IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →

From Zero to Audit-Ready: Your Complete Compliance Roadmap

Whether you're starting from scratch or building on existing security practices, this roadmap guides you through the complete journey to compliance. We've designed it specifically for SMEs, with clear phases, realistic timelines, and decision points that help you invest appropriately for your actual risk level.

This roadmap aligns with the NIS2 directive and the CyberFundamentals framework, covering all NIS2 requirements step by step.

Winding mountain trail ascending toward the summit with visible waypoints - representing the compliance journey
Your compliance journey has clear phases and milestones

The 4 Phases of Your Compliance Journey

1

Phase 1: Assessment

Understand where you stand and where you need to go

Timeline: 1-2 weeks

Before implementing anything, you need clarity on your current security posture, your regulatory obligations, and the gap between them. This phase prevents wasted effort on unnecessary controls while ensuring you don't miss critical requirements.

Objectives:

  • • Determine if NIS2 applies to your organization
  • • Identify your required CyberFundamentals assurance level
  • • Document your current security measures and practices
  • • Identify gaps between current state and requirements
  • • Estimate effort and resources needed for compliance

Deliverables:

  • Scope determination document (in/out of NIS2, sector classification)
  • Current state inventory of existing security controls
  • Gap analysis report with prioritized findings
  • Resource estimate and preliminary timeline

Want to keep phase 1 as light as possible? Our free scope check gives scope and CyFun level directly on screen in five questions, no email required. Want the same outcomes signed on paper with a prioritized control list as a single package? The written report is €395 flat (ex VAT), delivered in 48 hours.

2

Phase 2: Build

Achieve solid protection with Basic tier

Timeline: 2-3 months

The Basic tier is the entry level of CyberFundamentals: 34 controls that give your security posture real depth. This level provides robust protection suitable for most SMEs and satisfies many customer and partner security requirements. It's the recommended target for organizations that handle sensitive data or provide services to larger enterprises.

Objectives:

  • • Implement all 34 Basic tier controls
  • • Formalize security policies and governance
  • • Establish regular security review cycles
  • • Implement technical controls for network and data protection
  • • Prepare for potential third-party audits

Basic Tier Control Categories

  • • Risk management framework
  • • Network security and segmentation
  • • Data protection and encryption
  • • Incident detection and logging
  • • Business continuity planning
  • • Supplier and third-party security

Deliverables:

  • Complete policy framework documentation
  • Technical controls implementation report
  • Security governance structure
  • Audit-ready evidence package
Lighthouse beacon cutting through coastal fog - guidance through uncertainty
Clear guidance through the complexity of compliance requirements
3

Phase 3: Mature

Achieve Important or Essential tier when your NIS2 class or risk assessment calls for it

Timeline: 2-4 months

Important tier (133 controls) and Essential tier (218 controls) are for organizations whose risk assessment calls for them, and Essential is the default for essential NIS2 entities. These levels require substantial investment.

Objectives:

  • • Implement advanced security controls specific to your tier
  • • Establish formal security governance with leadership involvement
  • • Implement continuous monitoring and threat detection
  • • Develop comprehensive incident response and recovery capabilities
  • • Prepare for regulatory audits and certification

Advanced Control Categories

  • • Security operations center (internal or outsourced)
  • • Advanced threat detection and response
  • • Supply chain security management
  • • Cryptographic controls and key management
  • • Physical security integration
  • • Security metrics and continuous improvement

Deliverables:

  • Comprehensive security program documentation
  • Continuous monitoring capability
  • Formal incident response team and procedures
  • Certification-ready evidence package
4

Phase 4: Maintain

Establish ongoing compliance as business as usual

Timeline: Ongoing

Compliance is not a one-time achievement: it's a continuous process. This phase establishes the practices that keep you audit-ready as threats evolve, your business changes, and regulations update. Without maintenance, even the best implementation degrades over time.

Objectives:

  • • Establish regular review and audit cycles
  • • Maintain current awareness of threat landscape
  • • Keep documentation and evidence up to date
  • • Ensure incident reporting capability (24-hour NIS2 requirement)
  • • Integrate security into business change processes
  • • Monitor regulatory developments and adapt accordingly

Ongoing Maintenance Activities

Activity Frequency
Control effectiveness review Quarterly
Policy review and updates Annually
Staff security awareness training Annually, plus ongoing
Penetration testing or vulnerability assessment Annually
Incident response drill Annually
Evidence collection and organization Continuous

Deliverables:

  • Documented review cycle and schedule
  • Continuous improvement log
  • Updated evidence repository
  • Annual compliance status report

How Phases Map to CyberFundamentals and NIS2

Each phase builds upon the previous one, aligning with CyberFundamentals assurance levels and NIS2 requirements: To understand the penalties for non-compliance, see our guide on NIS2 penalties. You can also compare NIS2 compliance tools to find the right fit.

Phase CyberFundamentals NIS2
Phase 1: Assessment Gap Analysis Scope Determination
Phase 2: Build Basic (34 controls) Standard compliance
Phase 3: Mature Important/Essential (133-218 controls) Full NIS2 compliance
Phase 4: Maintain Continuous assurance Ongoing compliance

Realistic Timeline Expectations

Based on our experience with SMEs, here are realistic timelines per CyFun tier. Reaching Important or Essential is a multi-year arc because each tier carries more controls and more evidence to build: there is no shortcut. The numbers below are time-to-first-audit for each tier in turn.

Risk analysis points to Basic: target CyFun Basic

Target: CyFun Basic (34 controls) 1 to 6 months

Faster end if MFA, EDR, immutable backup and acceptable-use policy already exist. Slower end if greenfield. Most reach Basic in their first year.

Risk analysis points to Important: target CyFun Important

Target: CyFun Important (133 controls) Straight to Important, or Basic in year 1 and Important in year 2

Nothing forces a Basic step first: the Royal Decree allows a CAB verification at Important at the first step (Art. 22 §1). Many organisations still reach Basic in year 1, spend 2-3 months on remediation, and take the discipline up to Important in year 2, because Important adds 99 controls.

Essential NIS2 entity: target CyFun Essential (the default)

Target: CyFun Essential Essential by 18 April 2027, or Important now plus a plan to reach Essential by 18 April 2028

Multi-year arc. Each audit cycle surfaces remediation work that needs months to close before the next tier opens. Essential adds operational maturity (continuous monitoring, advanced incident response, supply-chain attestation), realistic only after two audit cycles have proved discipline holds. The legal clock is shorter: the CCB expects an Essential certificate by 18 April 2027, or an Important verification statement plus a plan to reach Essential by 18 April 2028.

When to Stop vs. When to Continue

Not every organization needs to reach the highest tier. Here's how to make that decision:

Consider stopping at your current level if:

  • • You've reached your legally required tier
  • • Your risk assessment doesn't indicate elevated threats
  • • Customer/partner requirements are satisfied
  • • The cost of additional controls outweighs the risk reduction
  • • You're outside NIS2 scope and have solid basics in place

Continue to the next level if:

  • • Regulatory requirements demand a higher tier
  • • You handle particularly sensitive data
  • • You are an essential entity, or your risk assessment points to a higher level
  • • Key customers require specific certifications
  • • A security incident would have severe business impact

Ready to Start Your Journey?

Easy Cyber Protection guides you through each phase with actionable tasks, automated evidence collection, and clear progress tracking. Start with our free NIS2 scope check: five on-screen clicks, no email address needed, and you will know whether you are in scope and which assurance level applies.

Frequently Asked Questions

Can I skip phases if I already have some security in place?

You can't skip the Assessment phase: it's essential to understand where you are and what you need. However, if you already have controls in place, those phases will go faster. The assessment will identify what you already have, allowing you to focus only on gaps.

What if I can't afford to do this all at once?

That's exactly why we've structured this as phases. Start with Phase 1 (Assessment): it is achievable with minimal investment and tells you exactly what you need. Then progress through the phases as budget allows. Every Basic control you put in place reduces your risk, even before the tier is complete.

Do I need external consultants or can I do this internally?

Phases 1-2 (through Basic tier) can typically be done internally, especially with a guided platform. Phase 3 often benefits from external expertise due to the complexity and volume of controls. Phase 4 (Maintain) is primarily internal with occasional external audits.

How do I know which tier I actually need?

It starts with your NIS2 class. An essential entity that uses CyFun defaults to CyFun Essential: a certificate by 18 April 2027, or an Important verification statement plus a plan to reach Essential by 18 April 2028. It may choose a lower level only when its own risk assessment justifies it, at its own responsibility, and must show by 18 April 2027 that it meets that level. The CCB can check that choice. An important entity had no administrative formality with the CCB by 18 April 2026, but must implement all NIS2 measures, and the CCB can ask for evidence, for example after an incident. It chooses its level using the CCB Selection Tool, which is a risk assessment. If it opts for a voluntary CyFun assessment, the Royal Decree sets at least the Important level (Art. 11). If you're outside NIS2 scope, Basic tier is a strong recommendation for any business handling customer data or providing IT services.

What happens if regulations change after I've achieved compliance?

This is why Phase 4 (Maintain) is so important. Part of maintenance is monitoring regulatory developments and adapting your controls accordingly. A good compliance platform will alert you to changes that affect your requirements and help you adjust.

Related Resources

Sources

  1. Recommendation 2003/361/EC, Annex Art. 2 (SME definition)
  2. NIS2 Directive (EU) 2022/2555 : Official Journal of the European Union
  3. CyberFundamentals Framework : Centre for Cybersecurity Belgium (CCB)
  4. Centre for Cybersecurity Belgium (CCB) : Official Belgian cybersecurity authority
  5. CCB: FAQ NIS2 and CyberFundamentals : what essential and important entities must provide, and the risk-based lower level
  6. Royal Decree of 9 June 2024 (NIS2), Art. 6, 7, 11 and 22 (French text)
  7. CCB CyFun Selection Tool