Abstract network of glowing nodes representing a medium-sized organisation's cybersecurity infrastructure under NIS2

NIS2 for Medium Enterprises: Why “Appropriate and Proportionate” Means Something Different at 50–249 Employees

A 60-person logistics company and a 3,000-person telecom operator answer to the same ten measures under Article 21(2) of NIS2 — but not the same version of them. Article 21(1) requires “appropriate and proportionate technical, operational and organisational measures,” calibrated to your size, risk exposure, and the cost of implementation. For an organisation with 50 to 249 employees, that calibration is exactly where most guidance falls apart: SME explainers stop at whether you’re in scope; enterprise compliance guides assume a security team you probably don’t have. This article works through what “proportionate” concretely means for your size, measure by measure, plus the governance decision — internal CISO or outsourced — and the realistic cost most medium enterprises should budget.

Are You a Medium Enterprise Under NIS2?

You sit in NIS2’s medium-enterprise band if you employ 50–249 people and operate in one of the directive’s covered sectors. Article 2(1) sets the entry threshold by pointing to Commission Recommendation 2003/361/EC: your organisation must “qualify as medium-sized” — fewer than 250 staff, and either annual turnover not exceeding €50 million or a balance sheet total not exceeding €43 million — or exceed those ceilings, before size becomes relevant at all. Below that (small or micro), you’re generally out of scope unless you fall into one of nine size-independent categories under Article 2(2) — public electronic communications providers, trust service providers, TLD registries and DNS providers, and a handful of others.

Criterion Threshold What it means for you
Headcount 50–249 employees Below 50 and under €10M turnover/balance sheet: generally exempt (unless size-independent category)
Turnover ≤€50 million Either this OR the balance-sheet test needs to hold — it’s an “or,” not an “and”
Balance sheet total ≤€43 million Group consolidation applies — subsidiaries may inherit a parent company’s figures
Sector Listed in Annex I or Annex II Size only matters once you’re already in a covered sector

Classification follows from there. Under Article 3, a medium-sized organisation in an Annex I or Annex II sector is almost always an important entity — essential status is reserved for large organisations (250+ staff or exceeding the financial ceilings) in Annex I, plus a short list of medium-sized providers that count as essential regardless of size: public electronic communications networks/services, qualified trust service providers, TLD registries, and DNS providers. Run the full test against your own numbers on our scope test, and see the complete essential-vs-important breakdown, including the exceptions, on our classification guide.

The Squeezed Middle: Why 50–249 Employees Is a Different Compliance Problem

A 10-person startup is usually out of scope entirely. A 3,000-person essential entity has a security budget line, possibly a SOC, and a compliance officer whose whole job is this directive. A 50–249-employee organisation sits in between, and it’s the least comfortable place to be: you’re big enough to run several genuinely separate systems — an ERP, a customer-facing platform, cloud infrastructure, a handful of SaaS tools with real customer data — but you rarely have a dedicated security function. In our experience reviewing compliance programmes at this size, the same two or three people who run IT are also expected to own risk assessment, incident handling, supply chain review, and everything else in Article 21(2), on top of their day jobs.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

That gap is the actual reason “proportionate” matters here more than at any other size. A small company can sometimes argue a measure doesn’t apply to it. A large enterprise has the headcount to just build everything. A medium enterprise has to build all ten measures — the directive doesn’t let you skip a category — while genuinely scaling the depth of each one to match a team that doesn’t have a full-time person on any of it.

What “Appropriate and Proportionate” Actually Means Under Article 21(1)

Proportionality is not an exemption clause. Article 21(1) requires measures that are “appropriate and proportionate technical, operational and organisational,” having regard to “the state of the art and, where applicable, relevant European and international standards, as well as the cost of implementation,” weighed against your risk exposure, size, and the likelihood and severity of incidents. In practice, that means every measure in Article 21(2) still applies to you — what changes is depth, tooling, and formality, and you need to be able to show an auditor why you chose that depth, not just assert that you’re “just a medium-sized company.” Undocumented proportionality reasoning doesn’t survive a reactive audit; documented risk-based reasoning does.

Article 21, Measure by Measure: What’s Proportionate at Your Size

The table below translates each of the ten Article 21(2) measures into what a large essential entity typically builds versus what’s realistically proportionate for a 50–249-employee team. Treat the “proportionate” column as a floor, not a ceiling — scale up if your specific risk profile calls for it.

Measure (Art. 21(2)) What’s proportionate at 50–249 employees Effort
(a) Risk analysis & information security policy One documented methodology and risk register, reviewed at least annually, owned by whoever holds IT/security responsibility even part-time Medium
(b) Incident handling A written incident handling policy with a named escalation path to whoever owns the Article 23 reporting clock — in-house or on retainer Medium
(c) Business continuity, backup, disaster recovery, crisis management A business impact analysis scoped to the systems that would actually stop revenue or safety-critical operations, with tested backups — skip modelling units you don’t have Medium–High (mostly one-time)
(d) Supply chain security Classify direct suppliers into a small number of criticality tiers; add security clauses to contracts for the top tier only Medium
(e) Acquisition, development & maintenance security A patch-management cadence plus a vulnerability-disclosure clause with vendors — most organisations this size buy more software than they build Low–Medium
(f) Effectiveness-assessment policies An annual documented self-assessment against your own Article 21 measures — this is where your proportionality reasoning gets written down Low
(g) Cyber hygiene & training Mandatory onboarding plus annual refresher training for all staff, alongside the Article 20 management training that applies at every size Low
(h) Cryptography and encryption Encryption at rest and in transit for anything holding personal or business-critical data, documented in a short policy — “where appropriate” means risk-justified, not optional Low–Medium
(i) HR security, access control & asset management A maintained asset register (a spreadsheet is fine to start) plus access reviews at hire, role change, and exit Low–Medium
(j) Multi-factor authentication & secured communications MFA on every account with access to sensitive systems — at this size there’s usually no large segmented network to fall back on, so “where appropriate” typically means everywhere Low

See the full text and context of every measure on our Article 21 breakdown.

Internal CISO or Outsourced vCISO? The Governance Decision

Article 20 requires your management body to approve and oversee the Article 21 measures — and to complete training sufficient to identify risks and assess your cybersecurity risk-management practices. That obligation is fixed regardless of size. What isn’t fixed is who runs the programme day to day, because NIS2 doesn’t mandate a CISO title or an in-house team at all — it requires documented ownership of the ten measures, which can sit with an outsourced virtual CISO, an internal IT lead with delegated authority, or a hybrid of both.

Model Year-1 cost Ongoing annual Best fit
Internal full-time CISO ~€200,000 (salary + payroll tax + recruiting fee + onboarding) ~€160,000/year average Multiple frameworks running in parallel (NIS2 + ISO 27001 + GDPR), or headcount well past 249
Outsourced vCISO ~€60,000–€66,000 (4–5 days/month) ~€43,000–€66,000/year (€3,600–€5,500/month retainer) Most 50–249-employee organisations meeting NIS2 for the first time

These figures come from vCISO market pricing data and should be treated as an industry-reported range, not a quote for your organisation — actual costs vary by country, sector, and how much of the programme is already built. As a general guideline, an in-house hire tends to pencil out only once you’re managing multiple compliance frameworks at scale; a 50–249-employee organisation tackling NIS2 alone is usually better served scaling a vCISO engagement up during the build phase and down afterward. See our full breakdown of what the role actually needs to cover on the CISO responsibilities page, and how Article 20 exposes your board directly on the board liability page.

What NIS2 Compliance Actually Costs a Medium Enterprise

Independent budget benchmarking for 50–250-employee organisations puts the gap analysis and risk assessment phase at $5,000–$15,000, policy and documentation development at $12,000–$44,000, annual security tooling at $5,000–$50,000 or more depending on how much you already have, and external advisory support at $10,000–$30,000. Combined, that’s a typical first-year investment of $36,000–$120,000 for an organisation with some security measures already in place, with $26,000–$115,000 in ongoing annual maintenance after that — according to compliance budget research from Bastion.tech. Treat these as an order-of-magnitude guide rather than a fixed quote; the single largest lever inside that range is the documentation-development line, which a ready-made, auditor-mapped template set reduces directly instead of paying a consultant to draft from a blank page.

What You Can Scale Down — and What You Can’t

Proportionality applies unevenly across the directive, and conflating the two categories is the most common mistake we see at this size.

Obligation Scales with size? Notes
Article 21(2) technical measures (a)–(j) Yes Depth is proportionate to risk, size and cost — document the reasoning if you do less than a large entity would
Article 20 management training No Applies to every essential and important entity’s management body regardless of headcount
Article 23 incident-reporting deadlines (24h / 72h / 1 month) No The same clock runs for a 60-person company and a 6,000-person one
National competent authority registration No A fixed administrative obligation, not a risk-scaled one
Article 34 penalty tier No Determined by essential/important classification, not by how proportionate your programme is

Penalties If You Get This Wrong

As a 50–249-employee important entity, you fall under Article 34(5): fines up to €7 million or 1.4% of total worldwide annual turnover, whichever is higher, for breaches of the Article 21 and 23 obligations. If your organisation happens to be one of the size-independent essential categories — a medium-sized public electronic communications provider, for instance — the ceiling jumps to Article 34(4)’s €10 million or 2% of turnover. Enforcement is tiered, not automatic: national competent authorities work through warnings, binding instructions and compliance orders before reaching for a fine, and Ireland’s NCSC, like most national authorities, explicitly runs reactive, ex-post supervision for important entities — audits triggered by evidence of non-compliance rather than routine inspection. That’s a lower-intensity regime than essential entities face, but it is not a reason to under-document; reactive supervision still means an incident or complaint can trigger a full review with no warning. See the complete penalty structure, appeal mechanisms and enforcement tools on our penalties guide.

A Realistic Starting Sequence

If you’re starting from close to zero, the order matters more than the speed. First, run the scope test above to confirm essential-vs-important classification — it changes your penalty exposure and supervision model. Second, decide your governance model, because someone needs to own everything that follows. Third, build the Article 21(2)(a) risk methodology and register, since every other measure references it. Fourth, put an incident-handling owner in place for Article 23, because that deadline clock doesn’t wait for the rest of your programme to be ready. From there, work through the remaining measures in the order your own effectiveness self-assessment (measure (f)) flags as weakest, not in the order they’re numbered. For a full week-by-week build sequence with effort estimates, see our 90-day SME roadmap, and use our maturity assessment to establish your starting baseline before you commit to a timeline.

Frequently Asked Questions

Does a 50–249-employee company need a full-time CISO under NIS2?
No. Article 20 requires management-body approval, oversight, and training — not a specific job title or headcount. Documented ownership of the Article 21 measures, whether internal or outsourced, satisfies the requirement.

Can we do less than the ten Article 21 measures because we’re mid-sized?
No — proportionality lets you calibrate the depth of each measure, not skip a category. All ten apply; what changes is tooling, formality, and documented reasoning.

Are we essential or important at 50–249 employees?
Almost always important, unless you’re a medium-sized public electronic communications network/service provider, a qualified trust service provider, a TLD registry, or a DNS provider — those categories are essential regardless of size.

How much should we budget in year one?
Independent benchmarking points to roughly $36,000–$120,000 for an organisation with some security measures already in place, though a ready-made template set reduces the documentation-development portion of that range significantly.

Do the 24-hour incident reporting deadlines apply to us the same as to a large company?
Yes. Article 23’s 24-hour, 72-hour and one-month deadlines are fixed regardless of size — they are one of the obligations proportionality does not touch.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. NIS 2 Directive (EU) 2022/2555, Article 2 — Scope. nis-2-directive.com.
  2. NIS 2 Directive (EU) 2022/2555, Article 3 — Essential and important entities. nis-2-directive.com.
  3. NIS 2 Directive (EU) 2022/2555, Article 20 — Governance. nis-2-directive.com.
  4. NIS 2 Directive (EU) 2022/2555, Article 21 — Cybersecurity risk-management measures. nis-2-directive.com.
  5. NIS 2 Directive (EU) 2022/2555, Article 23 — Reporting obligations. nis-2-directive.com.
  6. NIS 2 Directive (EU) 2022/2555, Article 34 — Administrative fines. nis-2-directive.com.
  7. European Commission. Commission Recommendation 2003/361/EC concerning the definition of micro, small and medium-sized enterprises. EUR-Lex.
  8. National Cyber Security Centre, Ireland. NIS2 FAQ.
  9. Bastion.tech. NIS 2 Compliance Costs.
  10. Cybervize. Virtual CISO vs. Full-Time CISO Cost Comparison.
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: