Energy Renovation CRM
Custom online CRM Business website E-commerce website Web Design UX / UI Branding SEO / SEA Social media
Artificial intelligence Our work Blog Contact Request a quote
Home Blog NIS2 SMEs 2026

NIS2: How the EU cyber directive changes things for SMEs in 2026

The NIS2 directive significantly expands cybersecurity obligations across Europe. Many French SMEs are affected, often unknowingly, through security requirements imposed by their clients. Here's how to assess your situation and get prepared.

NIS2: How the EU cyber directive changes things for SMEs in 2026

What is the NIS2 directive and why is 2026 decisive?

NIS2 is the EU directive 2022/2555 on cybersecurity, replacing and broadening the original NIS directive. It aims to raise security standards across numerous organizations in Europe, spanning sectors from healthcare to digital services, energy, transport, manufacturing, and waste management.

France's transposition occurred in 2024-2025 through legislation on critical infrastructure resilience and cybersecurity strengthening. Precise calibration of obligations, sectors, and thresholds depends on implementing decrees expected through 2025-2026, making this period critical for compliance.

Important: Exact thresholds, decree timelines, and penalty amounts should be verified through official sources (ANSSI, Légifrance) before any decision, as they continue to be clarified.

Am I affected by NIS2 as an SME?

NIS2 distinguishes two categories: 'essential' and 'important' entities. The latter includes many SMEs and mid-market companies, especially those operating in covered sectors or forming part of the supply chain of a NIS2-subject entity.

In practice, many SMEs discover their exposure not directly, but through contractual clauses imposed by their customers: large groups or public administrations subject to NIS2 that cascade security requirements to their suppliers.

Concretely, you are likely affected if you match one of these scenarios:

  • You operate in a NIS2-covered sector and exceed certain size or revenue thresholds.
  • You are a subcontractor or supplier to a large group or public administration subject to the directive.
  • Your contracts now include security clauses, audit requests, or proof of system hardening.

What concrete obligations and what penalties?

NIS2 imposes risk management measures and incident notification obligations, proportionate yet demanding for both entity categories. This covers access management, updates, backups, monitoring, and incident reporting.

The EU text provides for financial penalties potentially reaching high amounts for essential entities (up to 10 million euros or 2% of global revenue under applicable provisions), with lower but still significant levels for important entities. These amounts should be confirmed in the official text and national transposition.

ANSSI is France's designated national authority for supporting and overseeing NIS2 compliance.

  • Expected technical measures: MFA, access management, regular updates.
  • Tested backups and verified recovery, stored off-site.
  • Server hardening and monitoring enabling incident detection and reporting.

Why are servers and hosting environments your priority security focus?

Cybersecurity reports (ANSSI, CERT-FR, vendors) consistently document the same entry vectors year after year: poorly hardened shared hosting and VPS environments, outdated cPanel or Plesk panels, absent off-site backups, and weak passwords. These vulnerabilities disproportionately target under-resourced SMEs.

Meanwhile, ransomware and phishing campaigns maintain pressure, and insurers now condition cyber coverage on minimum measures: MFA, tested backups, hardened servers.

Securing your servers and applications is therefore not just a compliance checkbox—it's your best defense against threats that won't wait for decrees to be finalized.

  • Outdated cPanel / Plesk panels.
  • Missing externalized and tested backups.
  • Poor access segregation, weak passwords, absent MFA.
  • Insufficient monitoring to detect incidents in time.

How to achieve NIS2 compliance by 2026 (and gain competitive advantage)?

NIS2 compliance requires concrete evidence: not just intentions, but documented technical hardening and the ability to detect and report incidents. This is exactly where JD Solutions audits, hardens, and monitors your servers (VPS, cPanel, Plesk) and secures your business applications and hosting environments.

For an SME subcontracting to a large group or public administration, presenting a security audit and a documented hardening plan becomes a sales argument as much as a regulatory response. The compliance requirement transforms into competitive advantage for winning or retaining contracts.

A pragmatic approach starts with current assets, prioritizes high-impact vulnerabilities, and delivers professional deliverables for your customers.

  • Conduct a security audit of your servers and applications.
  • Create a prioritized and documented hardening plan.
  • Implement tested backups, MFA, and incident monitoring.
  • Maintain evidence you can present to customers and insurers.

Go further

To transform NIS2 obligations into concrete evidence, these services directly address hardening and monitoring requirements:

  • securing your servers — Documented audit and hardening of your VPS, cPanel and Plesk—the concrete foundation of NIS2 compliance.
  • secure business applications — Protect your applications and hosting environments handling sensitive data required by your customers.

Frequently asked questions

Is a small SME really affected by NIS2?

It depends on sector, size, and especially position in the supply chain. Many SMEs are indirectly affected when a NIS2-subject customer imposes security clauses on them. Check exact thresholds on official ANSSI and Légifrance sources.

What is the difference between an essential and important entity?

NIS2 creates two categories with proportionate but demanding obligations in both cases. Essential entities face stricter oversight and heavier penalties, while important entities, including many SMEs and mid-market companies, remain subject to real security and notification requirements.

What are the penalties for NIS2 non-compliance?

The text provides for financial penalties potentially reaching high amounts for essential entities and lower but still significant levels for important entities. Beyond fines, the major risk for an SME is losing contracts due to inability to prove compliance. Exact amounts should be confirmed in the official text.

Where do I start preparing for NIS2?

Begin with an audit of your servers and applications to identify priority vulnerabilities, then establish a documented hardening plan covering access, updates, tested backups, and monitoring. These deliverables serve both as compliance proof and sales arguments with your customers.

Who is the reference authority for NIS2 in France?

ANSSI is designated as France's national authority for supporting and overseeing NIS2 compliance among French entities. Its website ssi.gouv.fr publishes official information on sectors, thresholds, and obligations as implementing decrees are finalized.

Related reading

Similar articles

Are Your Servers Really Secure?Security

Are Your Servers Really Secure?

VPS, cPanel or Plesk: review your hosting security and adopt the right habits.

Read the article
cPanel 2026 Flaw: Are You Exposed?Security

cPanel 2026 Flaw: Are You Exposed?

cPanel 2026 flaw: over a million sites potentially at risk. How to check your exposure and respond with a concrete 5-step action plan.

Read the article
Multi-Network Automation 2026Marketing

Multi-Network Automation 2026

How to automate your Facebook, Instagram and LinkedIn posts in 2026: compliance, lead quality and a multi-network flow with Farsem.net.

Read the article
A CRM or digital project?

Let’s talk about your needs

Leave your details and a JD Solutions specialist will call you back shortly.

Get a call back

Share your details — we’ll take care of the rest.

Please enter your name.

Please enter a valid number.

Anti-bot — type the correct answer, then click “Send”

Wrong answer, please try again.

Got it — thank you!

A JD Solutions specialist will get back to you very soon.

Ready for a faster, leaner and more persuasive website?

Let's talk about your project