
The NIS2 directive has become a must-discuss topic for Belgian businesses. Many SME managers are now asking themselves the same questions: am I concerned? What do I need to implement? Is it solely an administrative obligation or a genuine issue of cyber security ?
For SMEs in Brussels and Belgium, NIS2 should not be seen as a theoretical constraint reserved for large companies. Even when an SME is not directly subject to the law, it can be indirectly impacted by its clients, suppliers, or partners.
This article explains what NIS2 means in practice for a Belgian SME, who is concerned, and what actions to take to remain in the best possible conditions.
NIS2: what are we talking about?
The NIS2 Directive is a European regulation intended to strengthen the cybersecurity level of organisations that play an important role in the economy and society. It replaces the first NIS Directive (see the Centre for Cybersecurity Belgiumand significantly expands the number of organisations concerned.
In Belgium, this directive has been transposed via the NIS2 Act. The objective is clear: to improve the security of networks and information systems, to strengthen incident management, and to establish national supervision. It sets out minimum obligations regarding cybersecurity, risk management, incident notification, and supply chain security.
The sectors concerned are numerous: energy, transport, health, water, digital infrastructure, digital services, public administrations, managed service providers, critical manufacturing industry, and many others.
What NIS2 requires in practice
Specifically, NIS2 requires the organisations concerned to better manage their IT risks. This is not simply a matter of having antivirus software installed on computers. It must be possible to demonstrate that the company has identified its risks, implemented appropriate protective measures, documented its procedures, and planned a response in the event of an incident.
For a Belgian SME, this can concern several very concrete aspects:
- User account and access rights management; ;
- multi-factor authentication;
- protection of workstations and servers; ;
- backups and their restore testing ;
- security incident management ;
- Microsoft 365 and cloud tools configuration; ;
- remote access security ;
- the IT infrastructure documentation ;
- IT vendor and supplier management.
For a small or medium-sized enterprise (SME) that does not yet have a formalised security policy, this can seem daunting. However, in practice, many of these measures are accessible and proportionate to the size of the company.
Veuillez traduire le texte suivant en anglais (UK), en ne retournant que le texte traduit et sans ajouter de commentaires ou de guillemets supplémentaires. Les entités qui sont soumises à la directive NIS2 en Belgique comprennent : 1. **Les entités essentielles** : Ces entités sont actives dans les secteurs jugés critiques pour le fonctionnement de la société et de l'économie. Il s'agit notamment des secteurs suivants : * Énergie (électricité, pétrole, gaz) * Transport (aérien, ferroviaire, maritime, routier) * Banque * Marchés financiers * Santé * Eau potable * Eaux usées * Infrastructure numérique * Gestion d'infrastructures critiques TIC * Espace * Services postaux et d'expédition * Gestion des déchets * Production, fabrication et distribution de produits chimiques 2. **Les entités importantes** : Ces entités sont actives dans une gamme plus large de secteurs, mais sont toujours considérées comme ayant un impact significatif sur la sécurité et la résilience. Ces secteurs comprennent : * Services numériques (fournisseurs de services d'hébergement, services en ligne, plateformes de négociation en ligne) * Fabrication de biens critiques (produits du génie, machines, produits métalliques, produits du bois, textiles, papier, plastiques) * Traitement des denrées alimentaires * Production de denrées alimentaires * Certains services professionnels (services juridiques, comptables, fiscaux, de conseil, de publicité) * Recherche * Fabrication de dispositifs médicaux * Fabrication de produits informatiques, électroniques et optiques * Fabrication de matériel électrique * Services de cybersécurité * Services informatiques et TIC Il est important de noter que la classification exacte peut dépendre de la taille de l'entité, mesurée par le nombre d'employés ou le chiffre d'affaires annuel. Les petites entreprises peuvent également être couvertes si elles sont considérées comme particulièrement importantes dans leur secteur ou si elles font partie d'une chaîne d'approvisionnement critique. La transposition de la directive NIS2 en droit belge est en cours, et les détails précis concernant la portée et les obligations spécifiques sont susceptibles d'être précisés dans les textes législatifs nationaux.
Not all Belgian SMEs are automatically subject to NIS2. To determine if your company is affected, several criteria must be analysed.
The businesses directly involved
NIS2 directly applies to companies that operate in sectors defined as essential or important, AND that reach certain size thresholds (generally: at least 50 employees or more than €10 million in turnover).
Key sectors include, but are not limited to: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration.
Key sectors include: postal services, waste management, chemicals, food, manufacturing, digital providers.
Businesses indirectly affected
Even if your SME does not meet the thresholds or operate in a regulated sector, it may still be affected if it is a supplier, subcontractor, or service provider to an organisation subject to NIS2.
In practice, this means that a Brussels-based SME providing IT, logistics, legal, accounting, or communication services to a larger organisation may be subject to contractual security requirements.
This is why, even for SMEs that are not directly targeted by NIS2, an IT security approach remains important.
NIS2 and SMEs indirectly affected
Many SMEs in Belgium will not be directly subject to NIS2. However, they will still need to adapt. Why? Because NIS2 also strengthens requirements within the supply chain.
Let's take a simple example. A Brussels-based SME provides IT, logistics, or consulting services to a player in the health or energy sector. This player, subject to NIS2, must ensure that its suppliers also comply with minimum security standards. It can therefore ask the SME for guarantees, documentation, or even certification.
In this context, an SME that has not prepared itself risks losing contracts or being unable to respond to tenders.
The areas where the pressure is greatest are: outsourced IT services, cloud, Microsoft 365 tools, and remote access. Small and medium-sized enterprises (SMEs) that manage sensitive data or access to their clients' critical systems must be particularly vigilant.
Concrete measures to implement
NIS2 obligations should not be understood as a simple list of documents to produce. They imply real IT risk management. The company must know where its weaknesses lie, what measures already exist, and what actions should be prioritised.
For an SME, concrete measures can be grouped into several categories.
Securing access and identities
The first priority concerns user accounts. Today, many attacks begin with a compromised Microsoft 365 account, a reused password, or poorly secured administrator access.
The recommended actions are:
- enable multi-factor authentication ;
- Protect administrator accounts ;
- Delete old user accounts; ;
- restrict access rights; ;
- implement conditional access policies ;
- use a professional password manager ;
- Monitor suspicious connections.
In a Microsoft 365 environment, tools such as Entra ID, Conditional Access, Defender and Intune can significantly enhance security, provided they are correctly configured.
GVISION supports SMEs in setting up and securing Microsoft 365: user accounts, MFA, access rights, Exchange., SharePoint, OneDrive, Teams, Intune and device protection.
Protecting workstations, servers and applications
The second priority concerns the devices used by the company: PCs, laptops, servers, virtual machines, business applications, company smartphones.
A small and medium-sized enterprise must at a minimum plan for:
- A professional antivirus or EDR solution ;
- centralised update management ;
- an inventory of appliances; ;
- monitoring of critical alerts; ;
- a clear policy for personal devices ;
- ransomware protection;
- a hardening of roles and servers.
The objective isn't just to install a tool. It's necessary to be able to monitor the actual state of the IT park and react quickly when a problem appears.
This is precisely the role of a structured outsourcing To monitor, maintain, secure, and document the company's IT environment.
Make backups reliable
Backups are a cornerstone of cybersecurity. In the event of a ransomware attack, accidental deletion, or server failure, the question isn't “do you have a backup?”, but rather “can you restore your data quickly?”.
A small to medium-sized enterprise (SME) should check:
- What data is saved? ;
- where the backups are stored ;
- if a copy is isolated or outsourced; ;
- if Microsoft 365 is also backed up; ;
- how often are restorations tested; ;
- How long can the company operate without servers, emails or business applications?.
An untested backup gives a false sense of security. In a NIS2 approach, it must be possible to prove that the restoration works.
GVISION can help SMEs implement a suitable backup strategy: servers, critical workstations, Microsoft 365, OneDrive., SharePoint, Exchange, local data and cloud backups.
Prepare incident management
NIS2 strongly emphasises incident management. An SME must know what to do in the event of a cyberattack, data leak, account compromise, or significant unavailability.
A simple procedure should answer these questions:
- Who should be contacted first?
- Who makes the decision to isolate a workstation or a server?
- How to communicate internally?
- What elements should be kept as evidence?
- Who is contacting the IT provider?
- How to restart the activity?
- Which authorities or stakeholders need to be informed if necessary?
Even a short procedure is better than total improvisation on the day of the incident.
Documenting the IT environment
Documentation is often the weak point for SMEs. However, without documentation, it is difficult to prove that the environment is under control.
Basic documentation should include:
- the inventory of workstations and servers; ;
- The list of critical software ;
- network documentation ;
- administrator access; ;
- backup procedures; ;
- IT contracts ;
- onboarding and offboarding procedures ;
- the security measures in place ;
- supervision reports.
This documentation facilitates compliance, but also daily support.
At GVISION, we always recommend transforming IT documentation into an operational tool. It should help to resolve incidents more quickly, facilitate hardware replacements, secure access, and prevent all IT knowledge resting with a single person.
Concrete risks for an SME that does not prepare
Failing to prepare for NIS2 can create several risks for an SME.
The first risk is operational. A cyber-attack can block emails, files, business applications, the RDP server, the ERP, VoIP telephony, or access to customer data. For an SME, a few hours of downtime can have a significant impact on activity.
The second risk is commercial. Large companies and public organisations are increasingly incorporating IT security criteria into their tender documents and supplier contracts. SMEs that cannot demonstrate a minimum level of cybersecurity maturity risk losing business opportunities.
The third risk is legal and regulatory. If an organisation directly subject to NIS2 suffers an incident partly related to an insecure supplier, questions of liability may arise. Furthermore, if an SME is directly subject to NIS2 and does not comply with its obligations, it exposes itself to sanctions.
Finally, reputational risk is a real threat. A leak of customer data, a ransomware attack, or an email compromise can have a lasting impact on the trust of customers and partners.
NIS2 Brussels:Local specificities and challenges
SMEs located in Brussels operate within a particular environment. The region concentrates numerous non-profit organisations, consultancies, service companies, public bodies, international institutions, B2B companies, and suppliers to large accounts.
This proximity to more regulated organisations increases the requirements. A Brussels-based SME can quickly be faced with stricter security demands, even if it is not directly targeted by NIS2.
For local businesses, the priorities are often as follows:
- Securing Microsoft 365 ;
- Protect remote access; ;
- Set up structured IT outsourcing; ;
- document the network and servers; ;
- make backups more reliable ;
- protect user posts ;
- train teams on phishing risks ;
- have a Responsive IT provider in Brussels or in Belgium.
Local IT support remains important. In the event of a critical failure, network incident or server problem, a rapid intervention can make all the difference. An IT provider who knows the SME’s environment can also better prioritise actions and avoid solutions that are too complex or poorly suited.
GVISION supports SMEs in Brussels and Belgium with a practical approach: IT support, Managed IT services, Microsoft 365, cyber security, backups, network infrastructure, servers, cloud and VoIP telephony. The goal is to have a reliable, secure and well-maintained environment over time.
Where to start? A step-by-step approach
To move forward effectively, a small or medium-sized enterprise (SME) must not start by buying several tools at random. The right approach is progressive.
1. Check if your SME is affected
The first step is to analyse your situation: company size, business sector, services provided, clients and suppliers. This analysis will determine if you are directly targeted, indirectly impacted, or simply being cautious.
2. Conduct an IT and security audit
An audit assesses the current state of your infrastructure: workstations, servers, access, Microsoft 365, backups, user rights, network, telephony, and business applications. It identifies existing weaknesses and allows for the creation of a prioritised action plan.
3. Implement priority measures
Based on the audit, the actions to be taken first are selected: MFA, backups, updates, endpoint protection, access rights, user training. These basic measures often have the greatest impact for the lowest cost.
4. Document and structure
NIS2 compliance also relies on the ability to prove what has been implemented. It is therefore necessary to document the environment, security measures, procedures, and responsibilities. This documentation is also useful on a daily basis for support and maintenance.
5. Maintain and supervise over time
Cybersecurity is not a one-off project. Systems need to be kept up to date, alerts monitored, access regularly reviewed and measures adapted according to the evolution of the business and threats.
This is the approach GVISION recommends: progressive, tailored to each SME, focused on concrete results and sustained over time.
GVISION and NIS2 preparedness:A pragmatic approach for Belgian SMEs
For many SMEs, managing the full scope of NIS2 requirements alone is difficult. Leaders don't always have the time, in-house skills, or necessary tools to properly monitor IT security.
GVISION supports Belgian SMEs with a pragmatic approach: securing what is critical, documenting what needs to be, implementing suitable tools and maintaining the environment over time.
Our support can include:
- IT audit and cybersecurity ;
- Microsoft 365 security ;
- set up MFA and access management ;
- Workstation and server protection ;
- Local, cloud and Microsoft 365 backup ;
- supervision and maintenance ;
- IT documentation ;
- User support ;
- incident management;
- Managed IT services with regular follow-up; ;
- Conseils pour améliorer la maturité de la cybersécurité.
The goal isn't to sell a one-size-fits-all solution to all businesses. A small to medium-sized enterprise with 10 users, a non-profit organisation, an accounting firm, a construction company, or a business with multiple sites don't have the same priorities.
The right approach is to start with what already exists, identify the most significant risks, and build a realistic action plan.
Microsoft 365 et NIS2 :An environment to secure as a priority
Microsoft 365 has become central to many Belgian SMEs. Emails, files, calendars, Teams, SharePoint et OneDrive sont souvent au cœur du fonctionnement quotidien.
But Microsoft 365 Poorly configured can also become an entry point for cyberattacks. In a NIS2 SME Belgium approach, it is therefore essential to correctly secure the environment.
The key points are:
- activate MFA for all users ;
- configure conditional access policies ;
- Activate Defender for Business ;
- configure email inboxes against phishing and spam; ;
- manage SharePoint and OneDrive permissions; ;
- Back up Microsoft 365 With a Third-Party Tool ;
- monitor connections and alerts via Entra ID and Defender; ;
- manage devices with Intune; ;
- train users in best practices.
GVISION offers complete Microsoft 365 security: accounts, MFA, Entra ID, Conditional Access, Exchange, SharePoint, OneDrive, Teams, Intune, Defender, and backups.
How should you choose your IT service provider for NIS2?
The choice of IT provider is an important step. NIS2 compliance does not solely rely on tools, but on a method, documentation, and monitoring.
A good provider must be able to understand the reality of an SME: limited budget, need for simplicity, reliance on business tools, need to move quickly, and the importance of business continuity.
Before choosing a partner, ask the following questions:
- Can he carry out a clear IT audit?
- Does he know Microsoft 365, Entra ID, Intune, Defender et SharePoint ?
- does it offer a Managed IT services with monitoring and reporting?
- Can it handle backups and restore tests?
- Does it document the IT environment?
- Does it propose an incident management procedure?
- Can he intervene quickly in Brussels or Belgium?
- Does he understand the challenges faced by B2B SMEs?
- Can it support the company in the long term, and not just when an incident occurs?
Deliverables are also important. Serious support must produce concrete elements:
- audit report ;
- prioritised action plan;
- Network documentation ;
- Inventory of equipment ;
- security report ;
- backup status; ;
- interlocutory proceedings; ;
- Budgeted recommendations.
For an SME, the objective is not to obtain a theoretical report of 100 pages. The objective is to have real, understandable, and maintainable security.
This is GVISION's philosophy: to offer clear support, tailored to Belgian SMEs and focused on tangible results.
Conclusion :NIS2 is an opportunity to strengthen your IT security.
NIS2 isn't just another regulatory obligation. It's also an opportunity to seriously review your company's IT security.
For a small and medium-sized enterprise in Belgium, the priority is to answer three questions:
- Are we directly or indirectly affected by NIS2?
- Is our IT infrastructure sufficiently secure?
- Do we have the necessary evidence, procedures, and safeguards in case of an incident?
The best way to move forward is to start with an IT audit. This allows you to identify risks, prioritise actions, and build a roadmap tailored to your SME.
Whether you are based in Brussels, Wallonia or Flanders, cybersecurity is becoming a criterion of trust. Companies that anticipate will be better prepared, more credible with their clients and more resilient in the face of incidents.
GVISION supports Belgian SMEs in their NIS2 preparation, their Managed IT services, their cyber security and their Microsoft 365 environment.
Do you want to know if your SME is affected by NIS2 or get a concrete action plan? Contact GVISION to carry out an IT and cybersecurity audit of your company.
FAQ — NIS2 SMEs Belgium
Is a small Belgian SME automatically covered by NIS2?
No, not all small SMEs are automatically affected. The application particularly depends on the size, sector of activity, and service provided. However, a small SME could be indirectly impacted if it is a supplier or subcontractor to an organisation subject to NIS2.
What are the penalties for non-compliance with NIS2?
For essential entities directly subject to NIS2, the penalties can be significant. For others, the risks are more commercial and contractual: loss of markets, client demands, difficulties accessing certain tenders.
What is the difference between NIS and NIS2?
NIS2 significantly expands the scope of application compared to NIS. More sectors are affected, requirements are reinforced, and management responsibility is clarified. NIS2 also places greater emphasis on supply chain security.
Concrètement, qu'est-ce qu'une PME doit faire face à NIS2 ?
The first step is to assess whether the SME is directly or indirectly affected. This is then followed by an IT audit to identify existing vulnerabilities. The priority measures are generally: MFA, backups, endpoint protection, access rights, and documentation.
Does GVISION support SMEs with NIS2?
Yes. GVISION offers practical support: audits, action plans, Microsoft 365 security, IT outsourcing, backups, and documentation. The aim is to implement real security, tailored to the size and needs of the SME.
Does NIS2 apply to Belgian non-profit organisations and public bodies?
Yes, in many cases. Public administrations are concerned and certain non-profit organisations operating in essential sectors may also be targeted. It is important to assess each situation individually.



