So the scope checker said you’re out of NIS2 — a small or micro enterprise, or in a sector the Directive doesn’t cover. That means one regulator won’t fine you under NIS2. It does not mean your cyber risk went away. Attackers don’t read the Annexes, GDPR still applies to you in full, and your enterprise customers are now contractually obliged to police your security. Here’s why quantifying your exposure still matters when NIS2 doesn’t apply — and what actually changes for you.

The one-line version

NIS2 scope is about societal criticality — who the state needs to keep the lights on. Your financial risk is a different question entirely, and for most out-of-scope companies it’s the one that actually costs money.

1. “Out of scope” is a regulatory label, not a safety rating

NIS2 draws its line where a cyber incident would ripple out to society — energy, health, transport, finance. It deliberately excludes most micro and small enterprises because the Directive is about systemic resilience, not individual company safety. Your attacker uses the opposite logic: they don’t target you because you’re critical, they target you because you’re reachable and likely to pay. Ransomware crews and access-brokers overwhelmingly hit small and mid-sized firms precisely because they assume — often correctly — that the defences are thinner.

Being out of NIS2 changes who can fine you. It changes nothing about your probability of being breached.

2. GDPR doesn’t care how small you are

This is the liability most out-of-scope companies forget. The GDPR applies to any organisation that processes personal data — customers, employees, leads — with no size threshold at all. A personal-data breach can cost you the greater of €20 million or 4% of global annual turnover, plus notification duties, plus the clean-up. Where NIS2 governs availability and resilience for the few, GDPR governs confidentiality of personal data for everyone. If you hold customer records, you already have a quantifiable regulatory exposure — NIS2 or not. We break the numbers down in NIS2 fines & penalties.

3. NIS2 reaches you through your customers anyway

Even if the Directive doesn’t bind you directly, Article 21 forces every in-scope enterprise to secure its supply chain — to assess and manage the cyber risk of its direct suppliers and service providers. So the moment you sell to a mid-market or enterprise customer that is in scope, their compliance becomes your problem: security questionnaires, evidence requests, contractual security clauses, audit rights. A supplier who can’t demonstrate its posture is now a liability their procurement team is obliged to manage — and increasingly, to drop. We cover this pull-through in why mid-market suppliers are losing enterprise contracts under NIS2.

Turned around, that’s an opportunity: a small supplier who can prove a quantified, well-managed risk posture wins the deals that competitors lose on the security review.

4. The financial loss is real — and often heavier, proportionally

A week of downtime, a ransom demand, incident-response fees, lost revenue and breach notification don’t scale down neatly with headcount. For a lean company, a single ransomware event can be an extinction-level cost, while the same incident is a line item for a large enterprise. And the dominant path in for smaller, SaaS-only, or cloud-native firms usually isn’t an exposed, scannable server at all — it’s a stolen credential or an unprotected remote-access account, the invisible vector that doesn’t show up in a perimeter scan but still ends in encryption and extortion.

5. Insurers and customers are asking the same question

Cyber-insurance underwriting now hinges on demonstrable controls — MFA, EDR, backups, access management. A defensible, euro-denominated view of your own risk helps you buy the right cover, negotiate the premium, and answer the customer security review with evidence instead of adjectives. “We take security seriously” loses deals; “here is our modelled annual loss exposure and the controls that reduce it” wins them.

What Nisura actually does for an out-of-scope company

  • Puts a number on it. Translates your external exposure into a projected Expected Annual Loss in euros — not a red/amber/green heatmap.
  • Maps your real liability. Shows the regimes that do bind you — GDPR always, DORA if you’re a financial entity — with their statutory exposure, even when NIS2 doesn’t apply.
  • Gives you evidence. A defensible figure you can take to the board, your insurer, and your customers’ procurement teams.

Honest scope note: Nisura quantifies financial exposure and maps EU regulatory liability. It isn’t a NIS2 certification, and being out of scope is a genuinely good outcome — this is about the risk that remains, not manufacturing one that doesn’t.

So what should you actually do?

Confirm the verdict, then measure what’s left. If you haven’t run it yet, the NIS2 Scope Checker tells you exactly which regimes bind you (GDPR and possibly DORA will still be on the list). Then run a free CRQ simulation to see your projected annual loss in euros and the GDPR liability behind it — the number that matters whether or not a regulator is watching.

Sources & official references