Cybersecurity
Checklist

NIS2 Checklist for SMBs: Self-Assessment in 10 Steps

NIS2 compliance does not have to start with a formal audit. This ten-step self-assessment turns the Cyberbeveiligingswet's duty of care, reporting duty and governance rules into concrete yes/no questions, with a scoring guide to tell you what to fix first.

Aug 19, 2026
10 min read
NIS2 Checklist for SMBs: Self-Assessment in 10 Steps

NIS2 compliance sounds like a project for a compliance officer with a spreadsheet, but for most Dutch SMBs it comes down to a handful of concrete yes/no questions. This checklist takes the duty-of-care themes from the Cyberbeveiligingswet (the Dutch implementation of NIS2), the reporting duty, and the governance requirements, and turns them into a ten-step self-assessment you can work through in one sitting. It will not replace a formal audit, but it will tell you, honestly, where you stand and what to fix first.

How to use this checklist

Go through the ten steps below in order. For each one, answer yes or no based on what is actually in place today, not what is planned, half-documented, or "mostly true". Be strict: a policy that exists but that nobody has read does not count as a yes. At the end, add up your yes answers and use the scoring section to decide what to tackle first. If you want the legal background before you start, our deep-dive on NIS2 for SMBs covers scope, penalties and the law itself in more detail.

Before you start: are you in scope?

  • Do you operate in a sector NIS2 covers, such as energy, transport, healthcare, digital infrastructure, ICT service management, food production, manufacturing of medical devices, electronics, machinery or vehicles, chemicals, or public administration?
  • Do you have 50 or more staff, or turnover above EUR 10 million?
  • Even if both of the above are no: do any of your customers fall under NIS2? If so, expect them to push NIS2-level security requirements down to you as a supplier, regardless of your own size.

If you answered yes to any of these, or you are simply unsure, run the government's NIS2 self-assessment tool before continuing. Uncertainty is normal at this stage and not a reason to skip the rest of this checklist: supply chain pressure alone is already pushing NIS2-level expectations onto companies well below the legal size threshold.

The 10-point self-assessment

Work through each theme below and mark yourself yes or no. Where you answer no, that is your action list.

1. Governance and ownership

  • A named person, not "IT" in the abstract, owns cybersecurity and reports on it to management.
  • The management team or board has seen and approved the current security approach in the last 12 months.

2. Risk analysis

  • You have a written, current risk analysis covering your critical systems, data and dependencies.
  • The risk analysis has been reviewed or updated in the last year, not just written once and filed away.

3. Incident handling

  • You have a documented incident response plan describing who does what during an incident.
  • The plan has been tested or walked through, at minimum as a tabletop exercise, in the last 12 months.

4. Business continuity and backup

  • Backups run automatically for all business-critical systems and data.
  • You have actually tested a full restore in the last six months, not just confirmed that backup jobs completed.

5. Supply chain security

  • You know which suppliers can access your systems or data, and you have reviewed their security posture.
  • Security requirements are written into your contracts with critical suppliers, not just assumed.

6. Secure development and maintenance

  • Changes to business-critical systems and software go through a review or approval step before going live.
  • Vendor patches and updates for critical systems are applied on a defined schedule, not "eventually".

7. Cyber hygiene and training

  • All staff, including management, have completed security awareness training in the last 12 months.
  • Phishing simulations or equivalent practical training run at least once a year.

8. Cryptography and encryption

  • Sensitive data is encrypted at rest and in transit as a default, not an exception.
  • You know which systems still lack encryption and have a plan to close that gap.

9. Access control and asset management

  • You maintain a current inventory of devices, systems and accounts, including who has access to what.
  • Access follows least privilege: people only have the permissions their role actually requires, reviewed periodically.

10. Multi-factor authentication and reporting readiness

  • MFA is enforced on email, VPN, admin accounts and any system holding sensitive data, without exceptions for convenience.
  • You know exactly who reports a significant incident, to whom, and within what timeline: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month.

Score yourself

Yes answersWhat it means
8-10You are close to ready. Focus on formalising documentation and running the reviews NIS2 expects as evidence.
4-7You have real foundations but real gaps. Prioritise the technical basics (MFA, tested backups, patching) before the paperwork.
0-3Start now. The gap is wide enough that a structured, external review will save you more time than working through it alone.

What to do with a low score

If most of your answers were no, resist the urge to fix everything at once. Start with the items that also reduce your day-to-day risk regardless of NIS2: enforced MFA, tested backups, and a documented incident response plan cover a disproportionate share of the duty of care and are the fastest to implement. Documentation and formal risk analysis matter for compliance evidence, but they matter less if the technical basics are not in place yet. A phased plan, technical basics first, then policy and governance, then supply chain reviews, gets you further in three months than trying to do everything in parallel.

FAQ

Is this checklist a substitute for a formal NIS2 audit? No. It is a genuine starting point that tells you roughly where you stand and what to prioritise, but formal compliance evidence, registration, and any required audit still need to go through the proper channels.

We scored low. Does that mean we are already in breach? Not necessarily. The Cyberbeveiligingswet's obligations apply once the law is in force and, for many requirements, on a risk-appropriate basis. A low score means you have work to do, not that you are already being fined. The point of running this now is to close the gap before enforcement starts.

How often should we redo this self-assessment? At least once a year, and again after any major change: a new critical supplier, a significant incident, or a change in headcount or turnover that could shift which category you fall into.

We are too small to be directly in scope. Is this still worth doing? Usually yes. Even outside direct scope, larger customers bound by NIS2 are increasingly requiring their suppliers to demonstrate exactly these basics, so being able to answer yes to most of this checklist is becoming a commercial requirement, not just a legal one.

Get a second opinion on your score

Want an outside view on where you actually stand, not just a self-assessment? Our Cybersecurity & Identity team runs NIS2 gap assessments that turn this checklist into a prioritised, costed plan, often alongside a Managed IT & Support engagement that covers the technical basics on an ongoing basis. Read 8 measures that prevent ransomware for a closer look at the technical fixes that move the needle fastest.

NIS2
Cybersecurity
Checklist
MKB

Related Articles

Cybersecurity

AI-Powered Cybersecurity: How Machine Learning Is Transforming Threat Detection

Cyberattacks are growing in volume and sophistication. AI-powered security tools are shifting the balance back to defenders. This article examines how Dutch organisations are using ML-driven SIEM, EDR, and threat intelligence to stay ahead.

Read More
Cybersecurity

NIS2 for SMBs: What the Law Means and What You Must Arrange

The Dutch Cyberbeveiligingswet (NIS2) lands in 2026 and brings duty of care, a 24-hour reporting duty and personal director liability. Here is who is in scope, what you must arrange, and a practical step-by-step plan for SMBs.

Read More
Cybersecurity

Preventing Ransomware in the SMB: 8 Measures That Actually Work

SMBs are now the primary target for ransomware precisely because attackers assume their defences are weak. The good news: a handful of well-implemented measures stop the vast majority of attacks. Here are the 8 that deliver the most protection per euro.

Read More

Need Help with Your IT Infrastructure?

Let's discuss how we can help transform your IT operations with modern solutions.