01Home02Services03About us04Pricing05Vacancies06Contact
Security & NIS2

NIS2 checklist for SMEs: 10 steps

30 July 2026 · 6 min read

NIS2 compliance for SMEs in 10 concrete steps. From MFA and phishing protection to backups and an incident plan: this is how you get the basics in order step by step.

Max HoltropBy Max Holtrop

NIS2 is coming, and many SMEs wonder where to begin. The good news: you do not have to arrange everything at once. With a concrete checklist you get the basics in order step by step. In this article we go through ten practical steps with which you, as an SME, get serious about NIS2 compliance.

Why this checklist?

The NIS2 directive obliges more organisations to have their digital security demonstrably in order. What NIS2 exactly is and who it applies to, you read in our article NIS2 for SMEs and on our page about NIS2 compliance. This checklist is the practical translation: what can you do now?

What NIS2 concretely asks of you

NIS2 is about two things: managing your risks and being able to demonstrate that you do. The directive does not prescribe exact products, but does expect you to take appropriate measures in the areas of access, protection, backup and incident handling. For SMEs that mainly means: seriously getting the basics in order and recording them.

The good news is that many of those measures are simply good IT management too. You are not only working on compliance, you are genuinely making your organisation safer. The checklist below translates that into ten concrete steps.

The NIS2 checklist in 10 steps

  1. Determine whether NIS2 applies to you. Do you fall under one of the sectors and size criteria? Find that out first, so you know where you stand.
  2. Appoint someone responsible. Security is not a side issue. Record who is in charge of it within your organisation.
  3. Map your risks. Which systems and data are crucial, and what happens if they fail or are leaked?
  4. Arrange secure sign-in. Multi-factor authentication (MFA) on all accounts is one of the most effective measures against intrusion.
  5. Protect against phishing. Technology plus awareness: train your team to recognise suspicious messages.
  6. Keep everything up to date. Outdated software is an open door. Make sure updates happen automatically and on time.
  7. Make backups and test them. A backup you have never restored is not a backup. Test whether recovery really works.
  8. Draw up an incident plan. What do you do if it does go wrong after all? Who do you call, and how do you report an incident on time?
  9. Record your measures. NIS2 requires demonstrability. Document what you have arranged and keep it up to date.
  10. Evaluate and improve. Security is not a project but a process. Periodically check whether everything still fits.

Common mistakes with NIS2

Cannot see the wood for the trees? Watch out especially for these pitfalls:

  • Waiting for the law. Getting the basics in order takes time. Whoever waits until enforcement begins is too late.
  • Only looking at technology. Half of security is in behaviour: awareness and clear agreements are just as important as tools.
  • Recording nothing. NIS2 requires demonstrability. Measures you do not document do not count during an audit.
  • Seeing it as a one-off project. Security changes along with the threats. Without periodic evaluation you fall behind after all.

So start small but start now: take the first steps, record what you do and build it out calmly.

From checklist to practice

These ten steps may look like a lot of work, but much of it falls under good IT management and security that you can largely outsource. We lay the technical foundation with our Modern Work Baseline and help you get the rest demonstrably in order. Read more about the preparation in NIS2: how to prepare.

Getting started with NIS2?

Want to know how far your organisation is and what still needs to happen? Schedule a no-obligation consultation. We go through the checklist together and make a concrete plan.

← Back to news

Frequently asked questions

Good to know

Does NIS2 also apply to SMEs?

For part of the SME segment, yes. Whether you fall under it depends on your sector and the size of your organisation. Step 1 of the checklist is therefore to find out whether NIS2 applies to you.

What is the most important NIS2 measure to start with?

Multi-factor authentication (MFA) on all accounts. It is one of the simplest and most effective measures against unauthorised access, and a logical first step.

Do I have to arrange everything for NIS2 myself?

No. Many of the technical measures fall under good IT management and security that you can outsource. We lay the foundation and help you record the measures demonstrably.

What happens if I do not comply with NIS2?

Organisations that fall under NIS2 and do not comply risk supervision and fines. More importantly: you run unnecessary risk of incidents. Getting the basics in order on time prevents both.

Questions about this?

Want to spar with a specialist?

Curious what this means for your organisation? Book a no-obligation consult — we’re happy to think along.

Book a consultation →