forumNew topic

Major client says we fall under NIS2: What is NIS2, does it really apply to an SME in France?

HHavva Ö***MemberCommunity member
Joined
Aug 2025
Message
25
#1

We are a logistics software and data integration company with 22 employees based in Lille, France. We provide an order-tracking module to one of the leading retail and transport chains in France. Yesterday, we received an official letter from our client's procurement and risk management department. The letter stated that, under the European Union's NIS2 directive, we are in scope directly or as a critical supplier, and therefore we will very soon be subject to a comprehensive cybersecurity audit and mandatory certification processes.

The form they attached includes requirements that would require hundreds of thousands of euros in investment ranging from a 24/7 security operations center to digital forensics procedures. Our annual turnover is around 1.8 million EUR. As far as I know, this directive excluded small businesses.

What actually is NIS2, and can it legally be applied directly to a business like ours? Or is our major client trying to offload its own legal responsibilities onto us through the supply chain? How should we clarify the situation before panicking and buying expensive consulting services?

EEmre G***MemberCommunity member
Joined
Dec 2022
Message
198
Most Helpful#2

Short answer: As a general rule, the NIS2 directive directly excludes SMEs with fewer than 50 employees or an annual turnover under 10 million EUR from its legal scope; therefore, your company is not a NIS2 entity directly subject to legal penalties. However, because the directive obligates in-scope major companies to secure their supply chains, your client is passing these requirements on to you via contract.

Follow these steps to manage the situation: 1) Clarify your legal status; with 22 employees and 1.8 million EUR turnover, you fit the micro/small enterprise definition. Be aware that you are not subject to direct government oversight. 2) The form sent by your client is merely a supplier template reflecting the rules they themselves have to comply with. 3) Define the boundaries of the service you provide; does your software have direct and unrestricted access to their main network, or does it communicate via an isolated API?

There is no need to spend thousands of euros on expensive consulting firms or certification processes. In your official response to the client, you are expected to state that you do not fall directly under the regulation and present the reasonable measures you already take within a supplier security framework (access logs, multi-factor authentication, encrypted data transmission, and redundancy).

ANSSI, which oversees the implementation of the regulation in France, also emphasizes that small suppliers should not be overwhelmed with disproportionate costs and that risk-based, proportionate measures are sufficient. Therefore, insist on contract terms tailored to your actual risk level during negotiations.

LLeventVeteran
Job title
Digital transformation consultant
Organization type
two-branch business
Joined
Jul 2023
Message
208
#3

Corporate legal departments just copy-paste and blast these documents to everyone to cover their own backs. Stay calm, sit down at the table, and narrow the scope by telling them, 'We are not part of your critical infrastructure, we are an isolated software vendor.'

BBurcu E***Member
Job title
Data Analyst
Sector
Jewelry
Organization type
300-person organization
Joined
Jul 2023
Message
246
#4

We got a similar letter 3 months ago from a client in the energy sector. Initially, they demanded a 60-item audit. We sat down, talked it out, and brought it down to 8 items just by proving database access logs and two-factor auth, without spending an extra dime.

FFatih G***Member
Job title
Production planning
Sector
IT services
Organization type
medium-sized business
Joined
Nov 2024
Message
31
#5

How exactly are you connected to your client's system? If you have permanent, unrestricted access to their servers via a direct VPN, their concern is understandable. Is the connection strictly via a one-way API, or are you inside the network?

note: I wrote this based on my own experience, it might not apply to everyone.

TTarkanMember
Job title
Retail manager
Joined
Mar 2024
Message
104
#6

Put together a security summary right away: internal two-factor authentication, backup frequency, and basic security training for staff. Send that to the client's risk department and say, 'This is our security profile at SME scale.'

KKaan Y***Member
Job title
Social media manager
Sector
Furniture manufacturing
Organization type
two-branch business
Joined
Jun 2025
Message
84
#7

Lately there are opportunistic consultants popping up everywhere trying to bill small firms 20-30k euros under the name of 'NIS2 compliance consulting'. Absolutely do not sign anything, the regulation cannot directly fine SMEs.

DDeniz K***MemberCommunity member
Joined
Nov 2025
Message
21
#8

Article 2 of the EU directive clearly defines the enterprise size thresholds. In the official letter you send your client, it is in your best interest to put on record, in legal language, that you have no direct obligations by citing the European Commission's SME definition.

EEbru K***Member
Job title
System administrator
Sector
Healthcare services
Organization type
early-stage startup
Joined
Jun 2024
Message
28
#9

our client hit us with the exact same panic, the second companies hear nis2 they try to dump the whole burden on the supplier. keep the communication calm, once you show basic controls the matter usually goes away.

EElif P***New member
Job title
Quality control inspector
Sector
Energy
Organization type
a company within a holding
Joined
Jul 2026
Message
130
#10

Timely topic. An untested backup is not a backup.

Having backups accessible on the same network and with the same identity makes them part of the target. If you post the result here, it will help others too.

MMert P***Expert
Job title
Front office accounting
Sector
Energy
Organization type
regional distributor
Joined
Sep 2022
Message
204
#11

I agree with this. When making a decision, first look at what data you have on hand.

HHatice Ş***Member
Job title
Human Resources Specialist
Sector
IT services
Organization type
early-stage startup
Joined
Sep 2025
Message
123
#12

We need to make a distinction here. Everyone rushing into what is nis2 gets stuck at the same point.

Taking measures without an inventory leaves doors you haven't seen open. Correct me if I'm wrong.

HHasan A***Expert
Job title
Customer service representative
Sector
Accounting & advisory
Organization type
family business
Joined
Nov 2025
Message
102
#13

If you're going this route, sort this out first. Payment information changes are never verified through the channel they came from.

Payment information changes are never verified through the channel they came from. If I were you Id go this route.

NNevinMember
Job title
Language school
Joined
Apr 2024
Message
92
#14

Yes, that's exactly how it is with what is nis2. Start with a small trial; don't commit to everything at once.

If you don't write this down from the start, it leads to arguments later. If you have questions, write them; I'll answer as best I can.

MMelis A***Member
Job title
Operations manager
Sector
Plastic
Organization type
120-person company
Joined
Feb 2023
Message
94
#15

the discussion got scattered let me summarize.. but forgotten test enviornments are more often the entry point than live systems.

if you don't write this down from the starrt it leads to arguments later but proven by experience.

OOkan B***MemberCommunity member
Joined
Dec 2025
Message
134
#16

You're right... Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

ZZehra Y***Member
Job title
Marketing manager
Sector
Furniture manufacturing
Organization type
20-person company
Joined
May 2024
Message
324
#17

Let me summarize what's been said so far. Just because everyone does it doesn't mean it's right.

If its your first time start small; scaling comes later.

KKader C***Member
Job title
Studio Founder
Sector
Insurance
Organization type
chain store
Joined
May 2023
Message
166
#18

I feel the same way. Forgotten test environments are more often the entry point than live systems.

If permission and scope aren't in writing, don't start that test.

DDeniz B***Expert
Job title
Administrative manager
Sector
Jewelry
Organization type
family business
Joined
Jul 2024
Message
6
#19

Noted, thanks. Don't rely on a single measure; go layer by layer.

The harder it is to reverse a decision, the slower you should make it. If you post the result here, it will help others too.

KKadir G***MemberCommunity member
Joined
Sep 2022
Message
44
#20

We got stuck at the same point for a while. The biggest time-waster for us was not knowing who had the final say.

An automated scan report is not the same as a penetration test. Just leaving this note it might be useful.

Reply