Building an ISMS under NIS2: 10-Week Plan for SMEs

Practitioner note: This article is practice-oriented compliance documentation, not legal advice. We are a compliance specialist, not a law firm. For legally binding information, please consult a licensed attorney.

TL;DR

  • NIS2 requires ISMS-equivalent structures — Section 30 (1) BSIG
  • ISO 27001:2022 as the gold standard, not mandatory
  • 10-week build realistic for SMEs
  • 12 mandatory policies + 22 mandatory templates
  • Annual internal audit mandatory

1. Legal Basis: NIS2 vs. ISO 27001

AspectNIS2 (Section 30 BSIG)ISO 27001:2022
Mandatory statusstatutory (for in-scope entities)voluntary
Measures10 areas (subsection 2)93 controls (Annex A)
Risk assessmentrequired (subsection 1)clause 6.1.2
Certificationnot requiredpossible
FineEUR 10 million / 2%no

Practice recommendation: build an ISO 27001-compliant ISMS; certification optional.

2. Defining the ISMS Scope

Scope definition:

Recommendation for SMEs subject to NIS2: the entire company in scope.

3. Risk Analysis + Treatment Plan

  1. Asset inventory: all IT assets, data classes, business processes
  2. Threat analysis: typical threats per asset (ransomware, data breach, outage)
  3. Vulnerability assessment: current protection level
  4. Risk score: likelihood of occurrence × impact
  5. Treatment options: reduce / accept / transfer / avoid
  6. Statement of Applicability (SoA): which controls are applicable

4. 12 Mandatory Policies

  1. Information Security Policy (top-level)
  2. Acceptable Use Policy
  3. Access Control Policy
  4. Cryptographic Controls Policy
  5. Backup + Recovery Policy
  6. Patch Management Policy
  7. Incident Management Policy
  8. Supplier Management Policy
  9. Mobile Device + BYOD Policy
  10. Clear Desk + Clear Screen Policy
  11. Password Policy
  12. Physical Security Policy

5. Internal Audit + Management Review

6. 10-Week Roadmap

WeekActivity
1Appoint ISMS officer, define scope
2-3Asset inventory + risk analysis
4Risk treatment plan + SoA
5-7Draft and approve 12 policies
8Awareness training + onboarding
9Internal audit preparation + execution
10Management review + communication
22 mandatory templates (policies + work instructions + audit templates) in the NIS2 Kit.

Frequently asked questions

Do I need ISO 27001 certification?
No, NIS2 only requires equivalent structures. Certification, however, reduces audit risk and is a marketing benefit. Cost: EUR 15,000-50,000.
Who leads the ISMS?
The Information Security Officer (ISO/CISO). Management remains liable; the ISO acts under authorisation.
What is the scope?
A clearly defined area: all business processes, IT systems and locations falling under ISMS protection. For NIS2-affected organisations: usually the entire company.
Standards other than ISO 27001?
BSI IT-Grundschutz (DE), CIS Controls (US, SME-friendly), NIST CSF (US, EU-compatible), TISAX (automotive).
How often to audit?
Internal audit annually. With ISO certification: surveillance audit annually, recertification every 3 years.
Fine risk for ISMS gaps?
Section 60 BSIG: up to EUR 10 million or 2%. Plus Section 38 BSIG executive liability for gross negligence.

Sources

As of: 02 May 2026

Tools & self-tests

NIS2 Readiness Check Assess your NIS2 maturity in 10 minutes. Fining Calculator Estimate the potential fine exposure for your organisation. NIS2 Self-Test Are we in scope? Check thresholds and sector classification. NIS2 Mandatory Measures Audit 10 mandatory measures under Section 30 BSIG with maturity rating.