Building an ISMS under NIS2: 10-Week Plan for SMEs

Practitioner note: This article is practice-oriented compliance documentation, not legal advice. We are a compliance specialist, not a law firm. For legally binding information, please consult a licensed attorney.

TL;DR

  • NIS2 requires ISMS-equivalent structures — Section 30 (1) BSIG
  • ISO 27001:2022 as the gold standard, not mandatory
  • 10-week build realistic for SMEs
  • 12 mandatory policies + 22 mandatory templates
  • Annual internal audit mandatory

1. Legal Basis: NIS2 vs. ISO 27001

AspectNIS2 (Section 30 BSIG)ISO 27001:2022
Mandatory statusstatutory (for in-scope entities)voluntary
Measures10 areas (subsection 2)93 controls (Annex A)
Risk assessmentrequired (subsection 1)clause 6.1.2
Certificationnot requiredpossible
FineEUR 10 million / 2%no

Practice recommendation: build an ISO 27001-compliant ISMS; certification optional.

2. Defining the ISMS Scope

Scope definition:

Recommendation for SMEs subject to NIS2: the entire company in scope.

3. Risk Analysis + Treatment Plan

  1. Asset inventory: all IT assets, data classes, business processes
  2. Threat analysis: typical threats per asset (ransomware, data breach, outage)
  3. Vulnerability assessment: current protection level
  4. Risk score: likelihood of occurrence × impact
  5. Treatment options: reduce / accept / transfer / avoid
  6. Statement of Applicability (SoA): which controls are applicable

4. 12 Mandatory Policies

  1. Information Security Policy (top-level)
  2. Acceptable Use Policy
  3. Access Control Policy
  4. Cryptographic Controls Policy
  5. Backup + Recovery Policy
  6. Patch Management Policy
  7. Incident Management Policy
  8. Supplier Management Policy
  9. Mobile Device + BYOD Policy
  10. Clear Desk + Clear Screen Policy
  11. Password Policy
  12. Physical Security Policy

5. Internal Audit + Management Review

6. 10-Week Roadmap

WeekActivity
1Appoint ISMS officer, define scope
2-3Asset inventory + risk analysis
4Risk treatment plan + SoA
5-7Draft and approve 12 policies
8Awareness training + onboarding
9Internal audit preparation + execution
10Management review + communication
22 mandatory templates (policies + work instructions + audit templates) in the NIS2 Kit.

Sources

As of: 02 May 2026

Sources