NIS2 subcontractors: A very small business with fewer than 50 employees is generally not directly affected by the directive, but it may be affected commercially if it provides services to a regulated company. In practical terms, expect security questionnaires, contractual clauses, and basic evidence: backups, access management, updates, and an incident response plan. The real issue is the ripple effect throughout the supply chain.
NIS2 Subcontractors: Why the Cascading Effect Exists
The European NIS2 Directive, adopted on December 14, 2022, as Directive (EU) 2022/2555, replaces the previous NIS Directive of 2016. It entered into force on January 16, 2023, and Member States were required to transpose it into their national law by October 17, 2024, at the latest.
Its goal is easy to understand: to raise the level of cyber security organizations deemed essential or important to the economy and society. This includes, in particular, certain sectors such as digital, industrial, healthcare, energy, finance, and transportation, based on criteria related to size and activity.
The provision that changes everything for suppliers is found in Article 21. Regulated entities must manage the security of their supply chain—that is, the security related to their direct service providers, software vendors, hosting providers, IT service providers, web agencies, and digital service providers.
In other words, even if your company does not fall directly under the scope of NIS2, your client may need to verify that you do not become its weak link. This is less a direct regulatory requirement than a condition for trust—and sometimes for doing business.
Are very small businesses affected by NIS2?
In France, according to information published by ANSSI and MesServicesCyber in 2026, “relevant entities” include, in particular, organizations that employ at least 50 people or have annual revenue and total assets exceeding 10 million euros, provided they operate in the targeted sectors. A very small business with 12 employees that develops a website, an API, or an application for an affected client is therefore not automatically subject to NIS2.
But this distinction is misleading. The Irish National Cybersecurity Center, in its NIS2 FAQ, clearly explains that an organization can be indirectly affected if it is part of the supply chain of one or more NIS2 entities. This is not a magical extension of the directive to all small service providers. It is a consequence of supplier risk management.
As of July 8, 2026, France had not yet notified the European Commission of its national transposition measures; the Commission has, in fact, referred France, Ireland, Spain, and the Netherlands to the Court of Justice of the European Union for this delay. ANSSI continues to indicate that the French transposition is pending and offers a pre-registration service.
This delay should not lull tort into a false sense of security. Major ordre donors, mid-sized companies, and regulated firms are already preparing their purchases, contracts, and internal audits. In the projects we’re working on, we often see cybersecurity evolve from a technical issue addressed at the end of the process to a selection criterion right from the request for proposals stage.
What Your Customers Might Ask You Right Now
Implementing Regulation (EU) 2024/2690 of October 17, 2024, establishes technical and methodological requirements for certain digital entities, particularly regarding supply chain security policies. Even though it does not apply directly to your company, it influences purchasing practices.
In practice, these requirements often take three forms: a security questionnaire, contractual clauses, and requests for evidence. Specialized platforms such as NISD2.eu report in 2026 that many European procurement teams are creating their own supplier questionnaires based on NIS2 requirements related to supplier risk.
A questionnaire might ask whether you use multi-factor authentication, how you back up data, who has access to production environments, how you manage security patches, or even how long it takes you to notify a customer in the event of an incident. Nothing out of the ordinary. But if nothing is documented, providing accurate answers quickly becomes time-consuming.
For a WordPress site, for example, the question isn’t just “Is the site up to date?” It becomes: Who applies the updates, within what timeframe, with what backup in place before making changes, what logging (history of actions), what hosting, and what application firewall? To explore this specific point in more depth, a dedicated framework is available at the impacts of NIS2 on a WordPress site.
- An incident notification clause requiring notification within 24 to 72 hours, depending on the severity and the contract.
- A requirement to encrypt administrative access and sensitive backups.
- A restriction on shared accounts, which are all too common in small organizations.
- Evidence requirements: configuration snapshot, internal policy, access log, scan report.
- A cascading subcontracting clause, if you yourself outsource hosting, support, or development.
Budget, Deadlines: A Realistic Scope for a Small Organization
The classic pitfall is seeking full “NIS2 compliance” even though your small business isn’t directly within the scope of the regulation. With this budget, it’s better to aim for a verifiable security foundation: simple measures that are consistently maintained over time and that you can explain to a client without having to improvise.
Costs vary depending on your IT system, but the French market offers some points of reference. A small organization starting from scratch can often achieve a solid initial level within a few weeks, provided it remains pragmatic.
| Action | Typical timeframe | Indicative budget in France | Interest in a NIS2 client |
|---|---|---|---|
| Basic Security Audit of a Website or Application | 3 to 10 days | Approximately €1,500 to €5,000, excluding tax | Identify obvious weaknesses before conducting a survey or renewing a contract |
| MFA Setup, Access Management, Basic Hardening | 1 to 3 weeks | Approximately €1,000 to €4,000, excluding tax | Reduce the Risk of Compromise Due to Stolen Passwords |
| Tested Backup and Restore Policy | 1 to 2 weeks | Around €800 to €3,000 excl. tax | Demonstrate the ability to recover from an incident or ransomware attack |
| Supplier Documentation: Procedures, Supporting Documents, Sample Responses | 1 to 3 weeks | Approximately €1,500 to €6,000, excluding tax | Respond more quickly to purchase orders and limit vague terms |
| Targeted Penetration Test on an Exposed Application | 1 to 3 weeks | Approximately €4,000 to €12,000, excluding tax | Apporter: A More Robust Proof for a Critical Service |
These figures are not a substitute for a formal quote. They provide a rough estimate. Honestly, a full penetration test is only justified if the application handles sensitive data, exposes a critical API, or becomes dependent on a major client; for a simple showcase website, the money is often better spent on hosting, updates, backups, and monitoring.
Technical choices matter, too. Basic shared hosting may be sufficient for a small institutional website, but it will be difficult to justify for a client connected to a business system. OVHcloud, Scaleway, AWS, Microsoft Azure, or Google Cloud may be suitable depending on your needs, provided that access, logs, backups, and contractual responsibilities are configured correctly.
What should you ask of your own subcontractors?
The ripple effect doesn’t stop with you. If you’re an agency, SaaS provider, IT service provider, or systems integrator, your own vendors come into play: hosting providers, freelancers, email marketing tools, maintenance providers, payment solutions, and outsourced support.
The right approach is not to send a 120-question survey to everyone. That’s counterproductive. Instead, categorize your suppliers by risk: access to personal data, administrator access, access to code, access to production environments, and dependence on service availability.
A freelancer working on a public Figma mockup does not pose the same level of risk as an administrator with SSH (secure shell) access to the production environment. The same logic applies to a mobile API: if it provides access to user accounts or business data, security controls must be more rigorous. Risks associated with interfaces are often underestimated; a useful point is detailed in this analysis on Mobile API Security.
The minimum acceptable standards boil down to a few requirements: multi-factor authentication, named accounts, revocation of access upon completion of the assignment, verified backups, encryption of data transfers, and an incident reporting procedure. From the agency’s perspective, the natural instinct is to request simple but concrete evidence, rather than a general statement such as “we are secure.”
The Pitfall That Non-Technical People Fall Into: The Proof
Many companies have good internal practices. The executive knows that backups exist, that the developer updates the website, and that the hosting provider is reliable. The problem arises when a client requests dated, legible, and legally enforceable proof.
Evidence can be simple: a one-page procedure, a screenshot showing MFA enabled in Microsoft 365 or Google Workspace, a backup export, a WordPress update report, a hosting certificate, or even an empty incident log. Without these elements, your response is based solely on trust. In a procurement process, that’s not enough.
Another pitfall: agreeing to overly broad clauses. Some requests require the supplier to guarantee full NIS2 compliance, even if the supplier is not directly involved and does not have control over the entire system. You need to renegotiate. You can commit to specific measures, notification deadlines, a technical scope, and shared responsibilities—but not to the impossible.
The GDPR, which has been in effect since 2018, has already accustomed companies to this approach of documented outsourcing. NIS2 adds a more operational layer of security: business continuity, vulnerabilities, incidents, and suppliers. These two topics often overlap, especially when a website or application processes personal data.
Building an acceptable safety net without overpaying
The Cyber France Framework (ReCyF) version 2.5, published by ANSSI on March 17, 2026, sets forth 20 security objectives as a working basis for NIS2. For a small business with a direct scope, it can serve as a guide, not as a checklist to be applied mechanically in its entirety.
Start with the most likely risks. Weak passwords, shared accounts, outdated extensions, backups that have never been tested, and access rights retained after a service provider leaves cause more damage than highly sophisticated scenarios. Simple. But difficult to stick to.
On a mobile application, security isn't limited to the App Store or Play Store. You need to check the embedded secrets, API calls, session management, logs, and third-party libraries. Before release, a Mobile Application Security Checklist already helps prevent visible and costly vulnerabilities.
Visit passkeys, which are standardized by the FIDO Alliance and are gradually being adopted by Apple, Google, and Microsoft, can also reduce password-related risks for certain use cases. They do not replace access governance, but they may be appropriate for client-side applications or sensitive interfaces. This topic should be evaluated realistically, particularly by referring to this guide on Passkeys for websites.
A solid foundation for a small business vendor often hinges on six key areas: an inventory of services provided, MFA for critical accounts, tested backups, regular updates, incident response procedures, and vendor documentation. It’s nothing spectacular. That’s precisely why it works.
Defining the scope of this type of project early on helps avoid most unpleasant surprises: unrealistic requirements, misallocated budgets, underestimated timelines, and unclear responsibilities with service providers. Above all, an outside perspective helps distinguish between what truly protects the business and what merely adds unnecessary complexity to the project.
FAQ on NIS2 and Service Providers
Does a very small business with fewer than 50 employees have to be registered with NIS2?
Generally speaking, no, except in specific cases related to its business or to a future national regulation. However, it may be required to meet contractual requirements if it supplies an essential or significant entity.
Can a customer require its supplier to comply with NIS2 provisions?
Yes, within the limits of the contract and the actual scope of services. It is better to agree to specific commitments regarding security measures, evidence, and alert timelines rather than a general promise of compliance.
What documents should you prepare to complete a NIS2 supplier questionnaire?
Prepare a 2- to 5-page security fact sheet covering: hosting, backups, MFA, access management, updates, third-party service providers, and incident reporting. Include a few simple, dated pieces of evidence.
Does NIS2 replace the GDPR for data processors?
No. The GDPR primarily deals with personal data, while NIS2 focuses on cybersecurity and service continuity. The two complement each other when a service provider handles customer or user data.