Cybersecurity and NIS2 for SMEs
Getting an SME and its software suppliers ready for NIS2 compliance: a scope check, a gap analysis against Article 21 and the technical fixes. Every fix leaves evidence an auditor can read.
NIS2 on one sheet
- Legal basis
- Directive (EU) 2022/2555
- Applies to
- Mid-size and large firms, 18 sectors
- Incident reports
- 24 h, 72 h, one month
- Certificate
- None exists
NIS2 readiness: scope, gaps, fixes, evidence
Each stage leaves a document the next one starts from. The audit stays with an independent auditor.
What each stage covers
- Scope check
- Sector, size, entity type and national registration duties, settled before any other work.
- Gap analysis
- The NIS2 gap analysis checks each of the ten Article 21 measures against what runs today and orders the fixes by risk.
- Technical fixes
- MFA, tested backups, logging, vulnerability handling, secure development, a supplier inventory and incident runbooks.
- Evidence index
- What exists, where it lives and when it was last tested, in a form the company's auditor can read.
Not part of the work
The audit itself and any certificate. NIS2 has no certificate, and where national law requires an audit, an independent auditor performs it. ELASTO prepares the evidence that auditor asks for.
NIS2 scope: which companies it covers
Sector, size and member state decide it. Suppliers get the requirements through their customers.
First reading
The sector first, then the size or the customers.
A first reading; national law decides.
Scope, every case
- Listed sector, 50 or more staff or above EUR 10 million
- In scope as an essential or important entity. Next step: a NIS2 gap analysis.
- Listed sector, below both thresholds
- Usually out of scope, unless a size-independent rule applies: DNS and trust services, public electronic communications, sole provider of an essential service, central public administration. Next step: a NIS2 scope check.
- Sector not listed, customers in scope
- Out of direct scope. Customers in scope pass the Article 21 requirements down through questionnaires and contracts. Next step: NIS2 for software suppliers.
- Unclear, for example IT services or manufacturing
- The reading depends on the exact activity and on national law. Next step: a NIS2 scope check.
The 18 sectors in Annexes I and II
- Annex I, sectors of high criticality
- Energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management (B2B), public administration, space.
- Annex II, other critical sectors
- Postal and courier services, waste management, chemicals, food, manufacturing (medical devices, electronics, electrical equipment, machinery, vehicles), digital providers (marketplaces, search engines, social networks), research.
NIS2 requirements: measures, reporting, accountability
Ten minimum measures, a clock for reporting significant incidents and a management body that answers for both.
Article 21: ten measures, with evidence and fixes
Auditors ask for proof that a control runs. For each measure: the evidence that usually settles the question, and the engineering work that produces it.
- Risk analysis and security policies
- Evidence: a dated risk register and a security policy approved by management. Fix: an asset inventory, a risk register and policies written from the systems that actually run.
- Incident handling
- Evidence: an incident log and a response runbook with named roles. Fix: runbooks, alerting and a notification path that meets the 24 and 72 hour deadlines.
- Business continuity, backups and crisis management
- Evidence: restore tests with dates and results. Fix: automated offsite backups and a restore drill with a written record.
- Supply chain security
- Evidence: a supplier inventory and the security terms in each contract. Fix: the inventory, questionnaires and contract clauses, plus the supplier side of NIS2.
- Secure development and vulnerability handling
- Evidence: a patch process, dependency scanning and a disclosure contact. Fix: CI checks, dependency updates, an SBOM per release and a security.txt file, the practice on recent web platforms ELASTO builds.
- Effectiveness of the measures
- Evidence: test results over time, with findings and closing dates. Fix: automated checks in CI and a recurring review of the fix list.
- Cyber hygiene and training
- Evidence: training records and baseline settings on devices. Fix: device baselines and short training built on the company's own systems.
- Cryptography and encryption
- Evidence: an encryption policy and the settings that enforce it. Fix: TLS configuration, encryption at rest and key rotation.
- HR security, access control and asset management
- Evidence: joiner and leaver records, access reviews. Fix: role-based access, offboarding that closes every account, periodic access reviews.
- MFA and secured communications
- Evidence: MFA enforcement reports from the identity provider. Fix: MFA on email, admin consoles and remote access, and a secured channel for internal communication.
Article 34: fines
Maximum fines of at least EUR 10 million or 2% of worldwide annual turnover for essential entities, and EUR 7 million or 1.4% for important entities, whichever is higher. Each member state sets the final amounts in its own law.
NIS2 vs ISO 27001, DORA and the Cyber Resilience Act
The four overlap in places and answer different questions. NIS2 is an EU directive, applied through national law, for mid-size and large companies in listed sectors, and it has no certificate.
- ISO/IEC 27001
- A voluntary international standard for an information security management system, certified by accredited bodies. It covers much of Article 21; the 24 and 72 hour reporting and management training need separate work.
- DORA, Regulation (EU) 2022/2554
- Applies directly since 17 January 2025 to banks, insurers, investment firms and other financial entities, plus critical ICT providers. For financial entities, DORA takes precedence over NIS2 on the same topics.
- Cyber Resilience Act, Regulation (EU) 2024/2847
- Covers manufacturers of hardware and software products sold in the EU: reporting duties since 11 September 2026, CE marking from 11 December 2027. It regulates the product; NIS2 regulates the organisation that runs the systems.
Last checked 28 September 2026, against Directive (EU) 2022/2555.
Security by design, in the systems we built
Each control below runs in a client system; none of those projects was compliance work.
12per hour
Mozar
Secure staff sign-in and a record of every change
Rarău Rental
Counter access limited to the shop; sensitive actions need an admin
Muzeul Baia
Staff actions recorded by person
AI agent security: least privilege, approvals, logs
An agent with write access is a new kind of user account. Each agent ELASTO ships runs with the smallest set of permissions, asks a person before anything irreversible and logs every action.
- One service account per agent, read-only by default.
- Human approval before any irreversible action.
- A full action log the client can read.
- Secrets in a secrets manager, never in prompts or code.
- A pre-launch review against the OWASP Top 10 for LLM applications: prompt injection, sensitive data disclosure, excessive agency.
On Mozar, an AI agent proposes every change in plain view and a person confirms it before anything is saved. Every custom AI agent we build follows the same rules.
ELASTO as a supplier
How a vulnerability report reaches ELASTO and what happens to it are set out once, on the security and disclosure page, together with the measures that protect this site.
NIS2 supplier questionnaires and gap analysis
NIS2 for software suppliers
A customer's questionnaire answered with evidence.
An evidence folder
NIS2 gap analysis
A written report against Article 21, fixes by risk.
A written report
Security testing
Web applications and AI agents, scoped per system.
On request
NIS2 compliance questions
NIS2 in plain words
NIS2 is the EU directive on a high common level of cybersecurity, Directive (EU) 2022/2555. It requires companies in critical sectors to run ten minimum security measures, report significant incidents in three stages and make management accountable. Each member state applies it through national law.
NIS2 scope for a company
NIS2 applies to a company when its sector appears in Annex I or II and it has 50 or more staff, or turnover and balance sheet both above EUR 10 million. Some entities are covered regardless of size, such as DNS and trust service providers.
National law decides the final list, so a NIS2 scope check reads the company's activities against the member state's text.
NIS2 certification
NIS2 certification does not exist, and no body can certify a company as NIS2 compliant. What exists is evidence that the Article 21 measures run, national audits where the law requires them, and voluntary certificates such as ISO 27001 that cover part of the ground.
ISO 27001 and NIS2
An ISO 27001 certificate covers much of Article 21, because both rest on risk management and similar controls. It does not cover the NIS2 reporting deadlines, the duties of the management body or national registration.
The NIS2 gap analysis maps existing ISO controls to Article 21 and lists what is left.
Auditor role and who performs the audit
ELASTO is not an auditor and does not perform NIS2 audits. The work covers scope, gap analysis, technical fixes and the evidence the auditor asks for. Where national law requires an audit, an independent auditor performs it; in Romania, one attested by DNSC.
Management liability and training
Under Article 20, the management body approves the cybersecurity measures, oversees how they are applied and can be held liable for breaches. Its members must follow training, and companies are encouraged to offer similar training to staff. The gap analysis report includes a summary written for that approval.
Incident reporting deadlines
A significant incident is reported in three stages under Article 23: an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours and a final report within one month of the notification. Reports go to the national CSIRT or competent authority.
The 24-hour deadline is easier to meet with a runbook that names who decides and who sends.
Working alongside one IT person
Working alongside a single IT person is the usual case. ELASTO takes the engineering work, such as the MFA rollout, backups with restore tests, logging and the patch process, while the IT lead keeps ownership of the systems. Every document stays editable and in the company's own accounts, as the handover checklist sets out.
NIS2 work starts with a scope check
One call covers the sector, the size, the customers and the controls already in place.
- Studio
- Cluj-Napoca, Romania, EU