Glossary · Term

SME explained

SME stands for small and medium-sized enterprise. Many of them fall under NIS2 for the first time.

At a glance
Meaning
Small and medium-sized enterprises
EU definition
< 250 employees, ≤ EUR 50 million turnover
NIS2 threshold
Usually from 50 employees or EUR 10 million
Relevance to NIS2
Many SMEs in scope for the first time
Updated
June 2026
Editorial team
Compliance Compass

What is an SME?

SME stands for small and medium-sized enterprise. Under the EU definition this covers organisations with fewer than 250 employees and at most EUR 50 million in annual turnover or EUR 43 million in balance sheet total. The distinction is not merely statistical: under NIS2 the size of an organisation helps decide whether it counts as an Entity within the scope of the directive at all.

SMEs and NIS2

In regulated sectors NIS2 generally covers organisations with 50 or more employees or more than EUR 10 million in turnover and balance sheet total. The directive thus latches on to the medium size class: micro and small enterprises below that threshold are mostly left out, while medium-sized enterprises come under binding cybersecurity duties for the first time. Depending on the sector they are then classed as an important or an essential entity under the directive.

Challenge and opportunity

SMEs in particular often have no security department of their own and no dedicated resources for compliance. NIS2 looks demanding at first – but it is also a chance to tackle information security in a structured, demonstrable way and with manageable effort. One point matters: the duties apply regardless of how mature your IT is, and senior management carries responsibility for implementing them.

A pragmatic start

A lean, prioritised start makes sense: an asset inventory, a simple risk analysis, basic cyber hygiene (updates, backups, multi-factor authentication) and an emergency plan – rather than perfect full coverage straight away. For instance: An IT service provider with 70 staff and EUR 12 million in turnover finds that it is over the threshold, registers with the body designated in its own Member State and builds the basics within a few weeks, before deepening the measures step by step.

Further reading: European Commission – NIS2 Directive

Frequently asked questions

What does SME mean?

SME stands for small and medium-sized enterprise. Under the EU definition this covers organisations with fewer than 250 employees and at most EUR 50 million in annual turnover or EUR 43 million in balance sheet total. The distinction is not merely statistical: under NIS2 the size of an organisation helps decide whether it counts as an entity within the scope of the cybersecurity directive at all.

Are SMEs in scope of NIS2?

Yes, many small and medium-sized enterprises fall under NIS2 for the first time. In regulated sectors the directive usually bites from 50 employees or more than EUR 10 million in annual turnover and balance sheet total. Micro and small enterprises below that threshold are as a rule left out, while medium-sized operations come under binding cybersecurity duties as important or essential entities, depending on the sector.

How should an SME best get started?

A lean, prioritised start makes more sense than perfect full coverage straight away: first an asset inventory of all IT systems, a simple risk analysis, basic cyber hygiene such as multi-factor authentication, updates and backups, and an emergency plan. It also matters to settle the registration duty, which is governed by national law: your Member State fixes which body you sign up with, in what form and by when, and where that date has already passed the duty does not lapse.

NIS2 for SMEs

NIS2 even without an IT department of your own

Compliance Compass guides SMEs through NIS2 step by step – pragmatically, with clear direction, and in weeks rather than months.