GDPR and NIS2, for an SME established in the Union.
The GDPR has applied since 2018. NIS2 has been in force at European level since October 2024 and is being transposed state by state, widening the scope considerably.
The point to retain is not the size of the fines, it is that security oversight becomes a personal, non-delegable obligation of the director. That is a shift of responsibility, not one more technical constraint. The detailed rules vary between member states; the substance does not.
What the law requires
- Approval of the security measures by the board itself.
- Training of the director on security risks.
- Securing the supply chain, suppliers included.
- Reporting an incident within 24 hours, then a report within 72 hours.
What it does not require
- Nothing for companies under fifty staff, save sector exceptions.
- No tool or provider imposed.
- No mandatory certification at this stage of the transposition.
The facts, in short
| GDPR fine | 4% of global turnover |
| NIS2 fine | 2% of global turnover |
| Notification | 24 h then 72 h |
| Director | mandatory training |
Thresholds and deadlines come from the directive; supervision arrangements are set by each member state.
Where do you stand?
Three questions, immediate answer, no email address.
Answer the three questions to see what applies to your situation.
The guides in this section
The guides in this section are being written.
Would you rather we handled it?
The compliance review does this sorting for you, in thirty minutes, and you leave with the written list of your gaps, ranked by severity.
Request a review