NIS2ComplianceSMEs

NIS2 for SME leaders: who is affected?

Could your SME fall within the scope of NIS2? Where does French transposition stand? A visual guide to help you decide in 10 minutes.

Hakim Djelili8 min read

NIS2 is the European Union's major cybersecurity directive of the decade. Many SME leaders still think it will not apply to them. That is a misreading of the text.

The framework

NIS2 explained on one page

NIS2 (Network and Information Security 2) is EU Directive 2022/2555. It replaces the first NIS Directive of 2016, which was considered too narrow. It has three objectives:

18

Sectors covered

Compared with 7 under NIS1

≈ 100,000

Companies affected in the EU

Including tens of thousands in France

2025

French transposition

Bill PRMD2412608L is being adopted

In France, transposition is being carried out through the bill on the resilience of critical infrastructure and stronger cybersecurity, referenced as PRMD2412608L. The text was presented to the Council of Ministers on 15 October 2024 and adopted at first reading by the Senate on 12 March 2025. ANSSI is preparing the operational implementation of NIS2 and supporting the entities that will fall within its scope.

Am I affected?

The two-gate rule

To determine whether NIS2 could apply to your SME, you need to pass through two successive gates.

1Does my activity fall within one of the 18 NIS2 sectors?

Yes

I move to gate 2 (size).

No

I am outside the scope unless ANSSI designates my company individually.

2Does my company have at least 50 employees OR €10 million in revenue?

Yes

I am potentially within the scope of NIS2 (as an essential or important entity).

No

I am outside the scope, except for sector-specific exceptions (DNS, trust services, etc.).

The two categories of entities

Annex I

Essential entities

  • Energy, transport, banking
  • Healthcare, drinking water
  • Digital infrastructure (cloud, data centres, DNS)
  • MSPs / MSSPs (business-to-business ICT services)
  • Public administration, space

Annex II

Important entities

  • Postal and courier services, waste management
  • Chemicals, food production
  • Manufacturing (medical devices, electronics, automotive)
  • Digital providers (online marketplaces, social networks)
  • Research

The size thresholds to remember

≥ 250

Employees (essential entity)

or €50m revenue and €43m balance sheet total

≥ 50

Employees (important entity)

or €10m revenue and €10m balance sheet total

< 50

Outside the scope

Except for sector-specific exceptions

When

The actual timetable for a French SME

  1. October 2024

    EU transposition deadline

    France fell behind schedule.

  2. 15 October 2024

    Bill presented

    Bill PRMD2412608L was presented to the Council of Ministers.

  3. 12 March 2025

    Adopted at first reading by the Senate

    An important parliamentary step, but not the enactment of final legislation.

  4. 2026

    Operational preparation

    ANSSI is providing resources, including MonEspaceNIS2 and the ReCyF working document.

  5. After adoption

    Implementing texts

    Decrees, frameworks and supervisory arrangements will clarify the French requirements.

  6. Plan ahead

    Inspections and penalties

    The maximum penalties provided for by the Directive and incorporated through transposition will apply under the final framework.

What to do

The 10 minimum requirements, in practical terms

The NIS2 Directive provides for technical and organisational measures. Here is a practical interpretation for SMEs, to be adjusted once the final French texts are available:

  • A risk analysis policy approved by management (updated annually)
  • An incident management procedure with a 24/7 point of contact
  • A business continuity plan: tested backups and a disaster recovery plan
  • A cybersecurity assessment of your critical suppliers (cloud, MSPs)
  • Security in development and patch management
  • Regular technical audits or penetration tests
  • Annual awareness training for all employees
  • Encryption policies for sensitive data
  • MFA, least privilege and an up-to-date asset inventory
  • Secure communications during crisis management

Penalties

What you actually risk

€10m

Directive ceiling: essential entity

Or 2% of annual worldwide revenue, whichever is higher

€7m

Directive ceiling: important entity

Or 1.4% of annual worldwide revenue

€420,000

Ceiling for an SME with €30m revenue

Important entity category

Beyond the fine: senior leaders on the front line

  • Enhanced supervisory measures depending on the entity's category
  • Formal orders to remedy identified shortcomings
  • Possible publication of certain decisions under the final framework
  • Loss of contracts: large companies and the public sector will demand more cybersecurity evidence

Action plan

Where to start if this is new to you

The priority is not to overhaul everything. It is to secure the next three quarters in this order:

  1. Week 1

    Confirm your eligibility in writing

    NAF business code, employee count, revenue. Document the decision.

  2. Week 2

    Monitor ANSSI resources

    MonEspaceNIS2, ReCyF and transposition updates will help you anticipate the framework.

  3. Weeks 3 to 10

    Gap assessment

    Current posture against the 10 minimum measures. Six to eight weeks is enough.

  4. Month 3

    12-month roadmap

    Prioritised by risk, approved by management and traceable.

  5. Month 4

    Train senior management

    Essential for demonstrating active cybersecurity governance.

If you want a precise assessment of your situation, request a free NIS2 diagnostic: 30 minutes to clarify your category, obligations and exposure.

Need a second opinion?

Let's talk for 30 minutes — no commitment

A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.

Book a call