Abstract illustration representing NIS2 cybersecurity compliance for a small business

NIS2 Small Business Guide: 10-Step Compliance Plan Without a CISO

If your company has never had a CISO, a compliance officer, or even a written IT policy, NIS2 can look like it was written for someone else’s business. It wasn’t. Directive (EU) 2022/2555 pulls in any medium-sized company across 18 sectors the moment it crosses roughly 50 employees or €10 million in turnover [1][2] — and in January 2026 the European Commission proposed amendments to simplify the rules — amendments the Commission itself says will still ease compliance for 6,200 micro and small enterprises that remain in scope [6].

This guide skips the 40-page maturity frameworks written for companies with a dedicated security team. It’s ten steps, in the order a business under 100 staff can actually complete them without hiring a CISO first: scope check, leadership sign-off, a lightweight asset list, a risk register you can build in an afternoon, three policies instead of thirty, a backup plan that survives ransomware, a one-page incident process, supplier checks you can finish by email, 30 minutes of staff training, and the reporting clock you need memorised before an incident happens, not during one. We built our own compliance templates against these same ten steps, and the businesses that finish fastest are the ones that skip the enterprise-sized paperwork the other guides start with.

Two readers get different value here. If you own the business, steps 1, 2, 5 and 6 matter most — they decide whether you’re exposed at all. If you’re the person who’ll actually implement this — often an IT contractor, office manager, or ops lead wearing a security hat part-time — steps 3 through 10 are your punch list.

The Penalty Reality Check: What Happens If You Get This Wrong

In plain terms: if you’re in scope and skip this, NIS2 sets two fine tiers — and, unusually for EU regulation, reaches past the company and into the boardroom.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Entity type Maximum fine Personal liability
Essential entity Up to €10 million or 2% of global annual turnover, whichever is higher Management body members can be held accountable for Article 21 infringements [3]
Important entity Up to €7 million or 1.4% of global annual turnover, whichever is higher Same Article 20 exposure applies [3]

Article 20 is the detail most small-business owners miss: the management body — which, at this size, usually means you — has to approve the cybersecurity measures in Article 21 and oversee their implementation. National law can add temporary bans on exercising management functions for serious negligence [3]. You can hand off the work. You cannot hand off the accountability. For the full deadline-by-deadline breakdown, see our NIS2 compliance checklist.

Step 1: Scope Self-Check — Do You Actually Need to Comply?

Start here — getting this wrong wastes money, either on compliance you don’t need or on ignoring an obligation you do have.

The baseline rule: you’re in scope if you operate in one of NIS2’s 18 covered sectors and either employ 50 or more people, or your annual turnover or balance sheet exceeds €10 million [1][2]. You only need to meet one of the two financial/headcount criteria, not both.

But six categories are in scope regardless of size [1]:

  • Providers of public electronic communications networks or services
  • Trust service providers, top-level domain registries, and DNS service providers
  • The sole provider of a service essential to critical societal or economic activity in a Member State
  • Entities whose disruption could significantly affect public safety, security, or health
  • Entities whose disruption could cause significant cross-border systemic risk
  • Entities of specific national or regional sectoral importance, and certain public administration bodies

Run our full NIS2 scope test if you’re unsure. Don’t assume “medium-sized” means rare: Germany’s BSI opened registration to roughly 29,500 companies under its national transposition law alone [7]. If none of the six exceptions apply and you’re under both thresholds, you’re not in scope today — but check again after any hire, acquisition, or new contract that changes your sector exposure.

Effort: Low. This is a decision, not a build — most businesses can answer it in under an hour using the scope test above.

Step 2: Put a Director’s Name on the Plan — Leadership Accountability

Article 20 requires your management body to approve the Article 21 measures, oversee how they’re carried out, and complete regular training sufficient to assess cybersecurity risk and its impact on the business [3]. At a company this size, ‘management body’ is usually one or two people — the owner, the MD, or a small founding team.

In practice: put cybersecurity approval on a recurring quarterly calendar item, keep dated minutes of what was reviewed, and document one training session for the management body itself — not just staff. It doesn’t need to be a formal course; a one-hour session with dated notes is defensible evidence. See our breakdown of Article 20 personal liability for what auditors actually check.

Effort: Low. The work is documentation discipline, not new technical capability.

Step 3: Build a Lightweight Asset Inventory

You can’t assess risk for a system you haven’t listed, and you can’t plan a backup for data you don’t know exists. Article 21(2)(i) requires asset management as part of your risk-management measures [4] — but for a business this size, that doesn’t mean a formal configuration management database.

A single five-column spreadsheet does the job: asset, owner, where it lives (cloud, on-prem, or vendor-hosted), what data it touches, and current backup status. List your accounting system, CRM, website, email, file storage, and any supplier-hosted line-of-business software. Most businesses this size have 10–25 assets worth listing, not hundreds.

Effort: Medium. Expect one to two days spread across a week, mostly spent tracking down who actually owns each system.

Step 4: Create a Risk Register — the “Lite” Version

Article 21(1) explicitly requires measures to be “appropriate and proportionate,” assessed against the entity’s size, its exposure to risk, and the cost of implementation [4]. That proportionality clause is written into the law itself — a ten-line risk register isn’t a corner you’re cutting, it’s the correctly scaled version of what a 300-person company would build as a 40-page document.

For each asset from Step 3, score it on two axes: likelihood (1–3) and impact (1–3), multiply for a risk score, and note one mitigation with an owner and a rough timeframe. Your accounting system with no MFA and customer payment data scores high; your internal wiki with no sensitive data scores low. Read our fuller NIS2 risk assessment guide for the SME-scaled methodology behind this.

Effort: Medium. A half-day once the asset inventory exists.

Step 5: Write Three Policies, Not Thirty

Article 21(2) lists ten measure categories, and most template kits translate that into ten-plus separate policy documents [4]. For a business without a dedicated security function, three documents can legitimately cover the ground, with the remaining categories handled as short procedures nested inside them rather than standalone policies:

  • Information Security Policy — the umbrella document satisfying Article 21(2)(a), stating who’s responsible for what and referencing the other two below
  • Access Control & Authentication Policy — covers Article 21(2)(i) access control and Article 21(2)(j) multi-factor authentication in one document, since for a small business they’re usually the same control (who gets a login, and how it’s protected)
  • Incident Handling Policy — satisfies Article 21(2)(b) and sets up the process you’ll need for Steps 7 and 10

The remaining categories don’t disappear — they become short procedures referenced from these three, sized to what you actually run. A ten-person company on standard cloud software has a far shorter secure-development obligation than one building its own product.

Effort: Medium-High. This is the most time-consuming step — budget two to four days, or a week if you’re drafting from scratch rather than adapting a template.

Step 6: Backup + Disaster Recovery — Your Highest-ROI Control

Article 21(2)(c) names backup management and disaster recovery explicitly, grouped with business continuity and crisis management [4]. The mechanism worth understanding: a ransomware incident with working backups and a tested recovery plan is usually a bad day. The same incident without them is what Article 23(3) calls a “significant incident” — one causing severe operational disruption or financial loss [5] — which triggers your 24-hour reporting clock (Step 10) on top of the business damage.

As a general guideline, most practitioners now recommend the extended 3-2-1-1-0 rule over the older 3-2-1 standard: three copies, two media types, one offsite, one immutable or offline (so ransomware can’t encrypt the backup too), and zero errors confirmed by an actual restore test. The step people skip isn’t the backup — it’s the restore test. A backup you haven’t restored from is a theory, not a control.

Effort: Medium. Mostly configuration plus one dedicated day to run and document a full restore test.

Step 7: Draft a One-Page Incident Response Process

You don’t need a 20-page plan at this size — one page answering four questions before you’re under pressure is enough: what counts as escalation-worthy, who’s told internally first, who owns external reporting once the Article 23 clock starts, and where evidence is preserved.

Use Article 23(3)’s own test for what’s “significant”: an incident that has caused or could cause severe operational disruption or financial loss, or that has affected or could affect other people through considerable material or non-material damage [5]. That threshold is deliberately about impact, not about whether you’re certain of the cause — which matters for Step 10.

Effort: Low-Medium. A half-day, once Step 2’s leadership sign-off and Step 3’s asset list exist to reference.

Step 8: Vet Your Suppliers — the 80/20 Version

Article 21(2)(d) requires you to account for the vulnerabilities specific to each direct supplier [4]. The 66-document toolkits built for larger companies include four-tier supplier classification matrices with formal risk-weighting formulas. At this size, you don’t need that yet.

Instead, list your five to ten most critical vendors — the ones with access to your systems, your data, or your customers’ data — and split them into “critical” and “not critical.” For each critical vendor, ask three questions by email: do you have a documented incident response process, when was your last confirmed security incident, and will you notify us within 24 hours of a breach affecting our data. Keep the replies on file; that’s your audit evidence. Once you outgrow this approach, our guide on how to classify NIS2 suppliers covers the fuller four-tier method.

Effort: Low-Medium. A day or two of back-and-forth email, mostly waiting on vendor replies.

Step 9: Run 30-Minute Staff Awareness Training

Article 21(2)(g) requires basic cyber hygiene practices and cybersecurity training [4]. You don’t need an e-learning platform or a subscription service. A 30-minute in-person or video-call session covering phishing recognition, password and MFA habits, and — critically — who to tell if someone suspects an incident (tying back to Step 7) satisfies this for a business your size.

The audit evidence isn’t the training content, it’s the record: a dated agenda and a signed attendance sheet, repeated at least annually. See our NIS2 training requirements guide for what auditors expect to see documented.

Effort: Low. Half a day to prepare and deliver, once.

Step 10: Know the Reporting Clock Before You Need It

This is the step most small businesses get wrong not because they don’t know the rule, but because they wait to be sure before reporting. The obligation starts at “becoming aware” of a significant incident, not at the moment you’ve confirmed root cause [5].

Stage Deadline What’s required
Early warning Within 24 hours of awareness Flags whether the incident is suspected malicious/unlawful and whether it could have cross-border impact [5]
Incident notification Within 72 hours of awareness Updates the early warning with an initial severity and impact assessment, plus indicators of compromise if available [5]
Final report Within 1 month of the notification Full description, root cause, severity, impact, and mitigation taken [5]

If the incident is still ongoing at the one-month mark, submit a progress report instead, followed by a final report once resolved [5]. Know in advance where your national competent authority wants these filed — Germany’s BSI, for example, runs registration and reporting through its two-step BSI-Portal process [7]. Confirm your own country’s channel using our incident reporting guide now, not during an incident.

Effort: Low. Once Step 7’s process exists, this step is knowing where to submit, not building anything new.

Who Does What When You Don’t Have a CISO

The single biggest reason small businesses stall on NIS2 isn’t the technical work — it’s that nobody knows who owns which step. Here’s a role split that works for a company with no dedicated security hire:

Step Primary owner
1. Scope self-check Owner / MD
2. Leadership accountability Owner / MD (cannot be delegated)
3. Asset inventory IT contractor / MSP
4. Risk register Owner / MD, with IT contractor input
5. Three policies Office manager or ops lead, reviewed by owner
6. Backup + DRP IT contractor / MSP
7. Incident response process Owner / MD, drafted with IT contractor
8. Supplier checks Bookkeeper / finance (already owns vendor relationships)
9. Staff training Office manager or ops lead
10. Reporting clock Owner / MD

Note how few rows fall to the IT contractor alone — NIS2 assumes the management body drives most of this (Article 20 [3]), which is why this size doesn’t need a CISO, just an owner who stops treating security as someone else’s job.

Effort & Cost at a Glance

Step Effort Typical time
1. Scope self-check Low Under 1 hour
2. Leadership accountability Low Ongoing, ~1 hour/quarter
3. Asset inventory Medium 1–2 days
4. Risk register Medium Half a day
5. Three policies Medium-High 2–4 days
6. Backup + DRP Medium 1 day, plus ongoing testing
7. Incident response process Low-Medium Half a day
8. Supplier checks Low-Medium 1–2 days (mostly waiting on replies)
9. Staff training Low Half a day
10. Reporting clock Low 1–2 hours to document

Add it up and a business this size is looking at roughly two to three working weeks of effort spread across a few people over a month or two — not the multi-month program larger organisations need. This estimate is our own synthesis, not a figure from the directive, so treat it as a planning guide, not a guarantee.

Frequently Asked Questions

We have 45 employees — are we definitely exempt?
Not necessarily. The size test is employees or turnover/balance sheet — a 45-person company with over €10 million in turnover is still in scope [1][2]. And the six size-independent exceptions (DNS/trust services, sole essential-service provider, public safety impact, systemic risk, sectoral importance) apply regardless of headcount. Run the full scope test before assuming you’re out.

Do we need to hire a CISO?
No. Article 20 requires a management body that approves and oversees the measures and completes training — it doesn’t require a specific job title [3]. At this size, that’s usually the owner or MD, supported by whoever handles IT day to day.

Our country’s transposition deadline already passed — are we too late?
Transposition timing varies by country — most member states have national NIS2 legislation in force, and others are still finalising theirs. If you’re newly discovering you’re in scope, register and start now — a documented, in-progress program is a materially different position with a supervisory authority than none at all.

Can one person really do all 10 steps?
At a company under 100 staff, yes — the role table above splits the work across an owner, an IT contractor, and one or two other staff wearing part-time hats, not a dedicated team.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Key Takeaways

Your compliance program is supposed to scale with your size — that’s Article 21(1)’s proportionality principle working as intended [4], not a workaround. A ten-line risk register and three policies aren’t a lesser version of compliance at this size; they’re the correctly scaled version. Start with Step 1 this week, put Step 2’s accountability in writing before building anything else, and treat Step 6’s restore test as non-negotiable — it’s the control most likely to decide whether an incident stays a bad day or becomes a reportable one. The Commission’s January 2026 proposal to simplify NIS2 further is still moving through the legislative process, so re-check your scope if you’re near the thresholds [6].

Sources

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: