Three letters have quietly rewritten the compliance obligations of European businesses: NIS2, DORA, and the ever-present GDPR. What used to be an enterprise concern now reaches deep into the small and medium business world, and the penalties are no longer symbolic. If you run an SME and you have been hoping these frameworks do not apply to you, this checklist will tell you plainly where you stand and what to do about it. Good SME cybersecurity is now a legal requirement, not a nice-to-have.
Why These Rules Now Reach Your Business
For years, cybersecurity regulation targeted large enterprises and critical infrastructure. That era is over. The EU has deliberately widened the net because attackers exploit the weakest link, and smaller suppliers are often that link. Three frameworks matter most.
- ▸GDPR governs the personal data of EU residents and has applied to businesses of every size since 2018. It is the baseline.
- ▸NIS2 is the updated Network and Information Security Directive. It dramatically expands the sectors and company sizes in scope, pulling in many medium-sized businesses that were previously exempt, and it holds management personally accountable.
- ▸DORA, the Digital Operational Resilience Act, targets financial entities and, critically, their technology and service providers. If you supply software or services to a financial firm, DORA reaches you through your contracts.
The common thread is that being small no longer means being ignored, either by regulators or by attackers.
First: Figure Out What Actually Applies to You
Before doing anything, scope your obligations. Guessing wastes effort in the wrong places.
- ▸Do you process personal data of EU residents? Then GDPR applies. This is nearly universal.
- ▸What sector are you in, and how big are you? NIS2 covers named essential and important sectors, including many that SMEs operate in, typically above small-business size thresholds. Check whether your sector and headcount bring you into scope.
- ▸Do you serve financial-sector clients? If you provide ICT services to banks, insurers, or investment firms, DORA obligations will flow to you through their contracts even if you are not a financial entity yourself.
- ▸Where does your data live? Data residency and cross-border transfer rules affect all three frameworks and your architecture choices.
Write down which frameworks apply and why. This scoping document is the foundation everything else builds on, and auditors will ask for it.
Governance and Accountability: The Part SMEs Skip
The biggest shift in NIS2 and DORA is that cybersecurity is now a leadership responsibility, not something delegated to whoever manages the laptops. Management can be held accountable for failures. Put governance in place.
- ▸Assign clear ownership. Someone at leadership level owns cybersecurity, even if the hands-on work is outsourced.
- ▸Do risk assessments and write them down. Both NIS2 and DORA expect documented, regularly reviewed risk management, not informal awareness.
- ▸Maintain policies that exist on paper. Access control, acceptable use, incident response, and data protection policies need to be written, approved, and followed.
- ▸Train leadership, not just staff. Decision-makers are expected to understand the risks they are accountable for.
The Technical Controls Checklist
Across all three frameworks the expected technical baseline is remarkably consistent. Implement these and you satisfy the bulk of what each demands.
- ▸Multi-factor authentication on all accounts, especially anything privileged or internet-facing.
- ▸Access control on least-privilege principles, reviewed regularly, with prompt revocation when people leave.
- ▸Encryption of sensitive data in transit and at rest.
- ▸Patch and vulnerability management on a defined schedule, with a way to prioritise critical fixes fast.
- ▸Network segmentation so a breach in one area cannot spread freely.
- ▸Logging and monitoring so you can actually detect an incident rather than learning about it from a customer.
- ▸Secure, tested backups that are isolated from your live environment for ransomware resilience.
- ▸Endpoint protection on all devices.
None of this is exotic. It is disciplined execution of well-understood controls, which is exactly what regulators are checking for.
Incident Response and Reporting Deadlines
This is where the frameworks get specific and unforgiving, and where unprepared SMEs get caught out. Each has notification duties on tight clocks.
- ▸GDPR requires notifying the supervisory authority within 72 hours of becoming aware of a qualifying personal data breach.
- ▸NIS2 introduces its own layered reporting, including an early warning within 24 hours of awareness of a significant incident, followed by more detailed reports.
- ▸DORA sets out its own incident classification and reporting expectations for ICT-related incidents affecting financial entities.
The practical implication is that you need an incident response plan written and rehearsed before anything happens. When an incident hits, the clock is already running, and improvising a reporting process under pressure is how deadlines get missed and penalties compound. Build the plan, assign the roles, and run a tabletop exercise at least once so it is muscle memory.
Third-Party and Supply Chain Risk
All three frameworks care intensely about the vendors and partners you rely on, because their weaknesses become yours. This is especially explicit in NIS2 and DORA.
- ▸Inventory your suppliers, particularly those touching your data or systems.
- ▸Assess their security posture before onboarding and periodically after. Ask for evidence, not assurances.
- ▸Get the right contractual clauses in place covering security obligations, incident notification, and audit rights. DORA in particular expects specific provisions in ICT contracts.
- ▸Map your critical dependencies so you understand what happens to you if a key provider fails or is breached.
Your compliance is only as strong as the weakest vendor in your chain, and regulators now expect you to prove you have looked.
Your Consolidated 2026 Compliance Checklist
Use this as a working list. Each item advances NIS2 compliance, DORA compliance, and GDPR security simultaneously because the requirements overlap heavily.
- ▸Scoping document identifying which frameworks apply and why
- ▸Named leadership owner for cybersecurity, with documented risk assessments
- ▸Written, approved policies for access, incident response, and data protection
- ▸MFA, least-privilege access, and prompt offboarding in force
- ▸Encryption in transit and at rest, secrets properly managed
- ▸Patch management and vulnerability scanning on a schedule
- ▸Network segmentation, logging, and monitoring in place
- ▸Isolated, tested backups
- ▸Incident response plan written, roles assigned, tabletop rehearsed
- ▸Breach notification procedures aligned to 24 and 72-hour clocks
- ▸Supplier inventory, security assessments, and contractual clauses
- ▸Personal data mapped, privacy notices current, data subject rights honoured
Work through it methodically. You do not have to finish everything this week, but you do need a plan showing you are progressing, because demonstrating a good-faith, documented effort matters enormously if regulators ever come asking.
How TuniCyberLabs Helps
Compliance across GDPR, NIS2, and DORA is genuinely complex, and most SMEs neither have nor want a full-time compliance team to untangle it. TuniCyberLabs bridges that gap: we scope which frameworks apply to you, run a gap assessment against this checklist, implement the technical controls, and help you build the governance, incident response, and supplier processes the regulations demand. As an EU-structured firm, HQ in Tallinn, office in Limassol, engineering in Sousse, we understand these frameworks from the inside and deliver the work at nearshore cost, so getting compliant does not blow your budget. You get a defensible security posture and the documentation to prove it.
Unsure where your business stands on NIS2, DORA, or GDPR? Contact TuniCyberLabs for a compliance gap assessment and a clear roadmap to close it.
