NIS2 for Small Enterprises 50-100 Employees: Quick Compliance
Practitioner note: This is not legal advice. For specific situations, consult a qualified attorney or compliance officer.
TL;DR
- Lean NIS2 compliance for SMEs with 50-100 employees in 8 weeks
- Total budget: approximately EUR 8,000 with the right tooling and external consulting
- Essential entity from 50 employees, EUR 10M turnover, and one of the 11 NIS2 sectors
- Important entity from 50 employees, EUR 10M turnover, and one of the 7 additional sectors
- Outsource SOC, retain management accountability and crisis-team leadership
1. Are you in scope?
Essential entity status applies from 50 employees and EUR 10M turnover when the company operates in one of the 11 NIS2 essential sectors (energy, banks, health, cloud, etc.). Important entity status applies under the same size thresholds for the seven additional sectors. Below 50 employees you are usually out of scope unless the entity is "critical."
2. 8-week roadmap
| Week | Activity |
|---|---|
| 1 | Asset inventory |
| 2 | Risk analysis |
| 3-4 | 12 mandatory policies |
| 5 | MFA rollout and backup strategy |
| 6 | Incident-response plan and awareness training |
| 7 | Top-10 supplier audit |
| 8 | Tabletop exercise and documentation |
3. EUR 8,000 budget breakdown
- Microsoft 365 Defender: included in E5 license (assume already in place)
- Veeam Cloud Backup: ~EUR 1,500
- External consulting (5 person-days): ~EUR 5,000
- Compliance-Kit NIS2 Kit: EUR 1,490
4. Outsourcing options
- SOC-as-a-Service: EUR 800-3,000 per month
- External CISO / virtual CISO: EUR 8,000-15,000 per year
- Cybersecurity advisor (1 person-day per month): EUR 1,500 per month
5. What you must keep in-house
Even with full outsourcing, three things stay with the management team:
- Risk acceptance decisions by the managing director
- Section 38 BSIG management-liability awareness
- Crisis-team availability when an incident occurs at 2 a.m.
Summary
An SME of 50-100 employees can reach defensible NIS2 compliance in 8 weeks for around EUR 8,000 by combining smart tooling, prebuilt templates, and a focused external advisor. The non-delegable parts are management accountability and crisis decision-making.
Frequently Asked Questions
Am I affected at all?
Check with our NIS2 self-assessment: 30 questions, 3 minutes, individual recommendation.
Is ISO 27001-Light sufficient?
No - Section 30 (2) requires all 10 areas. 'Light' is marketing.
Sources
- Directive (EU) 2022/2555 — NIS2 (As of: 2026-05-02)
- BSIG 2025 (consolidated) (As of: 2026-05-02)
- BSI — NIS-2 FAQ (as of: ongoing)