NIS2 Compliance Checklist for UK SMEs: What You Actually Need in 2026
If you run a business with 10 to 100 employees and work with EU clients, partners, or suppliers — NIS2 may already apply to you. And if you're not compliant, the penalties are significant: up to €10 million or 2% of global annual turnover.
This checklist cuts through the noise. No legal jargon. No corporate frameworks. Just what a small or medium business actually needs to implement to meet NIS2 Article 21 requirements.
Who Does NIS2 Apply To?
NIS2 applies to organisations in specific sectors that meet size thresholds:
| Category | Employees | Turnover | Examples |
|---|---|---|---|
| Essential | 250+ | >€50M | Energy, transport, healthcare |
| Important | 50–249 | €10M–€50M | IT services, manufacturing, digital providers |
| Supply chain | Any size | Any | Suppliers to essential/important entities |
Even if your business falls below the thresholds, your enterprise clients may contractually require NIS2 compliance from their suppliers. This is increasingly common in UK and EU procurement.
The NIS2 Article 21 Checklist
Article 21 defines ten security measures that organisations must implement. Here's what each one means in practice for a small business:
✦ NIS2 Article 21 — 10 Required Controls
Where Most SMEs Fall Short
Based on our audits of small and medium businesses, these are the most common gaps:
- No documented risk assessment — most businesses manage risk informally, with nothing written down
- No incident response plan — when a breach happens, there's no process to follow
- MFA not enforced — especially on email, VPN, and remote desktop access
- No patch management process — systems running outdated software for months
- No security awareness training — employees remain the easiest attack vector
How Long Does NIS2 Compliance Take?
For a business starting from scratch, a realistic timeline looks like this:
| Phase | Activity | Timeline |
|---|---|---|
| Gap Analysis | Audit current posture against all 10 controls | 1–2 weeks |
| Documentation | Write policies, procedures, risk register | 2–4 weeks |
| Technical Controls | Implement MFA, firewall rules, encryption, backups | 2–6 weeks |
| Training | Staff awareness session and documentation | 1 week |
| Maintenance | Quarterly reviews, ongoing monitoring | Ongoing |
Next Steps
The fastest way to understand your current NIS2 posture is a structured gap analysis. This maps your existing controls against all Article 21 requirements and produces a prioritised remediation plan.
At Fifth Ace, our NIS2 Business Audit delivers exactly that — a complete gap analysis, executive report, and remediation roadmap, designed specifically for businesses with 10 to 100 employees.
Ready to find out where you stand?
Our NIS2 Business Audit gives you a complete picture of your compliance posture — with a clear plan to fix what's missing. Fixed price. No surprises.
Book Your NIS2 Audit — £799 →Download our free NIS2 Readiness Checklist
Not ready to book an audit yet? Take our free 5-minute self-assessment and get the PDF checklist straight to your inbox.
Download our free NIS2 Readiness Checklist →