Skip to Content

NIS2 and European Standards: What It Means for Quebec SMBs with European Clients

The EU cybersecurity directive that might knock on your door through the supply chain

TL;DR: The European NIS2 directive, applicable since October 2024, imposes cybersecurity requirements on European companies in 18 sectors and makes them secure their suppliers: even if you're based in Quebec, your European clients are going to ask questions. Incident reporting within 24 hours, documented risk management, supply chain security. Here's what it actually means for local SMBs.


In this article

You have a client in France, a partner in Belgium, or a subcontracting deal with a German company. Everything's running smoothly, deliverables ship on time, invoices get paid. Then one day, you receive a 40-page questionnaire about your cybersecurity posture. Your European contact is almost apologetic: "it's the new directive, we have no choice."

Welcome to the world of NIS2.


What exactly is NIS2?

NIS2 (Network and Information Security Directive 2) is the second version of the European cybersecurity directive. It replaced the original (NIS1) on 18 October 2024. Member States had until 17 October 2024 to adopt and publish it in their national law, and had to apply those measures from the day after.

In short: Europe decided that cybersecurity is too important to let each company decide its own level of effort. The directive covers 18 critical sectors: energy, transport, health, digital infrastructure, cloud services, and many more.

Targeted companies are classified into two categories: essential entities (the largest, most critical ones) and important entities (the rest of the covered sectors). Both must comply, but fines differ: up to 10 million euros or 2% of global revenue for essential entities, 7 million or 1.4% for important ones.


The domino effect on the supply chain

Here's what directly concerns us in Quebec: NIS2 doesn't just target European companies. The directive requires covered entities to secure their supply chain, including their non-EU suppliers.

In practice, if you're an IT subcontractor, a cloud services provider, a software developer, or even a professional services provider for a European client, that client now has a legal obligation to make sure you meet a minimum level of cybersecurity.

The pressure doesn't come from a European regulator showing up in Montreal. It comes from your clients themselves: security questionnaires, contractual clauses, supplier audits. If you can't demonstrate your security posture, you risk losing the contract. Not because your work is bad, but because your client simply isn't allowed to take the risk.


The four pillars of NIS2

The directive revolves around four main obligations:

1. Risk management: documented security policies, risk assessments, baseline technical measures (patching, access control, encryption). Nothing revolutionary for a well-managed company, but it has to be written down, formal, and verifiable.

2. Incident reporting: this is where it gets serious. NIS2 requires a three-stage reporting process: an early warning within 24 hours of becoming aware of the incident, a detailed notification within 72 hours, and a final report no later than one month after that notification. The month runs from the 72-hour notification, not from the incident, and that nuance changes how you plan for it. Your European client will expect you to respond within the same timeframes if the incident involves you.

3. Supply chain security: identify critical suppliers, assess their security practices, include cybersecurity clauses in contracts. The text is explicit about it: the measures must cover supply chain security, "including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers". Direct supplier means you. This is precisely the part that affects Quebec SMBs.

4. Governance accountability: the management body has to approve the risk-management measures, oversee their implementation, and can be held liable for failures. Not just the IT department: the board and senior management. One correction worth making, because the opposite gets written a lot: the directive does not provide for personal fines. It provides for something else. Where other measures have failed and a deadline to fix things has been missed, the authority can have the head of an essential entity temporarily barred from exercising managerial functions. It is a last resort, and it applies to essential entities only.


Two years on, the directive still is not in everyone's law

Here is the detail that throws people when the questionnaire lands: several Member States still have not finished transposing NIS2 into their national law.

The European Commission opened proceedings on 28 November 2024, with letters of formal notice to 23 Member States. On 7 May 2025 it sent reasoned opinions to 19 of them. And on 8 July 2026 it referred four laggards to the Court of Justice of the European Union, Ireland, Spain, France and the Netherlands, asking the Court to impose a lump sum and daily penalty payments until transposition is complete. In France, the transposition bill passed the Senate in March 2025 but is still waiting for its floor vote in the National Assembly.

What matters here is not the procedure, it is what the procedure implies for you. Your French client can perfectly well send you a NIS2 questionnaire while France has not finished writing its own law. That is not a contradiction: the requirement reaching you does not come from your client's national law, it comes from your client's contract. Large European companies have been preparing since 2024 because they know the law is coming, and they started by tightening up their suppliers.

The practical corollary is simple. Do not build your answer on the text of one national law, which may still change or may not exist yet. Build it on the directive itself, which is the common denominator across all twenty-seven, and let your client tell you what their own law adds on top.


NIS2 vs Law 25: cousins, not twins

We already have Law 25 in Quebec, which governs the protection of personal information. Is it enough to meet NIS2 requirements? Not quite. Here's why:

Aspect Law 25 (Quebec) NIS2 (EU)
Scope Personal information protection Overall cybersecurity (not just personal data)
Incident reporting Obligation to report to the CAI, no strict timeline 24h (alert), 72h (notification), 1 month (report)
Supply chain Subcontractor agreements required Mandatory supplier security assessments
Executive liability Designated officer (highest-ranking executive by default) Management held accountable; temporary ban from management duties as a last resort (essential entities)
Maximum fines CAD $25M or 4% of global revenue €10M or 2% of global revenue
Technical measures "Reasonable" security measures Specific requirements: patching, encryption, access control, backups

Law 25 is a good starting point. If you're already compliant, you have a solid foundation. But NIS2 goes further on technical measures, reporting timelines, and supplier assessments. It's a complement, not a replacement.


What about GDPR in all of this?

Canada benefits from a partial adequacy decision from the European Commission for personal data transfers. In plain terms, Europe considers that PIPEDA (the federal law) offers an "adequate" level of protection for commercial data. In January 2024, after a review, the Commission concluded that PIPEDA continues to offer adequate protection. The decision still stands, and the next review is expected around 2028.

But be careful: "adequate" doesn't mean "identical." The decision only covers commercial organizations under PIPEDA, not government bodies or provincial organizations that aren't subject to the federal law. And one thing needs correcting here, because it is still written everywhere: Bill C-27, which was to replace PIPEDA with the Consumer Privacy Protection Act, died on the Order Paper when Parliament was prorogued on 6 January 2025. Its successor, Bill C-36, was introduced on 15 June 2026 and has not yet passed second reading in the House of Commons. The federal law governing your transfers today is therefore still PIPEDA, unchanged.

NIS2 and GDPR are two different but complementary things. GDPR protects personal data. NIS2 protects systems and networks. A cybersecurity incident can trigger obligations under both frameworks at the same time.


What Quebec SMBs should do now

Most Quebec SMBs will never be directly targeted by NIS2. But if you have clients in Europe, here's what's likely coming in the next few months:

Take stock of where you stand: document what you already have in place. Password policy, backups, updates, access control. Often, SMBs do the right things but don't write them down. NIS2 requires evidence.

Prepare an incident response plan: even a simple one. Who does what if a server gets compromised? How do you notify your client within 24 hours? We covered this in our article on disaster recovery planning.

Review your contracts: your agreements with European clients will likely include new clauses. Read them. Understand what you're committing to.

Document your supplier chain: you have subcontractors too. If your European client has to assess their chain, they're going to ask you to assess yours.

Our recommendation for SMBs doing business in Europe:

  1. Complete an inventory of your IT assets and existing security measures
  2. Write an information security policy, even a short one (5 pages is enough)
  3. Test your incident response plan at least once a year
  4. Keep a log of incidents, even minor ones


What we don't know yet

We'd rather be upfront about what we don't know yet:

NIS2 transposition varies from one European country to another. Germany has applied its transposition law since 6 December 2025. France does not have one yet. And where the law exists, the rules are not identical from one country to the next. If you serve clients in multiple EU countries, the requirements may differ in the details.

The European text itself is still moving. On 20 January 2026, the Commission proposed targeted amendments to NIS2: clarifying who is covered, lightening obligations for a new category of small mid-cap companies, and covering submarine cables more fully. It is a proposal, not a law: the European Parliament and the Council still have to agree on the text.

Enforcement against companies is still hard to read. The visible litigation is about Member States that have not transposed, not about companies being penalised. How many non-EU suppliers will actually lose a contract for failing to show their posture, nobody knows: that plays out in commercial conversations that never get published.

Most Quebec SMBs will never receive a fine from the EU. The real risk is commercial: losing a client or a contract because you can't demonstrate compliance. It's less dramatic than a 10-million-euro fine, but it's just as real for a 15-person SMB.

Finally, we're not lawyers. What we're writing here is a plain-language overview to give you context. For the legal details specific to your situation, talk to a lawyer who specializes in digital law.

Diagram: how NIS2 reaches a Quebec SMB Diagram of the path by which NIS2 requirements reach a Quebec SMB. The European directive covers essential and important entities across eighteen sectors. Those entities must secure their supply chain. They therefore pass the requirements on to their suppliers, wherever they are. The Quebec SMB receives a questionnaire, by contract rather than by law. 1 The NIS2 directive in force across the EU since 18 October 2024 European Union 2 The covered entity essential or important, in one of 18 sectors in Europe 3 Its supply chain it must secure it, so it questions you requirement passed down 4 Your Quebec SMB the questionnaire lands, by contract not by law in Québec NIS2 does not apply to you. Your client's contract does.


There's an angle that rarely comes up in NIS2 discussions: control over your infrastructure. When a European client asks where your data is hosted, who has access, and which jurisdiction it falls under, it's a lot easier to answer when you control your own systems.

That's our approach at Blue Fox: we help SMBs set up infrastructure they understand and control. Not out of ideology, but because it's concretely simpler to answer a compliance questionnaire when you know exactly what's running on your servers, where the backups are, and who holds the keys.

We've covered these issues from other angles in our articles on privacy-respecting jurisdictions and on digital sovereignty and organizational resilience.

Received a cybersecurity questionnaire from a European client? We offer support to document your security posture and prepare your responses.


Conclusion

NIS2 isn't a direct threat to Quebec SMBs. It's a commercial reality that will show up through the requirements of your European clients. Better to prepare now, while it's still a competitive advantage, than in six months when it becomes a prerequisite.

If you're already compliant with Law 25, you have working backups, an incident response plan, and a clear idea of who has access to what in your organization, you're probably further along than you think. The bulk of the work is just documenting it.

That's what we're here for. Let's talk about your compliance.


Sources

Local and Private AI for SMBs: Keep Your Data In-House with Ollama
How to deploy language models on your own servers, without sending your confidential data to the cloud