Back
NIS2 without panic: what changes for a small company

Security

NIS2 without panic: what changes for a small company

The NIS2 directive, transposed in Italy by legislative decree 138/2024, greatly widens the set of companies with cybersecurity obligations and puts management bodies on the hook. Companies outside the scope are drawn in as suppliers. The requirements are organisational before they are technological: no product makes you compliant.

13 Jun 2026 · 10 min read · updated on 27 Aug 2026

NIS2 is usually discussed in two unhelpful ways: as a requirement affecting only large enterprises, or as an emergency to be solved by buying something. It is neither.

It is a European directive on the security of network and information systems, transposed in Italy by legislative decree 138 of 4 September 2024, which makes the National Cybersecurity Agency the competent authority. Compared with the previous regime it widens the scope considerably, and above all it moves accountability onto the people running the company.

What follows is practical orientation, not legal advice: deadlines and scope must be checked against the text in force and the Agency's communications, which periodically update lists and requirements.

Who is in scope (and why you may be without knowing)

Scope is built by crossing two criteria: the sector you operate in and the size of the company. The listed sectors go well beyond classic critical infrastructure: energy, transport, banking, health and water, but also waste management, food production and distribution, manufacturing of devices and equipment, digital services, post and couriers, research.

On size, the medium-enterprise threshold applies: broadly, organisations with at least fifty staff or turnover or balance sheet above ten million. Companies identified this way fall into two categories, essential and important entities: obligations are largely the same, what changes is the intensity of supervision and the ceiling on penalties.

Note the point that surprises most: being in scope is not an informal self-assessment. The decree requires registration on the Agency's platform within an annual window, and from there inclusion in official lists. Not having registered is not a way out: it is itself a breach.

What is actually required

The obligations reduce to three families, and none of the three can be bought.

  1. Manage risk. Risk analysis and security policies, incident handling, business continuity and recovery, supply chain security, access control and multi-factor authentication, encryption, staff training, procedures to assess the effectiveness of measures.
  2. Report incidents. Significant incidents must be reported to the authority on tight timelines: an early warning within hours of becoming aware, a fuller notification in the following days and a final report. You need to know this beforehand: nobody reads the rules in the middle of an attack.
  3. Involve the board. The heaviest novelty: management bodies approve the measures, oversee their implementation and must be trained. Security stops being delegated to the IT department and becomes the responsibility of whoever governs the company.

On penalties the rules set significant amounts, differentiated between essential and important entities, with ceilings linked to worldwide turnover. But for a small company the most concrete consequence is rarely the fine: it is the large customer asking for guarantees and no longer able to accept vague answers.

If one of your customers is in scope, so are you — not by law, but by contract.The effect that reaches more companies than the law obliges

The supply chain effect

This is the part that concerns most small Italian companies. The rules require in-scope entities to manage the risks coming from their suppliers. Translated: whoever is in scope must be able to demonstrate that whoever serves them is not a weak link.

In practice this shows up as increasingly detailed questionnaires, contract clauses on notification and recovery times, requests for evidence and — more and more often — the question of whether you are certified. A supplier who cannot answer is not fined: they are replaced.

It is also why many companies formally outside the scope are starting a certification path: not out of obligation, but because it is the fastest way to answer those questions once instead of at every tender.

Where to actually start

None of these steps requires a large budget, and all of them are worth doing even if you turn out to be out of scope.

  1. Establish whether you are in scope, crossing sector and size, and check your position on the Agency's platform. It is a documentation check, not a project.
  2. Take inventory. Which systems you need to work, where the data is, who holds credentials, which suppliers have access. The list is almost always longer than anyone remembers.
  3. Write the incident plan. Who decides, who tells whom, on what timeline, and who speaks to the authority. Two clear pages are worth more than a manual nobody opens.
  4. Put second factor everywhere that matters and run a restore drill. They are the two measures with the best cost-to-effect ratio, and both appear in every control list.
  5. Take the topic to the board. A minuted meeting approving the measures and scheduling training is, literally, one of the requirements.

What is not needed


If a customer has already sent you a security questionnaire, NIS2 already concerns you — regardless of how the scope check turns out. That is where to start: the answers that questionnaire needs are the same ones the rules need.

How do I know for certain whether we are in scope?
The criterion is sector plus size, but borderline cases are common — corporate groups, mixed activities, public contracts. The check must be made against the text of the decree and with a lawyer or the body supporting you: it is one of the few things not to settle with an article, including this one.
Does ISO 27001 cover us?
They are not the same thing and certification does not replace the obligations, starting with registration and incident reporting. But an existing management system covers a large part of the required measures and turns compliance into an alignment job rather than a construction one.
How long does it take to comply?
For a small company with systems in order, a few months: the long part is not technical, it is writing procedures, defining roles and training people. If inventory and incident plan are missing, you start there and the time doubles.
Can we delegate it all to a supplier?
You can delegate technical execution, not accountability: the rules name the management bodies, and that part cannot be outsourced. A good supplier covers the infrastructure and brings you the evidence; governance stays yours.
Ready to publishShare on LinkedIn