✓ OSCP · OSWE · OSEP certified | Joost performs every test himself — no juniors | Response within 1 business day | Based in Haarlem

NIS2 in 2026: 10 Practical Steps for Dutch SMEs

NIS2 is coming, and many SMEs are asking themselves: “Does this apply to us — and what do we need to do right now?” This article gives you a practical checklist in plain language. No legal smoke and mirrors, just concrete actions.

1) Determine whether NIS2 applies to your organisation

Do you fall under essential or important sectors, or do you deliver critical services in the supply chain? Then preparation is wise — even if you’re only indirectly affected through customers or contract requirements.

2) Map your critical systems

Which systems absolutely need to keep running? Think:

  • Microsoft 365 / email
  • Accounting
  • CRM
  • Production/operations
  • Backups

3) Enable MFA everywhere you can

MFA on email, admin accounts, VPN and cloud environments is one of the fastest ways to reduce risk.

4) Restrict admin rights

Not everyone needs to be a local admin. Fewer rights means less impact in the event of an incident.

5) Patch policy: rhythm and ownership

Define who patches, when it happens, and how you verify updates were actually applied.

6) Test backup and recovery

Not just “we make backups” — but also: can you actually recover within an acceptable time?

7) Incident response on one page

Who do you call first? Who decides? Who communicates internally/externally? A simple runbook page prevents chaos.

8) Check suppliers and supply chain risks

Which parties have access to your data or systems? Document minimum security requirements.

9) Security awareness for employees

Short, repeated training works better in practice than one long annual session.

10) Start with a baseline assessment

Have your current situation assessed and create a realistic quarterly improvement plan.

A common mistake

Waiting for “full clarity” and therefore doing nothing. Most of the gain comes from basic measures you can take right now.

Conclusion

NIS2 doesn’t have to be a panic project. With a clear baseline, priorities and monthly improvement steps, you get in control quickly.

Want to know where your organisation stands right now?
Schedule a short security intake with MonkeysICT.

Related articles


More information

Scroll to Top