely inward — their own systems, their own policies, their own team. The supply chain obligation consistently catches organisations unprepared because it requires you to exert governance over third parties who may have their own priorities and timelines.
The practical consequence: if you have a SaaS vendor with access to your customer data who suffers a breach, and you cannot demonstrate that you assessed their security practices and had contractual obligations requiring them to notify you promptly, you bear regulatory exposure alongside them. Start the supplier conversation early — many vendors will have NIS2 questionnaire responses available, but some smaller suppliers will need time to prepare documentation. Discovering this three weeks before a compliance deadline is a problem you can avoid.
Mistake 3: No incident rehearsal
The 24-hour early warning deadline is unforgiving. In a real incident, there is no time to design your notification process — you need a pre-built procedure, named individuals, and a tested communication chain. SMBs routinely write incident response plans but never exercise them. The result: when an actual incident occurs, the plan is retrieved from a folder no one remembers, critical contact details are out of date, the person named as incident lead has left the company, and the 24-hour clock expires before anyone has agreed on what to report. Run a tabletop exercise at minimum once a year — twice if you are an essential entity. Thirty minutes of rehearsal prevents a €140,000 mistake.
Start your 90-day NIS2 compliance journey today
WebGuard Agency guides SMBs through NIS2 implementation end to end — from scoping and gap assessment through policy drafting, technical controls, and incident response rehearsal. Fixed-fee engagements with a dedicated compliance engineer.
Get your free NIS2 gap assessment →FAQ
What is the deadline for NIS2 compliance?
What are the fines for NIS2 non-compliance?
Does NIS2 apply to my SMB?
Written by Marcus Weber
29 July 2026 · 16 min read