NIS2 for SMEs: Practical Guide
Many SME owners believe NIS2 is "only for big companies." This is a dangerous misconception. Whether you're directly in scope or not, cybersecurity requirements will reach you through your customers and supply chains. The good news? Belgium's CyberFundamentals framework is tiered, and its entry level, Basic, is the one most SMEs work toward.
The "This Doesn't Apply to Me" Misconception
We hear it constantly from SME owners: "We're too small for NIS2" or "We're not in a critical sector." Here's the reality, and it's changing fast: Check if you are directly in scope. But even if not, supply chain requirements will likely still affect you.
Direct scope is narrower, but expanding
NIS2 directly targets companies with 50+ employees in specific sectors. But in January 2026, the EU proposed a new "small mid-cap" category (<750 employees, <€150M turnover) with simplified obligations. The scope keeps growing.
Supply chain pressure is real and growing
About 4,000 organizations in Belgium had registered with the CCB by January 2026. They must secure their supply chains. If you're a supplier to a hospital, bank, or manufacturer, they will require proof of your cybersecurity. The real TAM is 25,000-50,000 organizations when you include these suppliers.
Insurance requirements
Cyber insurance providers increasingly require basic cybersecurity measures. No compliance = no coverage or higher premiums.
Customer expectations
Tenders and contracts increasingly include cybersecurity requirements. No certification = lost business.
SME that received a supplier questionnaire and not sure where to start? Our free quick-check tells you in five questions, directly on screen, what CyFun level you are at and what the next step is. No email, no sales call. Want a signed answer plus a prioritized 30/90/180-day control list to forward to your customer afterwards? The written report is €395 flat, delivered in 48 hours.
Why SMEs Should Care
Cybercriminals don't care about your company size. In fact, SMEs are often easier targets:
Less security investment
Attackers know SMEs often lack dedicated IT security staff
Gateway to bigger targets
Hackers use small suppliers to reach larger companies
Devastating impact
88% of breaches at smaller businesses (under 1,000 staff) involve ransomware (Verizon DBIR 2025)
Reputation damage
One breach can destroy years of customer trust
What Large Companies Do vs. What SMEs Should Focus On
| Aspect | Large Enterprise | SME Focus |
|---|---|---|
| Dedicated security team | Yes, full-time CISO + team | IT partner or managed service |
| Budget | €100K+ annually | €0-5K to start |
| Framework level | Important or Essential | Basic (34 controls) |
| Timeline | 6-12 months | 1-9 months for Basic |
| Complexity | Complex policies, audits | Practical checklists |
| Certification | Full audit required | Self-assessment OK |
How SMEs Can Comply Without Breaking the Bank
The CyberFundamentals "Basic" level is the entry point for SMEs. Here's your practical roadmap: Use the CyberFundamentals framework as a guide and follow our detailed implementation plan.
Start with what you have
You're probably already doing some of this: antivirus, regular backups, password policies. Document what exists.
Score yourself against the 34 controls
Before you spend anything, work through Basic's 34 controls and mark each one as done, partly done, or not started. That list is the real scope of your work, and most SMEs find they already meet a good part of it.
Involve your IT partner
If you have an IT provider, ask them about CyberFundamentals. Good partners already know it, and the technical controls are theirs to implement.
Document as you go
Keep simple records of what you implement. A spreadsheet is fine to start.
Get visible proof
Once compliant, get the CyberFundamentals Basic badge. Use it in proposals and on your website.
SME Quick Wins Checklist
These 10 actions cover the foundations of the Basic level and significantly reduce your risk:
- 1 Enable MFA (multi-factor authentication) on all accounts
- 2 Ensure all devices have updated antivirus/antimalware
- 3 Set up automatic software updates
- 4 Implement automatic daily backups (test restores quarterly)
- 5 Use a password manager for the team
- 6 Create a simple inventory of your IT assets
- 7 Define who has access to what systems
- 8 Brief employees on phishing awareness
- 9 Have a basic incident response plan (who to call)
- 10 Review and document your current security measures
Not sure where to start? Use our NIS2 compliance checklist to assess your current status.
Cost Comparison: Your Options
| Approach | Estimated Cost | Best For | Considerations |
|---|---|---|---|
| DIY with free tools | €0-500 one-time | Very small businesses | Requires time and basic IT knowledge |
| Easy Cyber Protection, through your IT partner | €49–€750 per month | SMEs who want the 34 controls handled as tasks, not as a manual | Priced by headcount: Nano 1 – 4: €49, Micro 5 – 12: €99, Core 13 – 29: €169, Growth 30 – 49: €229, Medium 50 – 249: €395, Large 250 – 999: €750, 1,000+ on request. Per client, per month, ex VAT. Recurring, not one-time. There is no free tier: try the live demo first, no signup |
| IT partner implementation | €2,000-5,000 one-time | No internal IT capacity | One-time cost, ongoing support extra |
| Consultant audit | €5,000-15,000 one-time | Higher assurance levels | Overkill for Basic level |
Working with Your IT Partner
Your IT provider can be your greatest ally in this process. Here's how to work together effectively:
Ask the right question
"Are you familiar with CyberFundamentals?" Good partners know it.
Share responsibilities
Some controls are technical (they handle), others are organizational (you handle).
Request documentation
Ask them to document what security measures they've implemented for you.
Consider shared platforms
Tools like Easy Cyber Protection let you collaborate with your IT partner.
Why Easy Cyber Protection for SMEs?
We built Easy Cyber Protection specifically for SMEs who want to take cybersecurity seriously without hiring consultants or reading 200-page manuals.
Frequently Asked Questions
Is my small business really at risk of cyberattacks?
Yes. In the Verizon 2025 Data Breach Investigations Report, ransomware was part of 88% of breaches at smaller businesses (under 1,000 staff), against 39% at larger organisations, largely because smaller companies often have weaker security. Attackers use automated tools that don't discriminate by company size. Ransomware, phishing, and invoice fraud affect SMEs daily.
What if I'm not in a NIS2 sector?
Even outside NIS2 sectors, you'll likely face cybersecurity requirements from customers, insurance providers, or business partners who ARE in scope. Starting with CyberFundamentals Basic prepares you for these requests.
How long does it take for an SME to comply?
For CyberFundamentals Basic, most SMEs need 1 to 9 months for the 34 controls, depending on their starting position. Many controls are things you might already be doing: you just need to document them.
Do I need to hire a consultant?
Not for the Basic level. CyberFundamentals Basic is designed for self-assessment. A platform like Easy Cyber Protection guides you through each step. Consultants make sense only if you're targeting higher assurance levels.
Sources
- NIS2 Directive (EU) 2022/2555 : Official Journal of the European Union
- CyberFundamentals Framework : Centre for Cybersecurity Belgium (CCB)
- NIS2 Directive Resources : ENISA (European Union Agency for Cybersecurity)
- NIS2 Directive Overview : European Commission Digital Strategy