
If your company has fewer than 50 people and a turnover of up to €10 million, NIS2 most likely does not apply to you directly. That is the good news. The other news: many of your customers are covered, and NIS2 makes them responsible for the security of their suppliers. So the questions arrive anyway.
This article explains where small companies stand, and which basic measures give you honest, confident answers without hiring a compliance team.
Why small companies are usually outside NIS2
NIS2 generally applies to medium-sized and large organizations in the covered sectors. Small and micro companies (fewer than 50 people and a yearly turnover or balance sheet of up to €10 million) are usually outside. There are exceptions: some types of organization are covered whatever their size, for example providers of public electronic communications networks, trust service providers and DNS service providers. Your country's law can add others.
If you want a quick answer for your company, the free NIS2 check asks five questions and tells you in a minute.
Why you will be asked anyway
Covered companies must manage the security of their supply chain (Article 21(2)(d)). Their authority can ask them how they checked their suppliers. For you this shows up as security questionnaires, new contract clauses and sometimes a request to prove a specific measure, such as multi-factor authentication.
Small suppliers that answer well have an advantage: they are easier to buy from.
A practical minimum for small suppliers
You do not need a thick policy manual. These measures cover most questions and protect you against the most common attacks:
- Multi-factor authentication for email, remote access and every admin account.
- Backups of important data, kept separately, with a restore tested at least once a year.
- Updates installed quickly on laptops, servers and network devices; old systems replaced.
- Access control: personal accounts only, and access removed on the day someone leaves.
- Malware protection on every device, and disk encryption on laptops.
- An incident plan on one page: who to call, how to disconnect, how to inform customers.
- Short, yearly security training for everyone, including phishing examples.
- A few written policies: information security, acceptable use, backups and incidents. Short and true is better than long and copied.
Show it, do not just say it
Customers trust what they can see. Keep a short record for each measure: what you do, since when, who is responsible, and a piece of evidence (a screenshot, a test result, a training list). Then share it in one place, for example a trust page, instead of sending documents again for every request.
How CloudSignLab helps
The free package of CloudSignLab is made for this: the readiness score shows where you stand, the starter control set turns the minimum above into clear tasks, the answer library keeps your answers ready for the next questionnaire, and the trust page shows your security status to customers. When you grow, the Supplier package adds the full supplier control set, more questionnaires and a branded trust page.
Check if NIS2 applies to youThis article is a general introduction, not legal advice. The national law of your country decides the details; when in doubt, ask your authority or a legal adviser.


