Mahope tools: EUComply Clean Copy DeskUptime Transmute BugBottle All tools
FREE PREVIEW · E-BOOK

NIS2 Compliance for Small Web Agencies

A Practical Guide to Meeting EU Cybersecurity Requirements Without a Compliance Team

NIS2 Compliance for Small Web Agencies — book cover

About the book, chapter list and the free EPUB download →

Foreword

If you run a small web agency in the EU, this guide is for you.

NIS2 (the EU's Network and Information Security Directive 2) became enforceable in 2025. Unlike the original NIS directive, NIS2 casts a much wider net — it covers more sectors, more company sizes, and imposes stricter requirements. Most significantly for you: digital service providers, managed service providers, and their subcontractors are explicitly in scope.

This is not a legal document. It is a practical field guide written by someone who works with agencies like yours. Every recommendation has been tested with real agencies. You will not find abstract theory here — only what works.

Let's get you compliant.

Chapter 1: Does NIS2 Apply to Your Agency?

This is the first question, and it's the one most agencies get wrong. Many assume they are too small to be in scope. Under NIS2, that assumption can be costly.

The Scope Test

NIS2 applies to medium-sized and large enterprises in covered sectors. The size thresholds are:

  • Large enterprise: 250+ employees OR €50M+ annual turnover AND €43M+ balance sheet
  • Medium enterprise: 50–249 employees OR €10M–€50M turnover
  • Small enterprise: Below 50 employees AND below €10M turnover

Good news: If your agency has fewer than 50 employees and less than €10M annual turnover, you are a "small enterprise" and generally NOT directly in scope for NIS2.

Bad news: You still need to read this guide. Here's why.

Why Small Agencies Must Still Comply

  1. Your clients are in scope. If you serve medium or large enterprises that ARE subject to NIS2, they must assess their supply chain — and that includes you.
  2. Contractual requirements. Enterprise clients are already adding NIS2 clauses to their vendor contracts.
  3. Downstream liability. Under NIS2 Article 21(2)(c) on supply chain security, your clients are required to assess the security practices of their suppliers.
  4. Competitive disadvantage. Agencies that can demonstrate NIS2 alignment win more pitches.

Quick Self-Assessment

Answer these three questions:

  1. Do any of your clients have more than 50 employees? → If yes, they are likely in NIS2 scope.
  2. Do you handle any of the following for clients: hosting, server management, DNS, email infrastructure, SSL/certificate management, backup services, or security monitoring? → If yes, you are a digital service provider in their supply chain.
  3. Do you have access to your clients' networks, data, or administrative systems? → If yes, you are a vector they must secure.

If you answered yes to any of the above, you need to be NIS2-ready — even if the directive does not name you directly.

That was the beginning

The complete book continues with seven chapters and three appendices: the 10 essential security measures, incident reporting, supply chain security, contract clauses, and a 30-day compliance checklist.

Download the full EPUB — free

NIS2 readiness is mostly documentation, and the technical baseline checks in this book are the ones a scanner takes off your hands. EUComply Pro checks a whole site for you and writes a client-ready report — $79 per website per year.

No account, no email, no payment. See all six free e-books.