⚙️ Technical

NIS2 and your online store: are you in scope?

Let us start with the conclusion, to spare you three paragraphs of introduction: most online stores are not covered by NIS2. A regular store that sells its own goods in its own name is, as a rule, not an online marketplace, and is not in scope on that ground. If you recently took a call telling you to implement NIS2 within weeks or face a fine of 10 million euros, you were most likely talking to somebody selling fear rather than a service.

9 min read

There is, however, a minority for whom this is very real, and exceptions that are easy to miss inside your own company. This text should let you work out in five minutes which side you are on, and show the part that applies to stores outside the scope too. One disclaimer up front, repeated below: this is not legal advice.

What actually changed, and which dates matter

NIS2 is Directive (EU) 2022/2555. Member States had until 17 October 2024 to transpose it into national law. A directive does not bind your company directly: what binds you is the national act implementing it in the country where your company is established.

That is where the picture stops being uniform. The state of implementation and the registration deadlines differ from one Member State to another: some countries adopted their implementing law on time, others are late. Which register exists, who runs it, by when entities in scope must register and which authority supervises them are decided nationally. So before you accept any date quoted in a sales call, check the rules of the country where your company has its seat, and of every market where you have a local company.

Who the directive covers

As a rule, NIS2 covers medium and large entities, and in selected situations entities regardless of their size. The size of your company settles nothing on its own until you have checked whether you run an activity from the list of sectors.

Covered activities include, among others: online marketplaces, ICT service management, wholesale distribution of food, manufacture and distribution of chemicals, postal and courier services, waste and wastewater management, space, and research. Entities are split into essential and important ones, and that split determines the maximum level of a fine.

Several items on that list sound unconnected to selling online, yet sit inside the very company that runs the store. Wholesale food distribution and courier services are the most frequent surprises.

An online store is not the same thing as an online marketplace

This is the heart of the whole text, so we will put it plainly. An online marketplace matches sellers with buyers: it provides the infrastructure on which a transaction is concluded between two other parties, and the operator is an intermediary. An online store sells in its own name: you are the seller, you issue the sales document, you answer for the goods.

That is why a regular store selling its own goods is not an online marketplace and, as a rule, is not in scope on that ground. The criterion is the type of activity, not the platform and not the size of the basket.

There are, however, three situations in which the answer changes.

The first: a marketplace inside your own store. If you have let external sellers list their own assortment with you and conclude the contract directly with the buyer, you have stopped being only a shop. This is the most common scenario in which growing the offer quietly changes the status of the business.

The second: another type of activity inside the same company. If the same legal entity also runs wholesale food distribution, it may be in scope on that ground rather than because of the shop.

The third: capital links with an entity in scope. If your company is part of a larger structure, the answer is not decided at the level of the shop alone.

The five question test

Answer five questions. This is not a legal opinion and does not replace a lawyer, it is a tool for sorting your situation before that conversation.

  1. Do external sellers also sell inside my store, concluding the contract directly with the buyer?
  2. Does the same company run an activity from the list of sectors, for example wholesale food distribution, manufacture or distribution of chemicals, postal or courier services, ICT service management?
  3. Is my company linked by capital to an entity that is itself in scope?
  4. Is my company a medium or large entity?
  5. Have I already received a letter from a business partner, a bank or an insurer that refers to NIS2 and asks about my status?

If your answer to questions one to three is no, and the company is neither medium nor large, you are probably not in scope. If any of them is a yes and you are at the same time a medium or large entity, treat that as a signal that you are probably in scope and that a lawyer is needed urgently, because the national registration deadline may already be running. If the answers are ambiguous, for example the size threshold is borderline, that is the third outcome: I need a lawyer to confirm this. Where there is doubt, a lawyer decides, not the agency that maintains the store.

What an entity in scope actually does

If the test came out as "I am in scope", the duties look roughly like this. First, registration, in the form and deadline set by the law of your country. Second, risk management, a documented approach to what can go wrong and what you do about it. Third, reporting of significant incidents: an early warning within 24 hours of detection, a full notification within 72 hours, a final report within one month. Fourth, supply chain security: who you let into your systems.

Look at what those deadlines mean in practice. Reporting within 24 hours requires that somebody detected the incident and wrote down the hour. Without a ticket register with dates you cannot do that credibly, which is exactly the area we described in the text on the most common failures of online stores.

Fines, the number everybody quotes

For essential entities the fine reaches up to 10 million euros or 2% of annual worldwide turnover. For important entities, up to 7 million euros or 1.4%. Those brackets come from the directive itself.

And the honest part you rarely hear in a sales conversation: these are ceilings, not standard amounts, they apply to entities actually in scope, and procedure and supervision are national. Quoted at a store outside the scope, the ten million figure simply is not about that store.

The part that applies to EVERY store, including those out of scope

Here is the real reason to read this even after the answer "I am not in scope". Supply chain security works in both directions. If your B2B customer, your distributor or your large business partner is an entity in scope, they answer for the security of their suppliers. And you are one of their suppliers.

In practice they will ask for specifics: a register of suppliers and subcontractors, contracts with security clauses, an incident reporting procedure on your side, proof that updates are applied and how fast. That is why a store outside the scope still receives a security questionnaire. Not because the law covers the store, but because it covers the store's business partner. In our practice this is now a more frequent scenario than registration itself, and a store with nothing to show improvises.

What you can prepare as part of ordinary maintenance

The good news: most of what a questionnaire asks about is not a separate compliance project, but documentation that should exist anyway while the store is maintained. At our end it looks like this.

A register of suppliers and integrations: who has access, which integrations are plugged in, who is responsible. Updates with a deadline: critical ones within 72 hours, the rest within 14 days, on a test environment first, with a record of what was deployed and when. That is our own service standard, not a statutory deadline, and should not be confused with the incident reporting deadline. Backups with a restore test once a quarter: a backup without a test is a declaration, not a safeguard. Classification and a ticket register with dates, so it is possible to reconstruct when something was detected and what followed. A post incident note showing that somebody established the cause instead of merely bringing the store back up.

We will put this bluntly, because it is the line running through our whole knowledge base: this is not statutory compliance and we do not sell NIS2 compliance. It is technical documentation that compliance needs, that a partner's questionnaire needs as well, and that most stores do not have. How such clauses look in a contract we described in the text on the SLA agreement for an online store, and cost ranges in the text on how much it costs to maintain an online store.

If the test came out as "I am not in scope", do not buy a NIS2 implementation. If you want documentation you can show a partner without improvising, we will review it during ordinary maintenance: a register of access and integrations, update deadlines, a backup restore test, a ticket register. Details on /en/sla-help-desk.

Tags: #NIS2 #cyberbezpieczeństwo #zgodność #utrzymanie sklepu #łańcuch dostaw
Share: 𝕏 in f

Stay up to date

New articles about e-commerce and skalowaniu

Once a week, on Fridays. No spam, no fluff. Just practical knowledge from people who have migrated stores with 10M+ PLN GMV annually.

🔒 GDPR compliant. Unsubscribe in 1 click in the footer of every email.