NIS2 SME checklist 2026: sixteen control questions for the duty of care, per article 21 topic.
The Dutch Cyberbeveiligingswet transposes the NIS2 directive into Dutch law. Article 21 lists ten topics every designated organisation must cover. This checklist translates those ten into sixteen concrete yes/no questions for an organisation with 20 to 250 employees, with the evidence you must be able to show for each. The same sixteen questions form the security baseline in Qteco's free NIS2 scan.
From ten legal topics to sixteen testable questions.
Article 21(2) lists ten areas of measures, from risk analysis to MFA. They are written for all sectors and organisation sizes at once and are therefore abstract. Qteco has translated each area into one or two questions that can be answered with yes or no, and whose answer can be demonstrated with a document, report or setting. A question only counts as "yes" when the evidence exists.
Scoring
Sixteen questions, one point each. 14 to 16 is a good baseline, 11 to 13 a reasonable baseline, 6 to 10 insufficient and 5 or fewer critical. The NIS2 scan uses the same classes.
Evidence
Each question states what counts as evidence. Without evidence the answer is no, even if the measure is "more or less" in place. That is how a regulator works too.
Repeat
Go through the list at least annually and after every major change: a new supplier, a migration, a merger. Keep the completed list with a date as part of the evidence file.
Sixteen questions, grouped by topic from article 21.
Per question: the legal basis, what you must be able to show and what Qteco understands by it for an SME.
There is one named person responsible for information security and privacy.
Basis: art. 21(2)(a), policies on risk analysis; art. 20, governance. Evidence: a decision or job description assigning the role, and the name of the board member who is ultimately responsible. In SMEs this is often the managing director with an external vCISO or the MSP as executor; the responsibility stays with the board.
There is an up-to-date overview of systems, accounts, devices, data and suppliers.
Basis: art. 21(2)(a) and (i), risk analysis and asset management. Evidence: an inventory no more than twelve months old, with the owner and the risk per item. A well-managed Microsoft 365 and Intune environment can export most of this automatically.
All users use multi-factor authentication (MFA).
Basis: art. 21(2)(j), multi-factor authentication. Evidence: the Authentication methods report in Entra ID, 100 percent registered, and the Conditional Access policy that enforces MFA. Exceptions (service accounts) are documented.
Admin accounts are separated from regular e-mail accounts.
Basis: art. 21(2)(i), access control. Evidence: the role overview in Entra ID: admin roles only on separate accounts without a mailbox, at most a few global admins, a break-glass account documented.
Updates and security of computers are controlled centrally.
Basis: art. 21(2)(e), security in maintenance and vulnerability handling. Evidence: the patch and compliance report from Intune or the RMM platform: all devices known, updated and with EDR active.
E-mail domains are protected and phishing protection is configured.
Basis: art. 21(2)(g) and (j), cyber hygiene and secured communication. Evidence: SPF, DKIM and DMARC (policy quarantine or reject) on every domain, and an active anti-phishing policy with Safe Links and Safe Attachments.
Critical cloud data and e-mail are backed up independently.
Basis: art. 21(2)(c), business continuity and backup management. Evidence: the backup report of a solution outside the tenant, daily, immutable, stored in the EU. The Microsoft 365 recycle bin is not a backup.
A restore from backup has been tested in the past 12 months.
Basis: art. 21(2)(c), disaster recovery. Evidence: the record of the restore test: what was restored, how long it took, what was improved. A backup that has never been restored does not count.
There is a practical incident and data breach plan with contact persons.
Basis: art. 21(2)(b) and art. 23, incident handling and reporting obligation. Evidence: a plan of at most a few pages with roles, phone numbers, the 24-hour and 72-hour reporting deadlines and the route to the CSIRT and the Dutch Data Protection Authority, exercised at least annually.
Access is revoked immediately when someone leaves.
Basis: art. 21(2)(i), human resources security and access control. Evidence: an offboarding procedure with a time limit (same day) and a sample from the audit log showing accounts were actually blocked on time.
User permissions are reviewed periodically.
Basis: art. 21(2)(f) and (i), effectiveness and access control. Evidence: an access review no more than twelve months old, including guest accounts and shared folders, with the changes that resulted from it.
Processor and supplier contracts contain security agreements.
Basis: art. 21(2)(d), supply chain security. Evidence: the contracts or data processing agreements with your MSP, software suppliers and cloud services, and the evidence they provide (reporting, certification, SLA).
Employees receive annual security and privacy training.
Basis: art. 21(2)(g) and art. 20(2), cyber hygiene and training of the board. Evidence: the attendance list of the past twelve months, including the board, and the result of the phishing simulations.
Retention periods and deletion of personal data are documented.
Basis: GDPR art. 5 and 30 in conjunction with art. 21(2)(h), cryptography and data management. Evidence: the record of processing activities with retention periods and the retention policy in Microsoft 365 that enforces them technically.
Logging and security alerts are actually reviewed.
Basis: art. 21(2)(b) and (f), incident detection and effectiveness. Evidence: the audit log is enabled with a retention period, alerts are configured, and there is demonstrably someone (in-house or a SOC) who reviews them within an agreed time.
The board reviews the risks and improvement actions at least annually.
Basis: art. 20, approval and oversight by the management body. Evidence: the minutes or report of the annual management review: the risk analysis, the score on this list and the agreed improvement actions with owner and date.
Which questions cover which topic from article 21.
This shows at a glance whether a topic from the law is fully covered, and which questions you still need to pick up.
For the technical configuration of questions 03 to 08, 10 and 15 in Microsoft 365, this checklist refers to the publication Microsoft 365 Security Baseline 2026.
Frequently asked questions about the checklist.
Does this checklist apply if my organisation is not covered by NIS2?
Yes. The sixteen questions are a general security baseline. The GDPR requires appropriate security of personal data from every organisation, cyber insurers ask almost the same questions in an application, and organisations that are covered by NIS2 must ask them of their suppliers (supply chain security). Whoever has them in order is therefore also a more attractive supplier.
How many questions do I have to answer with yes to comply?
The law does not set a score; it requires appropriate and proportionate measures based on your risks. Qteco uses 14 out of 16 as a good baseline and 11 to 13 as a reasonable baseline. Below 11 the duty of care is in practice not demonstrably met. More important than the score is that every "no" has an improvement action with an owner and a date.
What is the difference with the ten measures on the NIS2 page?
The ten measures are the topics the law names. This checklist translates them into sixteen testable questions with evidence, so you can score and repeat them. The mapping table above shows which question belongs to which topic.
What do I have to report within 24 hours, and to whom?
A significant incident is reported within 24 hours as an early warning to the CSIRT and the supervisory authority of your sector, the incident notification follows within 72 hours and the final report within a month. A data breach involving personal data is additionally reported within 72 hours to the Dutch Data Protection Authority. Question 09 makes sure the contact details and the route are ready.
Can my MSP fill in this checklist for me?
Your MSP can supply the evidence for the technical questions and prepare the list, but the assessment and the approval are a task of the board (question 16). NIS2 explicitly places the responsibility with directors; outsourcing the execution is allowed, outsourcing the responsibility is not.
How often is this checklist reviewed?
Annually, and earlier when the Cyberbeveiligingswet or its implementing decrees change. Every version has a number and a date; the changes are listed at the bottom of this page. Always cite with the version number.
How to cite this publication.
This checklist is published under the Creative Commons Attribution 4.0 International licence (CC BY 4.0): you may share, adapt and quote it, including commercially, as long as you credit Qteco and state the version number. Changes per version are listed alongside.
Nguyêñ Dúc, T. (2026). NIS2 SME checklist 2026, version 2026.1. Qteco B.V., Eindhoven. https://qteco.nl/en/nis2-checklist. Licence: CC BY 4.0.
September 2026, first public version
Sixteen control questions with basis and evidence, mapping table to article 21, FAQ. Based on directive (EU) 2022/2555 and the Dutch Cyberbeveiligingswet. English edition and CC BY 4.0 licence added on 9 September 2026.
Find out in 5 minutes whether NIS2 applies to you and how many of the sixteen you already have.
The free NIS2 scan (in Dutch) determines your legal status and scores the same sixteen questions. You receive a personal report with your outcome and an action plan.
