NIS2 Directive: IT Security Obligations for Online Retailers
AI generated
§
2026
IT Security · NIS2 Directive · Cybersecurity · Online Retail Law
The NIS2 Directive and Your Online Shop
what IT security obligations mean for you

Few topics currently cause as much uncertainty as the EU's NIS2 Directive. Many shop owners wonder whether new obligations are suddenly heading their way, even though they have nothing to do with classic critical infrastructure. The good news first: most medium-sized and small online shops are not directly affected. Still, a calm look at the topic is worthwhile, because the underlying expectations increasingly reach shops through business partners, banks and payment providers. We explain what this is about and what you can calmly look into.

9 min read For shop owners, not legal advice Relevant if you have B2B customers or platform partners

1. What is the NIS2 Directive and what is it about?

NIS2 stands for "Network and Information Security 2" and is the short name for EU Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the European Union. A directive is not a law that automatically applies everywhere, but an EU requirement that every member state must transpose into its own national law. That is what distinguishes a directive from an EU regulation, which applies directly, without a national law in between. This is exactly the point to understand about NIS2: the actual obligations for companies only arise through the respective national transposition law, in Germany through its own law implementing the directive.

In substance, NIS2 pursues a simple basic idea: certain companies considered particularly important for the economy and society should meet a minimum level of cybersecurity. Cybersecurity here broadly means measures that protect computer systems, networks and data from attacks, outages and data loss, for example through access controls, backups or clear procedures for when something does go wrong. NIS2 replaces an older, much narrower predecessor rule that previously covered only a few sectors such as energy or water, and widens the scope to considerably more industries.

For you as an online retailer, the most important message up front is this: NIS2 is not aimed at "the internet" or "all web shops" in general, but specifically at certain types and sizes of companies. A classic shop selling physical goods is therefore not automatically covered just because it operates online. How exactly the boundary is drawn, and why the topic should still not be ignored entirely, is explained in the following sections.

2. Since when does it apply, when does it become relevant?

The NIS2 Directive has already been in force at EU level since 16 January 2023. That means: since this date, it has been clear what requirements the EU places on its member states, even though this did not yet create a direct obligation for individual companies. Member states were tasked with transposing the directive into their own national law by 17 October 2024, that is, passing a law setting out concrete obligations for affected companies.

In Germany, this transposition law, often abbreviated as the NIS2UmsuCG, has so far not entered into force on the originally planned schedule. The German transposition has been delayed, and the exact point at which it will finally take effect was not yet conclusively foreseeable at the time of writing. At first glance this sounds like good news for anyone who would prefer to postpone the topic, but that is only partly true.

Even without a finished German law, the substantive direction that NIS2 sets out already applies at EU level. Banks, larger platforms, insurers and many B2B customers are already orienting themselves around the basic ideas of NIS2 when they ask their own suppliers and partners about security measures. Anyone who believes the topic only becomes relevant once the German law is fully in force underestimates how quickly such expectations are already spreading in practice through contracts and questionnaires. So the later view on the formal legal situation changes little about the fact that the practical effects can already be felt now.

3. Who is affected, does this apply to medium-sized and small online retailers too?

NIS2 distinguishes between "important" and "essential" entities and lists specific sectors for this purpose, such as energy, transport, banking, healthcare, digital infrastructure and public administration. Within these sectors, medium and large companies are generally meant, usually with a certain minimum number of employees or a minimum annual turnover or balance sheet total. A pure online shop selling its own physical products normally does not appear on this sector list and is therefore not directly covered simply because of its business model.

The picture is different for so-called digital providers. Large online marketplaces, online search engines, cloud and hosting providers, and social networking platforms count as their own category and are explicitly covered by NIS2, provided they meet the relevant size criteria. So anyone who themselves operates a larger marketplace function on which other sellers trade, or provides a hosting or cloud offering for third parties, should take a closer look at their own classification, because here the line between "ordinary shop" and "digital provider" can blur faster than one might initially think.

For most classic medium-sized and small online retailers, the honest answer remains: you are generally not directly affected. Indirectly, however, NIS2 can still reach you, namely whenever you are a supplier or service provider to a larger company that is itself covered by NIS2. Such companies frequently pass on their own security requirements contractually to their business partners, for example in the form of security questionnaires, minimum requirements for access controls, or proof of backup routines. So even if you do not fall directly under NIS2, it is worth taking a look at the basic requirements, because banks, payment providers, larger B2B customers or platform partners are noticeably raising their cybersecurity expectations right now anyway.

A real-world example from a medium-sized shop

A medium-sized online shop for tools and fittings has for years supplied end customers alongside several larger hardware store chains in a B2B relationship. One of these large customers, itself a larger company with its own NIS2 exposure, suddenly sends a detailed security questionnaire to all its suppliers. Among other things, it asks about access protection for admin accounts, backup routines and how a security incident would be handled in an emergency. The shop owner is initially surprised, having never expected to deal with "laws for power plants". After a brief review, it turns out that the basics, backups, access controls, up-to-date software, are already largely in place, and the questionnaire can be answered properly with little effort.

Company type Directly covered by NIS2? Typical effect
Large digital providers / marketplaces Yes, if size thresholds are met Risk management, reporting obligations and regulatory oversight
Medium-sized / small classic online shops Generally no Usually no direct obligation, but growing indirect pressure
Suppliers / service providers to NIS2 companies Not directly, but indirectly via contracts Security questionnaires and minimum requirements from customers
Payment providers / banks Yes, usually covered via the financial sector Strict requirements passed on to trading partners

4. What you should specifically do

Even if your business does not currently fall directly under NIS2, it is worth taking a sober look at your own basic security, because the underlying expectations for security are shifting across the whole economy right now. The first sensible step is an honest stocktake: who has access to your shop backend, how up to date is the software you use, and is there actually a working backup routine that has really been tested.

A second important point is looking at your business partners. If larger B2B customers, payment providers or platform partners are already asking for security proof, that is a clear signal to engage with the topic actively instead of sitting it out. Such requests tend to pile up precisely in industries where many larger, NIS2-relevant companies already appear as customers anyway.

Third, it makes sense to establish clear responsibilities within your own company: who takes care of updates, who manages access, and who would be the first point of contact in the event of an actual security incident. In smaller teams especially, this responsibility otherwise tends to fall to nobody in particular, which costs valuable time in an emergency.

5. Checklist: basic security for your online shop

  • Check whether your company could fall directly under NIS2 due to its industry or size.
  • Watch whether larger B2B customers, payment providers or platform partners are already asking for security proof or questionnaires.
  • Regularly review access to your shop backend and admin accounts and remove any access no longer needed.
  • Make sure you have regular, genuinely tested backups of your shop and customer data.
  • Keep software, plugins and extensions up to date and install updates promptly.
  • Set out a simple emergency plan for who gets informed first in the event of a security incident and what happens first.
  • When in doubt, have a short security stocktake of your shop carried out instead of postponing the topic.

6. Fines and risks of non-compliance

For companies that actually fall directly under NIS2, the directive provides for a system of fines whose structure resembles the rules known from the General Data Protection Regulation. Fines can be scaled to a company's turnover and can be severe in serious cases. Specific amounts depend heavily on how the national transposition is worked out in detail, which is why no fixed figure is stated here, only the general order of magnitude.

Besides the actual fines, NIS2 also provides for personal accountability of the management of covered companies. Anyone serving as management of a directly affected company who fails to approve required security measures, or fails to oversee their implementation, can be held personally accountable, independently of any fine against the company itself.

For most medium-sized and small online retailers who are not directly covered, the real risk lies elsewhere: anyone who, as a supplier or service provider to a larger, NIS2-relevant company, cannot provide the required security assurances simply risks losing that business partner. Larger companies increasingly demand contractual assurances about IT security from their suppliers, and when in doubt will choose a provider who can answer these questions cleanly. This economic risk often hits harder in practice than a theoretical fine, precisely because it directly affects revenue.

Important to know

Direct regulatory fines under NIS2 primarily affect companies that actually qualify as "important" or "essential" entities, or as large digital providers. For most medium-sized and small online shops, the greater practical risk lies in losing B2B customers or platform partnerships if required security proof is missing. Getting your own basic security in order early reduces both risks at the same time.

7. Common misconceptions

A widespread misconception goes: "NIS2 only affects critical infrastructure such as power plants or water utilities, my online shop has nothing to do with that." That falls short, because NIS2 also covers several digital provider categories, and through supply chains the topic reaches much further than the name "critical infrastructure" might initially suggest. A second misconception is the assumption: "As long as my country has not finished the transposition, I can ignore the whole topic." That is risky, because the substantive direction of NIS2 is already set at EU level, and larger business partners have long since aligned their own expectations with it, regardless of the state of the German legislative process.

A third misconception concerns the technical side: "A firewall and up-to-date antivirus software are enough to be on the safe side." NIS2-style expectations go considerably further and also cover orderly procedures for emergencies, working backup routines, clean access management for staff, and a look at the security of your own suppliers, not just individual technical tools. A fourth, less frequently mentioned misconception is the assumption that a small shop is too insignificant to ever get pulled into such a discussion. Precisely because larger companies pass their requirements on consistently to all suppliers, even a comparatively small business can be confronted with a security questionnaire faster than might seem likely at first.

8. What we can take care of for you

We know that terms like NIS2, risk management or incident reporting sound intimidating at first for shop owners, even though at their core they usually come down to quite practical, solvable points. Mironsoft takes care of a calm, technical stocktake of your shop for you: together with you, we check how access rights and admin accounts are currently organised, how things stand with backup and update routines, and whether your business environment has already produced any early requests for security proof.

Should larger B2B customers, banks or platform partners send you a security questionnaire, we support you in answering it factually and realistically, without you having to work your way deep into legal or technical detail yourself. For genuinely more complex legal questions, for example the precise classification of your company, we work closely with specialised law firms or, if needed, put you in touch with a suitable contact.

The goal is always a free initial consultation, in which we jointly assess how relevant the topic actually is for your specific shop, instead of selling you a blanket, elaborate security project that you may not need in that scope at all. That way you gain clarity before you need to make any decision, and you keep control over effort and budget.

9. Summary

The NIS2 Directive has been in force at EU level since 16 January 2023 and is primarily aimed at larger companies in specific sectors as well as digital providers such as large marketplaces, search engines or cloud providers. A classic medium-sized or small online shop selling physical goods generally does not fall directly under it. Still, a look at the basic requirements is worthwhile, because banks, payment providers and larger B2B customers are already aligning their own cybersecurity expectations with it and passing those expectations on contractually to their suppliers.

The German transposition of the directive has been delayed, which does not, however, mean the topic is meaningless in practice. Anyone who checks their own basic security early, organises access rights and ensures working backups noticeably reduces both the legal and the economic risk. This article offers a general overview and does not replace individual legal advice for your specific case.

NIS2 Directive and Online Retail — The Essentials at a Glance

What it is about

EU-wide minimum requirements for cybersecurity, reporting and diligence obligations for certain companies.

Who is affected

Mainly larger companies in specific sectors and digital providers, smaller shops usually only indirectly.

Biggest risk

Severe fines and personal management accountability for covered companies, loss of B2B contracts for others.

What to do

Check your basic security, take partner requests seriously and, when in doubt, have a stocktake carried out.

10. FAQ: NIS2 Directive and Online Retail

1What is the NIS2 Directive in simple terms?
An EU directive requiring certain companies to meet a minimum level of cybersecurity, with risk management and reporting obligations for serious incidents.
2Since when has NIS2 applied?
At EU level since 16 January 2023, national transposition was meant to be completed by 17 October 2024.
3Has the German transposition been completed?
The German transposition has been delayed, an exact date was not yet conclusively foreseeable at the time of writing.
4Does NIS2 also affect my ordinary online shop?
Generally not directly, but possibly indirectly through business partners who are themselves covered by NIS2.
5What is a digital provider within the meaning of NIS2?
For example large online marketplaces, search engines, cloud and hosting providers, and social networks above a certain size.
6Can small suppliers be affected too?
Not directly by law, but often contractually, when larger customers pass on their own security requirements.
7What penalties are at risk for non-compliance?
Turnover-based fines for covered companies, more likely the loss of larger contracts for suppliers.
8Is a firewall and antivirus software enough?
No, NIS2-style expectations also cover backups, access management and orderly procedures for emergencies.
9What should I specifically do as a shop owner now?
Check access rights, backups and updates, take partner requests seriously and, when in doubt, have a stocktake carried out.
10Can Mironsoft help me with this?
Yes, we take care of the technical stocktake, support you with partner security questionnaires and put you in touch with a suitable contact for complex legal questions.

This article offers a general overview of the NIS2 Directive and does not replace individual legal advice for your specific case.