IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →
By · Founder, Easy Cyber Protection · · How we write this

NIS2 for SMEs: Practical Guide

Many SME owners believe NIS2 is "only for big companies." This is a dangerous misconception. Whether you're directly in scope or not, cybersecurity requirements will reach you through your customers and supply chains. The good news? Belgium's CyberFundamentals framework is tiered, and its entry level, Basic, is the one most SMEs work toward.

SME business owner reviewing cybersecurity
Cybersecurity is achievable and affordable for SMEs

The "This Doesn't Apply to Me" Misconception

We hear it constantly from SME owners: "We're too small for NIS2" or "We're not in a critical sector." Here's the reality, and it's changing fast: Check if you are directly in scope. But even if not, supply chain requirements will likely still affect you.

Direct scope is narrower, but expanding

NIS2 directly targets companies with 50+ employees in specific sectors. But in January 2026, the EU proposed a new "small mid-cap" category (<750 employees, <€150M turnover) with simplified obligations. The scope keeps growing.

Supply chain pressure is real and growing

About 4,000 organizations in Belgium had registered with the CCB by January 2026. They must secure their supply chains. If you're a supplier to a hospital, bank, or manufacturer, they will require proof of your cybersecurity. The real TAM is 25,000-50,000 organizations when you include these suppliers.

Insurance requirements

Cyber insurance providers increasingly require basic cybersecurity measures. No compliance = no coverage or higher premiums.

Customer expectations

Tenders and contracts increasingly include cybersecurity requirements. No certification = lost business.

SME that received a supplier questionnaire and not sure where to start? Our free quick-check tells you in five questions, directly on screen, what CyFun level you are at and what the next step is. No email, no sales call. Want a signed answer plus a prioritized 30/90/180-day control list to forward to your customer afterwards? The written report is €395 flat, delivered in 48 hours.

Why SMEs Should Care

Cybercriminals don't care about your company size. In fact, SMEs are often easier targets:

Less security investment

Attackers know SMEs often lack dedicated IT security staff

Gateway to bigger targets

Hackers use small suppliers to reach larger companies

Devastating impact

88% of breaches at smaller businesses (under 1,000 staff) involve ransomware (Verizon DBIR 2025)

Reputation damage

One breach can destroy years of customer trust

Supply chain cybersecurity illustration
NIS2 requirements flow through the entire supply chain

What Large Companies Do vs. What SMEs Should Focus On

NIS2 requirements scale to your organization size
AspectLarge EnterpriseSME Focus
Dedicated security team Yes, full-time CISO + team IT partner or managed service
Budget €100K+ annually €0-5K to start
Framework level Important or Essential Basic (34 controls)
Timeline 6-12 months 1-9 months for Basic
Complexity Complex policies, audits Practical checklists
Certification Full audit required Self-assessment OK

How SMEs Can Comply Without Breaking the Bank

The CyberFundamentals "Basic" level is the entry point for SMEs. Here's your practical roadmap: Use the CyberFundamentals framework as a guide and follow our detailed implementation plan.

1

Start with what you have

You're probably already doing some of this: antivirus, regular backups, password policies. Document what exists.

2

Score yourself against the 34 controls

Before you spend anything, work through Basic's 34 controls and mark each one as done, partly done, or not started. That list is the real scope of your work, and most SMEs find they already meet a good part of it.

3

Involve your IT partner

If you have an IT provider, ask them about CyberFundamentals. Good partners already know it, and the technical controls are theirs to implement.

4

Document as you go

Keep simple records of what you implement. A spreadsheet is fine to start.

5

Get visible proof

Once compliant, get the CyberFundamentals Basic badge. Use it in proposals and on your website.

SME Quick Wins Checklist

These 10 actions cover the foundations of the Basic level and significantly reduce your risk:

  • 1 Enable MFA (multi-factor authentication) on all accounts
  • 2 Ensure all devices have updated antivirus/antimalware
  • 3 Set up automatic software updates
  • 4 Implement automatic daily backups (test restores quarterly)
  • 5 Use a password manager for the team
  • 6 Create a simple inventory of your IT assets
  • 7 Define who has access to what systems
  • 8 Brief employees on phishing awareness
  • 9 Have a basic incident response plan (who to call)
  • 10 Review and document your current security measures

Not sure where to start? Use our NIS2 compliance checklist to assess your current status.

Cost Comparison: Your Options

Estimated costs for achieving CyberFundamentals Basic compliance. Three of these are one-time; the platform fee is per client per month.
ApproachEstimated CostBest ForConsiderations
DIY with free tools €0-500 one-time Very small businesses Requires time and basic IT knowledge
Easy Cyber Protection, through your IT partner €49–€750 per month SMEs who want the 34 controls handled as tasks, not as a manual Priced by headcount: Nano 1 – 4: €49, Micro 5 – 12: €99, Core 13 – 29: €169, Growth 30 – 49: €229, Medium 50 – 249: €395, Large 250 – 999: €750, 1,000+ on request. Per client, per month, ex VAT. Recurring, not one-time. There is no free tier: try the live demo first, no signup
IT partner implementation €2,000-5,000 one-time No internal IT capacity One-time cost, ongoing support extra
Consultant audit €5,000-15,000 one-time Higher assurance levels Overkill for Basic level

Working with Your IT Partner

Your IT provider can be your greatest ally in this process. Here's how to work together effectively:

Ask the right question

"Are you familiar with CyberFundamentals?" Good partners know it.

Share responsibilities

Some controls are technical (they handle), others are organizational (you handle).

Request documentation

Ask them to document what security measures they've implemented for you.

Consider shared platforms

Tools like Easy Cyber Protection let you collaborate with your IT partner.

Why Easy Cyber Protection for SMEs?

We built Easy Cyber Protection specifically for SMEs who want to take cybersecurity seriously without hiring consultants or reading 200-page manuals.

One task at a time : No overwhelm. We tell you exactly what to do next, in plain language.
Evidence collection : As you complete tasks, you're automatically building your compliance documentation.
IT partner portal : Share tasks with your IT provider. They see what needs technical implementation.
Dutch, French, English : Full support for businesses in your preferred language.

MSP-delivered, audit-ready CyberFundamentals support

Frequently Asked Questions

Is my small business really at risk of cyberattacks?

Yes. In the Verizon 2025 Data Breach Investigations Report, ransomware was part of 88% of breaches at smaller businesses (under 1,000 staff), against 39% at larger organisations, largely because smaller companies often have weaker security. Attackers use automated tools that don't discriminate by company size. Ransomware, phishing, and invoice fraud affect SMEs daily.

What if I'm not in a NIS2 sector?

Even outside NIS2 sectors, you'll likely face cybersecurity requirements from customers, insurance providers, or business partners who ARE in scope. Starting with CyberFundamentals Basic prepares you for these requests.

How long does it take for an SME to comply?

For CyberFundamentals Basic, most SMEs need 1 to 9 months for the 34 controls, depending on their starting position. Many controls are things you might already be doing: you just need to document them.

Do I need to hire a consultant?

Not for the Basic level. CyberFundamentals Basic is designed for self-assessment. A platform like Easy Cyber Protection guides you through each step. Consultants make sense only if you're targeting higher assurance levels.

Sources

  1. NIS2 Directive (EU) 2022/2555 : Official Journal of the European Union
  2. CyberFundamentals Framework : Centre for Cybersecurity Belgium (CCB)
  3. NIS2 Directive Resources : ENISA (European Union Agency for Cybersecurity)
  4. NIS2 Directive Overview : European Commission Digital Strategy

Related Articles