At first glance, NIS2 only applies to large companies, but it transforms a much wider range of businesses through supply chains. Why is it worth it for SMEs that are not directly affected to get involved – and how can they do so affordably?
Regarding NIS2, there is a common belief among domestic small and medium-sized enterprises that the regulation is “for the big ones.” The domestic implementation of NIS2 does indeed directly oblige organizations operating in larger, critical sectors – however, its impact spreads through a channel that many companies underestimate: the supply chain.
A key element of NIS2 is that companies covered by it are not only responsible for their own systems, but also for the cybersecurity risks associated with their direct suppliers and service providers. This is one of the risk management measures specifically mentioned in the regulation. A large company affected must assess and record the risks posed by its suppliers and service providers who have access to its systems or data – and this assessment cannot be done without the participation of partners.
Thus, the requirements gradually flow through the chain. The companies concerned increasingly expect information security compliance from their partners: as a contractual condition, as an audit right or in the form of a declaration of compliance with NIS2. This is already evident in practice - companies that are not themselves subject to the law but still need to prove how they handle cybersecurity because an important client asks them to do so regularly turn to consultants.
This primarily affects IT service providers, software developers, cloud providers and operators, but any supplier working in the supply chain of a regulated partner can be affected. For them, cybersecurity is no longer just a professional issue, but a business requirement – and a competitive advantage. They choose a company that is demonstrably prepared; one that cannot meet expectations can easily be eliminated from tenders and the supplier pool.
The good news is that building a basic cybersecurity control system does not require an investment of millions. Here are some steps that can put even an indirectly affected SME in a good position:
- It is worth assessing which systems and data the company has access to at its partners, and what it operates for them.
- It is advisable to establish basic policies and procedures for access management, password use, and incident management.
- It is recommended to implement multi-factor authentication and maintain a regular update routine.
- It is useful to prepare in advance for partners to send a cybersecurity questionnaire or request a statement - it is advisable to compile these in advance.
- Where possible, an existing framework (such as ISO/IEC 27001) provides a significant advantage in compliance.
The essence of NIS2 is not one-time compliance, but a routinely, security-conscious organization. More and more domestic companies will join this – not because the authority directly obliges them to do so, but because their business partners expect it. For companies that act in a timely manner, this will not be a burden, but an advantage.