A practical guide for 2026 — what the directive actually means for agencies with 1–50 employees, and exactly what to do about it.
Updated August 2026 · Reading time: 8 minutes
The EU's Network and Information Security Directive 2 (NIS2) came into force in 2025, replacing the original NIS directive from 2016. The headline change: it covers more sectors, applies to smaller entities, and imposes stricter supply chain requirements. For the first time, digital service providers — including hosting companies, managed service providers, and their subcontractors — are explicitly in scope.
If your web agency designs, builds, hosts, or maintains websites for EU clients, you are part of that supply chain. And while your agency itself may be below the direct NIS2 size threshold (50+ employees or €10M+ turnover), your clients may well be above it. That changes the conversation.
Medium+ enterprises (50+ employees) in covered sectors must comply. Your agency is likely below this threshold — but your clients aren't.
NIS2 Article 21(2)(c) requires in-scope entities to assess their suppliers. If you build their site, host their data, or manage their infrastructure, you will be assessed.
Enterprise procurement teams now include NIS2 clauses in vendor contracts. Without documented security practices, you will be disqualified in the first round.
Three questions. If you answer yes to any, you need to be NIS2-ready.
Do any of your clients have more than 50 employees?
Do you handle hosting, server management, DNS, email infrastructure, backups, or security monitoring for any client?
Do you have access to your clients' networks, data, or administrative systems?
If you answered yes to any question, the rest of this guide is for you. If you answered no to all three, bookmark this page — the question will change as your agency grows.
This plan assumes you have 1–10 employees and no existing security documentation. Each step takes one afternoon. By day 30 you will have a defensible compliance framework that satisfies most client procurement questionnaires.
One page. Cover acceptable use, password requirements, device security, remote work rules, and data handling. Use it as the foundation document for all other steps. Store it where all team members can access it. Review it annually.
Time: 2 hours. Template: the NIS2 e-book includes a fill-in policy template.
Multi-factor authentication should be mandatory on every admin account: email, hosting panels, DNS providers, WordPress admin, cloud services. Use a password manager (Bitwarden is free for up to 2 users) and never share passwords via email or chat.
Time: 1 hour setup + ongoing habit.
Three copies of client data, on two different media types, with one copy offsite. For client WordPress sites, use UpdraftPlus or BlogVault with automated daily backups to cloud storage. Test restoration quarterly — a backup you can't restore has no value.
Time: 2 hours to set up, 30 minutes per quarter to test.
This is the single document your clients care about most. Create a 2-page PDF answering the 10 questions enterprise procurement teams ask (security policy, backups, access controls, incident handling, sub-processors, certifications, password policy, data residency). Share it proactively in pitches — it signals professionalism before they ask.
Time: 3 hours to write, then annual updates.
Every client contract should include: security obligations clause, incident notification clause (24-hour early warning), subcontractor security clause, data processing clause, and compliance verification clause. These protect both you and your client. The NIS2 e-book contains 5 ready-to-use clauses you can paste directly.
Time: 1 hour to update your contract template.
Run an automated vulnerability scan on your infrastructure. For WordPress agencies, run WPScan or Wordfence. For server infrastructure, use HackerTarget (free tier). Document the results, fix any critical issues, and schedule quarterly re-scans. Keep the reports — they are evidence of due diligence.
Time: 2 hours for first scan, 1 hour per quarter.
NIS2 requires a documented incident response process. A single page with six steps suffices: Detect → Triage → Contain → Eradicate → Recover → Review. Include contact details for your security lead, backup contact, and IT emergency number. Distribute to the team and review twice a year.
Time: 1 hour to write, 30 minutes per semi-annual review.
This guide covers the essentials. The full NIS2 Compliance for Small Web Agencies e-book goes deeper into every step — with complete template policies, 5 contract clauses you can paste directly, a 30-day day-by-day checklist, vendor security profile template, and incident report templates. Written for agencies with 1–50 employees. Available on Amazon Kindle.
Not for direct NIS2 compliance — the directive's size threshold starts at 50 employees. But if you serve clients who are above that threshold, they will ask. Agencies that can demonstrate security alignment win more pitches than those that can't. The documentation takes two afternoons and pays for itself in the first deal it saves.
Four documents: (1) Information Security Policy (1 page), (2) Incident Response Plan (1 page), (3) Vendor Security Profile (2 pages), (4) Contract clauses in your client agreement. The NIS2 e-book includes all of these as templates.
Security policy: annual. Incident response plan: semi-annual review. Vendor profile: annual (or when something changes). This is not a heavy maintenance burden — you can schedule everything on a single day in January and July.
You won't face direct NIS2 fines. But you will increasingly lose client contracts as enterprise procurement adds NIS2 requirements. More immediately: professional indemnity insurers now ask for documented security practices. Without them, you may pay higher premiums or be denied coverage.
Yes — that's the point. Your Vendor Security Profile is designed to share. Your Information Security Policy and Incident Response Plan are internal, but you can share excerpts as evidence. If a client asks for a full copy of your security policy, that's a reasonable request under most procurement frameworks.