Logo: to the web site of Uppsala University

uu.sePublications from Uppsala University
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Små aktörer, stora krav: NIS 2-direktivets påverkan på distributionskedjan
Uppsala University, Disciplinary Domain of Humanities and Social Sciences, Faculty of Social Sciences, Department of Informatics and Media.
Uppsala University, Disciplinary Domain of Humanities and Social Sciences, Faculty of Social Sciences, Department of Informatics and Media.
2026 (Swedish)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesisAlternative title
Small actors, big demands : The impact of the NIS 2 Directive on the supply chain (English)
Abstract [en]

The revised NIS 2 Directive, which came into force in January 2023, is part of the EU’s broader initiative to enhance cybersecurity and digital resilience across member states. The directive expands the responsibilities of organizations, requiring not only internal security controls but also oversight of their supply chains. For small and medium-sized enterprises (SMEs), these demands present significant organizational and economic challenges.

This study investigates the specific impact of NIS 2 on SMEs operating in the EU. The study is based on a qualitative literature review following a Systematic Literature Review (SLR) approach. Key themes include supply chain risk management, incident reporting obligations, scope interpretation, and the evolving role of organizational leadership in cybersecurity compliance.

The findings indicate that SMEs frequently lack the technical infrastructure and administrative capacity to fully comply with NIS 2 requirements. Difficulties include verifying supplier security, managing tight incident reporting deadlines, and assessing whether their operations fall under the directive. Furthermore, compliance is shown to be not merely a technical process, but an institutional and cultural practice shaped by norms, legitimacy, and stakeholder expectations.

The study recommends the development of tailored tools such as sector-specific guidelines, simplified contracts, and maturity assessments to support SMEs. It also calls for further research on the intersection of NIS 2 and the EU’s AI Act—particularly how automated decision-support tools can be lawfully and effectively integrated into cybersecurity reporting and supplier evaluation.

In conclusion, the NIS 2 Directive acts as a systemic reform of cybersecurity governance in Europe. While it poses major challenges for SMEs, it also offers an opportunity to professionalize security practices—provided that proportional and practical support mechanisms are put in place.

Place, publisher, year, edition, pages
2026. , p. 42
Keywords [en]
NIS 2, cybersecurity, SMEs, supply chain risk, incident reporting, compliance, AI Act, information security policy
National Category
Information Systems, Social aspects
Identifiers
URN: urn:nbn:se:uu:diva-590433OAI: oai:DiVA.org:uu-590433DiVA, id: diva2:2073460
Educational program
Bachelor programme in Information Systems
Available from: 2026-06-18 Created: 2026-06-16 Last updated: 2026-06-18Bibliographically approved

Open Access in DiVA

No full text in DiVA

By organisation
Department of Informatics and Media
Information Systems, Social aspects

Search outside of DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric score

urn-nbn
Total: 5 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf