---
title: "NIS2 for small businesses: how it actually affects you"
url: https://www.hqsolutions.ro/en/guides/nis2-for-small-business/
lang: en
site: HQ
---

> Does NIS2 apply to your small business? While often not directly, it impacts you through client requirements. Understand the expectations and necessary steps.

# NIS2 for small businesses: how it actually affects you

NIS2 is the European cybersecurity directive that has likely triggered at least one anxious email in your inbox. The good news: for most small businesses, the panic is unwarranted. The caveat: not being directly targeted does not mean you are completely exempt. Let’s break down the reality objectively.

## Directly regulated entities

NIS2 primarily applies to medium and large companies in essential or important sectors, such as energy, transport, healthcare, digital infrastructure, and certain types of manufacturing. The general threshold starts at 50 employees or €10 million in turnover within these sectors, and in Romania, the supervisory authority is the DNSC.

If you operate a 15-person company providing accounting, retail, or standard services, you are likely not on the list of directly regulated entities. However, the analysis doesn't stop here.

> The general threshold is at least 50 employees or €10M turnover in covered sectors.

## The indirect impact: your supply chain

The directive requires regulated companies to verify the cybersecurity of their supply chain—which includes your business if you are a supplier. In practice, this translates into security questionnaires, new contractual clauses, and sometimes client-requested audits. For many small companies, their first encounter with NIS2 is not a regulatory fine, but a comprehensive security spreadsheet from their largest client.

At that point, relying on an informal 'IT guy' is no longer an acceptable answer. Clients demand concrete evidence: verified backups, controlled data access, consistent updates, and a documented history of incident resolution.

> Your first contact with NIS2: a comprehensive security questionnaire from a major client.

## Practical steps, without alarmism

The positive aspect is that the baseline requirements of NIS2 are essentially the standard IT hygiene any serious company should already maintain: validated backups, timely updates, strict access and password management, and a clear incident response protocol. It does not require exotic solutions, but rather consistent maintenance and operational discipline throughout the year.

Our recommendation is straightforward: do not purchase a 'NIS2 package' driven by marketing pressure, but do not ignore the subject either. Ask yourself: if your largest client requests proof of your security posture tomorrow, what can you show them? If the answer is uncertain, that is your starting point, and a standard on-site IT audit will reveal exactly where you stand. For the definitive legal classification of your business, the correct authority is the DNSC, not marketing emails.

> Baseline requirements equal consistent IT hygiene, not a once-a-year effort.
