Cybersecurity

The 2026 SME Cybersecurity Checklist for GDPR, NIS2 and DORA

TuniCyberLabs Team
6 min read
Updated

GDPR, NIS2 and DORA now reach far beyond big enterprise. This SME cybersecurity checklist turns NIS2 compliance, DORA compliance and GDPR security into a clear, practical set of actions you can actually complete.

Three letters have quietly rewritten the compliance obligations of European businesses: NIS2, DORA, and the ever-present GDPR. What used to be an enterprise concern now reaches deep into the small and medium business world, and the penalties are no longer symbolic. If you run an SME and you have been hoping these frameworks do not apply to you, this checklist will tell you plainly where you stand and what to do about it. Good SME cybersecurity is now a legal requirement, not a nice-to-have.

Why These Rules Now Reach Your Business

For years, cybersecurity regulation targeted large enterprises and critical infrastructure. That era is over. The EU has deliberately widened the net because attackers exploit the weakest link, and smaller suppliers are often that link. Three frameworks matter most.

  • GDPR governs the personal data of EU residents and has applied to businesses of every size since 2018. It is the baseline.
  • NIS2 is the updated Network and Information Security Directive. It dramatically expands the sectors and company sizes in scope, pulling in many medium-sized businesses that were previously exempt, and it holds management personally accountable.
  • DORA, the Digital Operational Resilience Act, targets financial entities and, critically, their technology and service providers. If you supply software or services to a financial firm, DORA reaches you through your contracts.

The common thread is that being small no longer means being ignored, either by regulators or by attackers.

First: Figure Out What Actually Applies to You

Before doing anything, scope your obligations. Guessing wastes effort in the wrong places.

  • Do you process personal data of EU residents? Then GDPR applies. This is nearly universal.
  • What sector are you in, and how big are you? NIS2 covers named essential and important sectors, including many that SMEs operate in, typically above small-business size thresholds. Check whether your sector and headcount bring you into scope.
  • Do you serve financial-sector clients? If you provide ICT services to banks, insurers, or investment firms, DORA obligations will flow to you through their contracts even if you are not a financial entity yourself.
  • Where does your data live? Data residency and cross-border transfer rules affect all three frameworks and your architecture choices.

Write down which frameworks apply and why. This scoping document is the foundation everything else builds on, and auditors will ask for it.

Governance and Accountability: The Part SMEs Skip

The biggest shift in NIS2 and DORA is that cybersecurity is now a leadership responsibility, not something delegated to whoever manages the laptops. Management can be held accountable for failures. Put governance in place.

  • Assign clear ownership. Someone at leadership level owns cybersecurity, even if the hands-on work is outsourced.
  • Do risk assessments and write them down. Both NIS2 and DORA expect documented, regularly reviewed risk management, not informal awareness.
  • Maintain policies that exist on paper. Access control, acceptable use, incident response, and data protection policies need to be written, approved, and followed.
  • Train leadership, not just staff. Decision-makers are expected to understand the risks they are accountable for.

The Technical Controls Checklist

Across all three frameworks the expected technical baseline is remarkably consistent. Implement these and you satisfy the bulk of what each demands.

  • Multi-factor authentication on all accounts, especially anything privileged or internet-facing.
  • Access control on least-privilege principles, reviewed regularly, with prompt revocation when people leave.
  • Encryption of sensitive data in transit and at rest.
  • Patch and vulnerability management on a defined schedule, with a way to prioritise critical fixes fast.
  • Network segmentation so a breach in one area cannot spread freely.
  • Logging and monitoring so you can actually detect an incident rather than learning about it from a customer.
  • Secure, tested backups that are isolated from your live environment for ransomware resilience.
  • Endpoint protection on all devices.

None of this is exotic. It is disciplined execution of well-understood controls, which is exactly what regulators are checking for.

Incident Response and Reporting Deadlines

This is where the frameworks get specific and unforgiving, and where unprepared SMEs get caught out. Each has notification duties on tight clocks.

  • GDPR requires notifying the supervisory authority within 72 hours of becoming aware of a qualifying personal data breach.
  • NIS2 introduces its own layered reporting, including an early warning within 24 hours of awareness of a significant incident, followed by more detailed reports.
  • DORA sets out its own incident classification and reporting expectations for ICT-related incidents affecting financial entities.

The practical implication is that you need an incident response plan written and rehearsed before anything happens. When an incident hits, the clock is already running, and improvising a reporting process under pressure is how deadlines get missed and penalties compound. Build the plan, assign the roles, and run a tabletop exercise at least once so it is muscle memory.

Third-Party and Supply Chain Risk

All three frameworks care intensely about the vendors and partners you rely on, because their weaknesses become yours. This is especially explicit in NIS2 and DORA.

  • Inventory your suppliers, particularly those touching your data or systems.
  • Assess their security posture before onboarding and periodically after. Ask for evidence, not assurances.
  • Get the right contractual clauses in place covering security obligations, incident notification, and audit rights. DORA in particular expects specific provisions in ICT contracts.
  • Map your critical dependencies so you understand what happens to you if a key provider fails or is breached.

Your compliance is only as strong as the weakest vendor in your chain, and regulators now expect you to prove you have looked.

Your Consolidated 2026 Compliance Checklist

Use this as a working list. Each item advances NIS2 compliance, DORA compliance, and GDPR security simultaneously because the requirements overlap heavily.

  • Scoping document identifying which frameworks apply and why
  • Named leadership owner for cybersecurity, with documented risk assessments
  • Written, approved policies for access, incident response, and data protection
  • MFA, least-privilege access, and prompt offboarding in force
  • Encryption in transit and at rest, secrets properly managed
  • Patch management and vulnerability scanning on a schedule
  • Network segmentation, logging, and monitoring in place
  • Isolated, tested backups
  • Incident response plan written, roles assigned, tabletop rehearsed
  • Breach notification procedures aligned to 24 and 72-hour clocks
  • Supplier inventory, security assessments, and contractual clauses
  • Personal data mapped, privacy notices current, data subject rights honoured

Work through it methodically. You do not have to finish everything this week, but you do need a plan showing you are progressing, because demonstrating a good-faith, documented effort matters enormously if regulators ever come asking.

How TuniCyberLabs Helps

Compliance across GDPR, NIS2, and DORA is genuinely complex, and most SMEs neither have nor want a full-time compliance team to untangle it. TuniCyberLabs bridges that gap: we scope which frameworks apply to you, run a gap assessment against this checklist, implement the technical controls, and help you build the governance, incident response, and supplier processes the regulations demand. As an EU-structured firm, HQ in Tallinn, office in Limassol, engineering in Sousse, we understand these frameworks from the inside and deliver the work at nearshore cost, so getting compliant does not blow your budget. You get a defensible security posture and the documentation to prove it.

Unsure where your business stands on NIS2, DORA, or GDPR? Contact TuniCyberLabs for a compliance gap assessment and a clear roadmap to close it.

TAGS
NIS2DORAGDPRSME securitycompliancerisk managementincident responseEU regulation

Frequently Asked Questions

Does NIS2 apply to small and medium-sized businesses?

+

Often, yes. NIS2 dramatically expands the sectors and company sizes in scope compared with the original directive, pulling in many medium-sized businesses that were previously exempt. Whether it covers you depends on your sector, the directive names essential and important sectors, several of which SMEs operate in, and on size thresholds, typically above small-business headcount. The practical first step is a written scoping document recording which frameworks apply to you and why; auditors will ask for it.

Does DORA affect companies that are not financial institutions?

+

Yes. DORA, the Digital Operational Resilience Act, targets financial entities and, critically, their technology and service providers. If you supply software or ICT services to banks, insurers, or investment firms, DORA obligations reach you through your clients' contracts even though you are not a financial entity yourself. Expect specific contractual provisions covering security obligations, incident notification, and audit rights, plus expectations around incident classification and reporting for ICT-related incidents.

How quickly must a security incident be reported under GDPR and NIS2?

+

The clocks are tight. GDPR requires notifying the supervisory authority within 72 hours of becoming aware of a qualifying personal data breach. NIS2 adds layered reporting, including an early warning within 24 hours of awareness of a significant incident, followed by more detailed reports. Because the clock starts immediately, an incident response plan needs to be written, roles assigned, and rehearsed before anything happens, improvising a reporting process under pressure is how deadlines get missed.

Can managers be held personally accountable for cybersecurity failures?

+

Under NIS2, yes, management can be held accountable for cybersecurity failures, which is the biggest shift the directive brings for SMEs. Cybersecurity is now a leadership responsibility rather than something delegated to whoever manages the laptops. In practice this means naming a leadership-level owner for security even if hands-on work is outsourced, documenting and regularly reviewing risk assessments, maintaining written, approved policies, and training decision-makers themselves, not just staff, on the risks they answer for.

What security measures satisfy GDPR, NIS2 and DORA at the same time?

+

The technical baseline the three frameworks expect is remarkably consistent, so one set of controls advances all of them: multi-factor authentication on every account, least-privilege access with prompt offboarding, encryption in transit and at rest, scheduled patch and vulnerability management, network segmentation, logging and monitoring, secure backups tested and isolated from the live environment for ransomware resilience, and endpoint protection on all devices. Regulators are checking for disciplined execution of these well-understood controls, not exotic technology.

Need help with
this topic
?

Our team specializes in the technologies and strategies discussed in this article. Let’s talk about how we can help your business.

Get in Touch