• For whom
    • Small and medium businesses
    • Sales teams
    • Marketing departments
    • Customer service departments
    • For startups
  • Features & Benefits
    • Summary
    • Contact management
    • Process Automation
    • Analytics and Reporting
    • Project management
    • Data security
  • Pricing
  • News
  • Contact
  • English
    • Polski

Try it yourself

Edit Content

Log in to our demo account
and test the capabilities of Epic CRM.

Login - [email protected]
Password - demo

Close

Log in or sign up

Edit Content

Please login to your account

Forgot Password?

Sign In
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Close
Security & Data

NIS2 Deadline: What Small Businesses and Suppliers Should Know

October 2, 2024 Krzysztof Balicki Comments Off on NIS2 Deadline: What Small Businesses and Suppliers Should Know
NIS2 Deadline: What Small Businesses and Suppliers Should Know

Short answer to the NIS2 small business question? The directive probably doesn’t cover your company directly. But it will reach you anyway, through the larger clients it does cover. According to the Commission’s NIS2 overview, Member States have until 17 October 2024 to transpose the directive into national law. And that is why security questionnaires are landing in supplier inboxes this autumn. Below: what sits behind those forms and how to answer them when you have no security department (most small firms don’t).

Table of Contents

  • NIS2 Directive Explained in Plain Language
  • NIS2 Small Business Scope: Does the Directive Apply to You?
  • Why the NIS2 Supply Chain Rules Reach Small Suppliers
  • What Clients Usually Ask: NIS2 Suppliers Requirements in a Questionnaire
  • A Supplier Readiness Checklist: Cybersecurity Risk Management Basics
  • Where Customer Data Lives: Checking Your Own Tools
  • What to Do Before and After 17 October
  • FAQ
    • Does NIS2 apply to small businesses?
    • What happens on 17 October 2024?
    • How should a small supplier answer a client’s security questionnaire?

NIS2 Directive Explained in Plain Language

NIS2 replaces NIS1. It sets cybersecurity risk management and incident reporting duties for entities in more sectors than before, and the Commission sums up the change as a wider scope, clearer rules and stronger supervision tools. One catch. It’s a directive, so it works through national law, and the practical detail comes from each country’s own act. So when you see “NIS2 October 2024”, read it as a deadline for governments to legislate, not a single switch-on date for every company.

NIS2 Small Business Scope: Does the Directive Apply to You?

As a rule, no. NIS2 covers medium-sized and large entities in listed sectors, which leaves a typical small company outside its direct scope. Whether a given organisation is in depends on two things, sector and size, and both are defined in national legislation. There are also exceptions that can pull smaller firms in. My advice: read your country’s law (or its draft) and confirm your position with an adviser. And don’t relax too early, because out of scope is not the same as unaffected.

Why the NIS2 Supply Chain Rules Reach Small Suppliers

Covered entities have to manage the security risks of their suppliers. So what do they do? They pass the questions down the chain. In practice, the NIS2 supply chain duty shows up as questionnaires, new contract clauses and requests for a named security contact. A small vendor with access to client data or systems tends to be asked first, since that is where the customer’s exposure is most direct.

There’s a commercial side too. Clear answers keep a contract moving through procurement. Vague ones stall it or send it off to legal review. Treat the form as part of the sale, not as an interruption, and it usually pays off.

What Clients Usually Ask: NIS2 Suppliers Requirements in a Questionnaire

Most questionnaires circle the same handful of topics: who has access, how data is protected, what happens when something goes wrong. The wording differs from customer to customer. Still, the NIS2 suppliers requirements they translate into tend to fall under these headings:

  • Access control - who can log in to which system, and who approves it
  • Leavers and offboarding - how quickly accounts are closed when someone departs
  • Backups and recovery - whether copies exist and whether a restore has been tested
  • Incident notification - whom the client hears from, and how
  • Subcontractors and tools - which third parties touch the client’s information
  • Data location - where records are stored

Answer honestly. “Yes”, “no” or “planned by a date” beats an optimistic guess every time, because a wrong “yes” turns into a contractual problem later, once the customer relies on it. Same logic for certifications and compliance: never claim what you do not hold.

A Supplier Readiness Checklist: Cybersecurity Risk Management Basics

Five basics cover most of what a small supplier is asked to prove. No dedicated security team needed. Just an owner and a few hours of attention.

  1. Map access. List who can use which system and schedule regular user access reviews so the list stays true.
  2. Back up and restore. Confirm that backups exist for every system holding client data. Then test one restore and see that it actually works.
  3. Close accounts on departure. Write down a routine for removing access when people leave, with one person responsible for running it.
  4. Name an incident contact. Pick one person. Record how and when clients are informed if something goes wrong.
  5. Keep a vendor list. Note every tool and subcontractor that touches customer information.

Put the results in one short document. That’s it. This is cybersecurity risk management at a scale a small team can sustain, and it turns the next questionnaire into minutes of copying instead of days of digging.

Where Customer Data Lives: Checking Your Own Tools

Your vendor list is only as good as what you know about each tool: hosting location, encryption, permissions, backups and a data processing agreement. Put those questions to every software provider. Before you write to support, though, look at the vendor’s security page and its DPA page, because the answers are often sitting there already. And if a vendor cannot say where your records are kept? Then you cannot tell your client either.

An example. EpicCRM runs on EU servers with encryption, roles and permissions, automatic backups and a published DPA page - facts a supplier can quote directly in a form. Keep the same questions in mind when choosing the right CRM or any other system that will hold customer information.

What to Do Before and After 17 October

For a small supplier the deadline changes little overnight. The questions from clients will keep coming, though. A sensible order of work: first confirm your own scope with an adviser, then complete the checklist above, and finally prepare standard written answers you can reuse. One more thing. Access rules are easier to keep when they are enforced in one place, and roles and permissions in EpicCRM are one such place for customer data.

Seen this way, the NIS2 small business story is less about legal exposure and more about being a supplier that larger customers can approve quickly. Who has access, where the data sits, whom to call in an incident. Firms that know those three things will answer with confidence, whatever form the next request takes.

FAQ

Does NIS2 apply to small businesses?

Generally not directly. The directive covers medium-sized and large entities in listed sectors, so most small companies are out of scope. Exceptions exist, and the exact criteria are set in national law. Check your country’s rules and confirm your position with an adviser.

What happens on 17 October 2024?

It is the date by which Member States are to transpose the directive into national law. Obligations for individual companies follow from those national rules, not from the date itself. For a small supplier the visible effect is mostly this: more security questions from clients.

How should a small supplier answer a client’s security questionnaire?

Honestly, and with evidence for access control, offboarding, backups, an incident contact and a vendor list. Something missing? Mark it as planned and give a date. Don’t claim certifications or compliance you do not hold, because the client may rely on that statement in the contract.

Post navigation

Previous
Next

Search

Categories

  • Automation & Integrations (33)
  • CRM best practices and tips (56)
  • CRM Guides (41)
  • Customer Support (17)
  • Industry insights and trends (12)
  • Sales Management (45)
  • Security & Data (17)

Recent posts

  • Sales Playbook for Small Teams: What to Write Down First
    Sales Playbook for Small Teams: What to Write Down First
  • Key Account Management for Small B2B Teams: Where to Start
    Key Account Management for Small B2B Teams: Where to Start
  • Cyber Resilience Act Reporting: What to Ask Your Software Vendors
    Cyber Resilience Act Reporting: What to Ask Your Software Vendors

Tags

AI analytics automation B2B business business growth Business Software business tools checklist compliance CRM CRM Trends customer data Customer Engagement Customer Retention customer service customer support Data Management data migration data quality Data Security email marketing follow-up forecasting GDPR guide help desk KPI lead generation lead management lead scoring marketing pipeline productivity revenue Sales Sales Forecasting sales management sales pipeline sales process sales team small business software spreadsheets workflow

Related posts

Key Account Management for Small B2B Teams: Where to Start
Sales Management

Key Account Management for Small B2B Teams: Where to Start

September 26, 2026 Krzysztof Balicki Comments Off on Key Account Management for Small B2B Teams: Where to Start

Key account management means picking the few clients your business really depends on and giving each one a named owner, a written plan and a regular review. That way they stop sitting in the same queue as everyone else. And plenty of small B2B firms have exactly this problem: a handful of clients bring in […]

Cyber Resilience Act Reporting: What to Ask Your Software Vendors
Security & Data

Cyber Resilience Act Reporting: What to Ask Your Software Vendors

September 25, 2026 Krzysztof Balicki Comments Off on Cyber Resilience Act Reporting: What to Ask Your Software Vendors

The Cyber Resilience Act reporting rules put new duties on manufacturers. Not on the small companies that buy their products. But they do hand you, the buyer, a solid excuse to ask every vendor one thing: how will news of a flaw and its fix actually reach us? What follows is the customer’s side of […]

Overdue Invoice Follow-Up: Getting Paid and Keeping the Client
CRM best practices and tips

Overdue Invoice Follow-Up: Getting Paid and Keeping the Client

September 5, 2026 Krzysztof Balicki Comments Off on Overdue Invoice Follow-Up: Getting Paid and Keeping the Client

A polite, scheduled overdue invoice follow-up gets you paid faster than ad hoc chasing. It also protects the relationship, because the client knows what to expect at every step. Most small B2B firms are fine at sending invoices on time. Chasing them? Different story. It runs on mood and memory, and the fear of sounding […]

Do you want to receive news and updates?


    Epic CRM

    CRM for small and medium businesses: sales, tasks, contracts and customer service in one place.

    Resources
    • Features
    • Pricing
    • News
    • FAQ
    • Terms of Service
    • Privacy Policy
    • Cookie Policy
    • DPA
    • Cookie settings
    • Features
    • Pricing
    • News
    • FAQ
    • Terms of Service
    • Privacy Policy
    • Cookie Policy
    • DPA
    • Cookie settings
    Partners
    • Botino: AI voicebots
    • Web Systems Łódź
    • Sellaro: eCommerce integrations
    • MailCraft: email marketing
    • Inteleo: AI assistants
    • Botino: AI voicebots
    • Web Systems Łódź
    • Sellaro: eCommerce integrations
    • MailCraft: email marketing
    • Inteleo: AI assistants

    All rights reserved 2024 - 2026 ©EpicCRM

    • Developed by Web Systems