NIS2 Deadline: What Small Businesses and Suppliers Should Know
Short answer to the NIS2 small business question? The directive probably doesn’t cover your company directly. But it will reach you anyway, through the larger clients it does cover. According to the Commission’s NIS2 overview, Member States have until 17 October 2024 to transpose the directive into national law. And that is why security questionnaires are landing in supplier inboxes this autumn. Below: what sits behind those forms and how to answer them when you have no security department (most small firms don’t).
Table of Contents
NIS2 Directive Explained in Plain Language
NIS2 replaces NIS1. It sets cybersecurity risk management and incident reporting duties for entities in more sectors than before, and the Commission sums up the change as a wider scope, clearer rules and stronger supervision tools. One catch. It’s a directive, so it works through national law, and the practical detail comes from each country’s own act. So when you see “NIS2 October 2024”, read it as a deadline for governments to legislate, not a single switch-on date for every company.
NIS2 Small Business Scope: Does the Directive Apply to You?
As a rule, no. NIS2 covers medium-sized and large entities in listed sectors, which leaves a typical small company outside its direct scope. Whether a given organisation is in depends on two things, sector and size, and both are defined in national legislation. There are also exceptions that can pull smaller firms in. My advice: read your country’s law (or its draft) and confirm your position with an adviser. And don’t relax too early, because out of scope is not the same as unaffected.
Why the NIS2 Supply Chain Rules Reach Small Suppliers
Covered entities have to manage the security risks of their suppliers. So what do they do? They pass the questions down the chain. In practice, the NIS2 supply chain duty shows up as questionnaires, new contract clauses and requests for a named security contact. A small vendor with access to client data or systems tends to be asked first, since that is where the customer’s exposure is most direct.
There’s a commercial side too. Clear answers keep a contract moving through procurement. Vague ones stall it or send it off to legal review. Treat the form as part of the sale, not as an interruption, and it usually pays off.
What Clients Usually Ask: NIS2 Suppliers Requirements in a Questionnaire
Most questionnaires circle the same handful of topics: who has access, how data is protected, what happens when something goes wrong. The wording differs from customer to customer. Still, the NIS2 suppliers requirements they translate into tend to fall under these headings:
- Access control - who can log in to which system, and who approves it
- Leavers and offboarding - how quickly accounts are closed when someone departs
- Backups and recovery - whether copies exist and whether a restore has been tested
- Incident notification - whom the client hears from, and how
- Subcontractors and tools - which third parties touch the client’s information
- Data location - where records are stored
Answer honestly. “Yes”, “no” or “planned by a date” beats an optimistic guess every time, because a wrong “yes” turns into a contractual problem later, once the customer relies on it. Same logic for certifications and compliance: never claim what you do not hold.
A Supplier Readiness Checklist: Cybersecurity Risk Management Basics
Five basics cover most of what a small supplier is asked to prove. No dedicated security team needed. Just an owner and a few hours of attention.
- Map access. List who can use which system and schedule regular user access reviews so the list stays true.
- Back up and restore. Confirm that backups exist for every system holding client data. Then test one restore and see that it actually works.
- Close accounts on departure. Write down a routine for removing access when people leave, with one person responsible for running it.
- Name an incident contact. Pick one person. Record how and when clients are informed if something goes wrong.
- Keep a vendor list. Note every tool and subcontractor that touches customer information.
Put the results in one short document. That’s it. This is cybersecurity risk management at a scale a small team can sustain, and it turns the next questionnaire into minutes of copying instead of days of digging.
Where Customer Data Lives: Checking Your Own Tools
Your vendor list is only as good as what you know about each tool: hosting location, encryption, permissions, backups and a data processing agreement. Put those questions to every software provider. Before you write to support, though, look at the vendor’s security page and its DPA page, because the answers are often sitting there already. And if a vendor cannot say where your records are kept? Then you cannot tell your client either.
An example. EpicCRM runs on EU servers with encryption, roles and permissions, automatic backups and a published DPA page - facts a supplier can quote directly in a form. Keep the same questions in mind when choosing the right CRM or any other system that will hold customer information.
What to Do Before and After 17 October
For a small supplier the deadline changes little overnight. The questions from clients will keep coming, though. A sensible order of work: first confirm your own scope with an adviser, then complete the checklist above, and finally prepare standard written answers you can reuse. One more thing. Access rules are easier to keep when they are enforced in one place, and roles and permissions in EpicCRM are one such place for customer data.
Seen this way, the NIS2 small business story is less about legal exposure and more about being a supplier that larger customers can approve quickly. Who has access, where the data sits, whom to call in an incident. Firms that know those three things will answer with confidence, whatever form the next request takes.
FAQ
Does NIS2 apply to small businesses?
Generally not directly. The directive covers medium-sized and large entities in listed sectors, so most small companies are out of scope. Exceptions exist, and the exact criteria are set in national law. Check your country’s rules and confirm your position with an adviser.
What happens on 17 October 2024?
It is the date by which Member States are to transpose the directive into national law. Obligations for individual companies follow from those national rules, not from the date itself. For a small supplier the visible effect is mostly this: more security questions from clients.
How should a small supplier answer a client’s security questionnaire?
Honestly, and with evidence for access control, offboarding, backups, an incident contact and a vendor list. Something missing? Mark it as planned and give a date. Don’t claim certifications or compliance you do not hold, because the client may rely on that statement in the contract.



