NIS2 checklist for SMEs: 10 steps
NIS2 compliance for SMEs in 10 concrete steps. From MFA and phishing protection to backups and an incident plan: this is how you get the basics in order step by step.
By Max HoltropNIS2 is coming, and many SMEs wonder where to begin. The good news: you do not have to arrange everything at once. With a concrete checklist you get the basics in order step by step. In this article we go through ten practical steps with which you, as an SME, get serious about NIS2 compliance.
Why this checklist?
The NIS2 directive obliges more organisations to have their digital security demonstrably in order. What NIS2 exactly is and who it applies to, you read in our article NIS2 for SMEs and on our page about NIS2 compliance. This checklist is the practical translation: what can you do now?
What NIS2 concretely asks of you
NIS2 is about two things: managing your risks and being able to demonstrate that you do. The directive does not prescribe exact products, but does expect you to take appropriate measures in the areas of access, protection, backup and incident handling. For SMEs that mainly means: seriously getting the basics in order and recording them.
The good news is that many of those measures are simply good IT management too. You are not only working on compliance, you are genuinely making your organisation safer. The checklist below translates that into ten concrete steps.
The NIS2 checklist in 10 steps
- Determine whether NIS2 applies to you. Do you fall under one of the sectors and size criteria? Find that out first, so you know where you stand.
- Appoint someone responsible. Security is not a side issue. Record who is in charge of it within your organisation.
- Map your risks. Which systems and data are crucial, and what happens if they fail or are leaked?
- Arrange secure sign-in. Multi-factor authentication (MFA) on all accounts is one of the most effective measures against intrusion.
- Protect against phishing. Technology plus awareness: train your team to recognise suspicious messages.
- Keep everything up to date. Outdated software is an open door. Make sure updates happen automatically and on time.
- Make backups and test them. A backup you have never restored is not a backup. Test whether recovery really works.
- Draw up an incident plan. What do you do if it does go wrong after all? Who do you call, and how do you report an incident on time?
- Record your measures. NIS2 requires demonstrability. Document what you have arranged and keep it up to date.
- Evaluate and improve. Security is not a project but a process. Periodically check whether everything still fits.
Common mistakes with NIS2
Cannot see the wood for the trees? Watch out especially for these pitfalls:
- Waiting for the law. Getting the basics in order takes time. Whoever waits until enforcement begins is too late.
- Only looking at technology. Half of security is in behaviour: awareness and clear agreements are just as important as tools.
- Recording nothing. NIS2 requires demonstrability. Measures you do not document do not count during an audit.
- Seeing it as a one-off project. Security changes along with the threats. Without periodic evaluation you fall behind after all.
So start small but start now: take the first steps, record what you do and build it out calmly.
From checklist to practice
These ten steps may look like a lot of work, but much of it falls under good IT management and security that you can largely outsource. We lay the technical foundation with our Modern Work Baseline and help you get the rest demonstrably in order. Read more about the preparation in NIS2: how to prepare.
Getting started with NIS2?
Want to know how far your organisation is and what still needs to happen? Schedule a no-obligation consultation. We go through the checklist together and make a concrete plan.
Good to know
Does NIS2 also apply to SMEs?
For part of the SME segment, yes. Whether you fall under it depends on your sector and the size of your organisation. Step 1 of the checklist is therefore to find out whether NIS2 applies to you.
What is the most important NIS2 measure to start with?
Multi-factor authentication (MFA) on all accounts. It is one of the simplest and most effective measures against unauthorised access, and a logical first step.
Do I have to arrange everything for NIS2 myself?
No. Many of the technical measures fall under good IT management and security that you can outsource. We lay the foundation and help you record the measures demonstrably.
What happens if I do not comply with NIS2?
Organisations that fall under NIS2 and do not comply risk supervision and fines. More importantly: you run unnecessary risk of incidents. Getting the basics in order on time prevents both.
Related services
ICT Security & NIS2
Control over your business information and demonstrable compliance, for the law and for your clients.
Read more →Keeper Password Security
Secure password management for your entire organisation: strong passwords, shared and under control.
Read more →Microsoft 365 security licenses
The right Microsoft security licenses for your organization: advice, setup and management.
Read more →Related articles
NIS2 checklist for SMEs: get the basics right in 10 steps
NIS2 sounds like a lot of work, but the basics are very manageable. This checklist of 10 concrete steps helps your SME get the most important measures in place: mapping risks, MFA and access management, backup and recovery, endpoint security, patch management, an incident reporting process, your supply chain, awareness, monitoring and management accountability. And you don't have to do it alone.
Read more →NIS2 for SMEs: do you have to comply?
NIS2 affects far more SMEs than you might think, often indirectly through customers and suppliers. We explain clearly who the law applies to and how to get the basics in order.
Read more →NIS2 is coming: how to start preparing now
The Dutch implementation of NIS2 is expected in 2026. Does it apply to you, and what can you already do today? A practical overview.
Read more →Want to spar with a specialist?
Curious what this means for your organisation? Book a no-obligation consult — we’re happy to think along.
