NIS2 Compliance

NIS2 Compliance Checklist for UK SMEs: What You Actually Need in 2026

By Piotr Kleszcz, Fifth Ace 7 min read Updated July 2026

If you run a business with 10 to 100 employees and work with EU clients, partners, or suppliers — NIS2 may already apply to you. And if you're not compliant, the penalties are significant: up to €10 million or 2% of global annual turnover.

This checklist cuts through the noise. No legal jargon. No corporate frameworks. Just what a small or medium business actually needs to implement to meet NIS2 Article 21 requirements.

Important: NIS2 does not issue a compliance certificate. Your obligation is to implement the required controls and be able to demonstrate them to a regulator or client on request. That's exactly what a structured audit delivers.

Who Does NIS2 Apply To?

NIS2 applies to organisations in specific sectors that meet size thresholds:

CategoryEmployeesTurnoverExamples
Essential250+>€50MEnergy, transport, healthcare
Important50–249€10M–€50MIT services, manufacturing, digital providers
Supply chainAny sizeAnySuppliers to essential/important entities

Even if your business falls below the thresholds, your enterprise clients may contractually require NIS2 compliance from their suppliers. This is increasingly common in UK and EU procurement.

The NIS2 Article 21 Checklist

Article 21 defines ten security measures that organisations must implement. Here's what each one means in practice for a small business:

✦ NIS2 Article 21 — 10 Required Controls

01
Risk Management Policy — A documented process for identifying, assessing, and treating cybersecurity risks. Updated at least annually.
02
Incident Handling Procedure — A written plan for detecting, responding to, and reporting incidents. Significant incidents must be reported to the relevant authority within 24 hours.
03
Business Continuity & Disaster Recovery — Documented backup procedures, recovery time objectives, and a tested restoration process.
04
Supply Chain Security — Assess the cybersecurity posture of your key suppliers and document the process. Ask them about their controls.
05
Network & Systems Security — Firewall configuration, network segmentation, and access controls on critical systems.
06
Vulnerability Management — Regular vulnerability scans, a patching schedule, and evidence of remediation. Penetration testing recommended annually.
07
Access Control & MFA — Least-privilege access, role-based permissions, and multi-factor authentication on all critical systems and remote access.
08
Encryption — Data encrypted at rest and in transit. TLS on all web services. Encrypted backups.
09
Security Awareness Training — Annual training for all staff covering phishing, password hygiene, and incident reporting. Document attendance.
10
Board-Level Accountability — Senior management must approve the security policy and can be held personally liable for non-compliance.

Where Most SMEs Fall Short

Based on our audits of small and medium businesses, these are the most common gaps:

How Long Does NIS2 Compliance Take?

For a business starting from scratch, a realistic timeline looks like this:

PhaseActivityTimeline
Gap AnalysisAudit current posture against all 10 controls1–2 weeks
DocumentationWrite policies, procedures, risk register2–4 weeks
Technical ControlsImplement MFA, firewall rules, encryption, backups2–6 weeks
TrainingStaff awareness session and documentation1 week
MaintenanceQuarterly reviews, ongoing monitoringOngoing

Next Steps

The fastest way to understand your current NIS2 posture is a structured gap analysis. This maps your existing controls against all Article 21 requirements and produces a prioritised remediation plan.

At Fifth Ace, our NIS2 Business Audit delivers exactly that — a complete gap analysis, executive report, and remediation roadmap, designed specifically for businesses with 10 to 100 employees.

Ready to find out where you stand?

Our NIS2 Business Audit gives you a complete picture of your compliance posture — with a clear plan to fix what's missing. Fixed price. No surprises.

Book Your NIS2 Audit — £799 →

Download our free NIS2 Readiness Checklist

Not ready to book an audit yet? Take our free 5-minute self-assessment and get the PDF checklist straight to your inbox.

Download our free NIS2 Readiness Checklist →