
Most SMBs are not NIS2-ready. What does that mean in practice?
NIS2 is not a checklist for IT alone. Management, suppliers and incident response all need visible ownership.
In brief
- Management accountability is part of the requirement.
- Supplier exposure belongs in your own risk picture.
- Incident reporting only works when roles are agreed in advance.
Start with business continuity
Identify the systems that keep delivery, customer service and payments running. Then map dependencies and decide how long each process can be unavailable.
Start with a real scenario. Your cloud administration is unavailable on Monday morning, the supplier cannot give a recovery time and invoices cannot be sent. Who makes the decision to switch processes, where is the backup and which customers must hear from you first? NIS2 becomes practical when the answers have names and times attached.
Make evidence routine
Policies matter, but records prove what happened. Keep supplier reviews, access changes, exercises and incidents in one controlled trail.
Evidence does not need to begin with expensive software. A controlled register with dates, owners, decisions and links to supporting documents is enough to create discipline. The value is in regular review and follow-up, not in a polished dashboard.
Management cannot outsource accountability
Cybersecurity is no longer only an IT agenda item. Management needs a current picture of the largest risks, the measures chosen and the residual risk the organisation accepts. That requires short, decision-ready reporting rather than technical noise.
A useful quarterly discussion covers critical services, serious open weaknesses, supplier concentration, recent incidents and tested recovery. If management cannot explain the top three operational cyber risks, the reporting is not doing its job.
Prepare before reporting pressure
An incident is the wrong moment to debate who calls whom. Create a one-page decision tree with the internal incident lead, legal contact, key suppliers, insurer and relevant authority. Exercise it with an imperfect scenario, because real incidents are never tidy.
Record the time the organisation first became aware, the facts confirmed at each stage and the reasoning behind decisions. Fast reporting and accurate reporting only coexist when that discipline is prepared in advance.
Sources and further reading
Last reviewed on 8 September 2026. Legislation and official guidance may change.
Not compliant yet?
Start the free AI Compliance Scan and know where you stand in 30 minutes.
Related within this theme