All articles

NIS2 for SMEs: a practical operational checklist

3 min readNIS2ComplianceSecurity Operations

NIS2 is written in the language of regulators, not of the people who have to run the systems. If you are a growing business that suddenly falls in scope — directly, or because a larger customer pushes their obligations down the supply chain — the practical question is simple: what has to change in our day-to-day IT operations?

This is the checklist we work through with SME clients. It is not legal advice; it is the operational translation.

1. Know what you have

You cannot secure or report on an environment you cannot see. Before anything else:

  • A current inventory of users, devices, applications and cloud tenants.
  • Ownership per system: who decides, who administers, who pays.
  • A record of which suppliers process your data.

Most NIS2 conversations stall here, because the inventory is a spreadsheet that stopped being true two years ago. Make it a live view, not a document.

2. Control identity properly

Identity is where most incidents start and where most audits focus.

  • Multi-factor authentication on every account, without exceptions for executives.
  • Named admin accounts, separate from daily-use accounts.
  • Joiner–mover–leaver handled as a process, with an auditable trail. Offboarding within hours, not weeks.
  • Periodic access reviews — quarterly is a reasonable rhythm for an SME.

3. Keep devices patched and provable

  • Managed enrolment for laptops and mobiles, so an unmanaged device is an exception you notice.
  • Disk encryption enforced and reported on.
  • Patch levels measured continuously, with a stated target (for example: critical patches within seven days).

The word that matters is provable. "We patch regularly" is not a control. "94% of endpoints are within the seven-day window, and here is the report" is.

4. Be able to recover

  • Backups that cover SaaS data, not just servers — mailboxes, files, and your line-of-business apps.
  • Restores tested on a schedule, with the test result written down.
  • A documented recovery time objective per critical system.

5. Have an incident process people can actually follow

NIS2 introduces reporting deadlines measured in hours. That is only achievable if the process exists before the incident.

  • A single reporting channel your staff know by heart.
  • Defined severity levels and who is called at each one.
  • A short, rehearsed decision path for "do we need to notify?".

6. Manage your suppliers

  • A list of critical suppliers with what they can access.
  • Security expectations written into contracts.
  • A route to be informed when their incident becomes your incident.

7. Make governance visible

Management accountability is explicit in NIS2. In practice that means leadership sees the same operational picture the engineers do: posture, coverage, open risks and what changed since last quarter.

Where this usually lands

Three of the four areas we operate for clients — workplace operations, security operations and infrastructure operations — produce exactly the evidence this checklist asks for, as a by-product of running the environment well. That is the point we keep making: compliance should be an output of good operations, not a separate project you run every year in a panic.

If you want a view of where you stand today, a short operational baseline assessment is usually enough to tell you which of these seven items are real and which are aspirational.