Back to knowledge baseCOMPLIANCE

The NIS2 directive: what does it mean in practice for your SME?

Elli27 June 2026Last updated on 14 August 20268 min read

What is the NIS2 directive?

NIS2 stands for Network and Information Security Directive 2 — the successor to the original NIS directive from 2016. The European Union issued this directive to strengthen the cyber security of organisations in critical and important sectors.

In Belgium, NIS2 has been transposed into national law through the act of 26 April 2024. This means Belgian organisations falling within its scope have concrete obligations around risk management, incident reporting and the security of their systems.

Who falls under NIS2?

NIS2 expands the scope considerably compared with NIS1. The directive distinguishes two categories:

- Essential entities: energy, transport, water, finance, healthcare, digital infrastructure

- Important entities: postal services, waste management, chemicals, food, manufacturing, digital providers

For SMEs the threshold is this: organisations with more than 50 employees or an annual turnover above €10 million in the sectors concerned may fall under NIS2. But smaller organisations in the supply chain of affected companies can pick up obligations indirectly as well.

"NIS2 is no longer somebody else's problem. Many Belgian SMEs are affected — even if they don't know it yet."

Which obligations follow from NIS2?

Affected organisations must, among other things:

- Carry out and document a risk analysis

- Take appropriate technical and organisational security measures

- Have an Incident Response Plan in place

- Report incidents with significant impact within 24 hours (initial notification) and 72 hours (detailed notification)

- Manage supply chain security

- Safeguard personnel security and access management

What are the penalties?

NIS2 provides for substantial fines. Essential entities risk up to €10 million or 2% of global annual turnover. Important entities risk up to €7 million or 1.4% of turnover.

But beyond the financial penalties, the reputational damage from an incident — and from being unable to demonstrate compliance — can be enormous.

Which first steps to take today?

Not sure whether your organisation falls under NIS2? Start with these steps:

1. Check whether your sector and size place you within NIS2

2. Run a baseline assessment: where does the organisation stand today?

3. Draw up a priority list of measures

4. Develop a basic information security policy

5. Consider external support through a CISO as a Service

NetGuard guides SMEs from baseline assessment to compliance. Get in touch for a no-obligation conversation.

Share this article

Elli

No author profile available.

Related articles

News

That voice on the phone might not be human

Scammers now use AI to mimic the voice of a business owner to push through an urgent payment. Here's how this new form of CEO fraud works, and five concrete steps to reduce the risk.

13 August 20265 min read
The NIS2 directive: what does it mean in practice for your SME? | NetGuard