NIS2 for SMBs: the technical checklist for endpoints
NIS2 mandates baseline technical hygiene. Here is how to meet it concretely with Microsoft Intune: MFA, encryption, updates, compliance and audit evidence.
The NIS2 directive dramatically broadens the scope of covered entities and raises the bar on cyber hygiene. Where NIS1 targeted a narrow circle of operators, NIS2 covers many sectors — health, energy, transport, manufacturing, digital, waste management, postal services — and pulls into scope many SMBs and mid-caps that never thought they were concerned, including as suppliers to regulated entities.
For these organizations, the question becomes very concrete: how do we demonstrate baseline technical measures across the device fleet, and how do we produce evidence during an audit or a client questionnaire? The good news is that most of these measures already exist in Microsoft Intune and Conditional Access. The challenge is configuring them correctly, documenting them, and making them auditable — not buying a new tool. NIS2 also stresses management accountability: leadership can be held personally liable for a failure to put measures in place.
What NIS2 expects on technical hygiene
NIS2 emphasizes risk management and proportionate measures. On workstations and mobile devices, this translates into a well-identified baseline, drawn directly from the basic cyber-hygiene measures the directive and its transposition texts cite.
- Strong authentication (MFA) for all access, especially privileged accounts and remote access.
- Encryption of devices and removable media, to protect data at rest.
- Patch management: OS and application updates applied automatically within a controlled window.
- Access control based on device compliance: a non-compliant device does not reach the data.
- Traceability of administrative actions through a usable, retained audit log.
- Response capability: remote wipe of a lost or stolen device, and an incident-notification procedure.
Translating each requirement into an Intune policy
Authentication and access
MFA is deployed via a Conditional Access rule targeting all users, paired with blocking of legacy authentication that would bypass MFA. Compliance-conditioned access relies on an Intune compliance policy: it checks encryption, OS version and absence of compromise, then Conditional Access denies non-compliant devices. Privileged accounts deserve a stronger requirement, such as a phishing-resistant authentication method.
Data and device protection
Encryption is applied via a BitLocker (Windows) or FileVault (macOS) policy, with the key backed up to Entra ID. Updates are handled through Windows Update for Business update rings and macOS update policies, which enforce installation of critical patches within a defined window. Defender antivirus, driven from Intune, covers the malware protection required as part of basic hygiene.
Logging and incident response
NIS2 expects an ability to detect, trace and respond. The Entra and Intune audit logs record who changed which policy and when, which forms a usable audit trail during a review. On the response side, Intune allows the remote wipe of a lost or stolen device, an essential action to limit a data breach. What remains is to formalize an incident-notification procedure, since NIS2 imposes short deadlines to alert the competent authority in the event of a significant incident.
The step-by-step approach
- 1Build the inventory: which devices, which operating systems, which users and privileged accounts.
- 2Deploy the silent baseline first: encryption, antivirus, automatic updates.
- 3Set up compliance policies and test them on a pilot group.
- 4Enable MFA in report-only, with a break-glass account excluded, then switch to enforced.
- 5Condition data access on device compliance.
- 6Document everything in a dated report, per framework, ready for audit.
A concrete example: an industrial subcontractor
Picture a forty-person SMB supplying a large energy group. It is not an essential operator itself, but its client is — and sends it an annual security questionnaire demanding a baseline aligned with NIS2. Until now, the company ticked 'yes' to the boxes with no real evidence, which became untenable as the client tightened its supplier audits.
In two weeks, the team deploys encryption, antivirus and automatic updates, sets up device compliance, then rolls out MFA after a report-only phase. Along the way, it excludes a break-glass account and previews the impact of each rule, so no user is ever locked out by surprise. Above all, it generates a dated NIS2 report listing covered controls and the coverage score. The client questionnaire, which used to take days to fill from memory, is now answered by attaching an up-to-date PDF — and the company secures its place in the supply chain, turning a compliance burden into a commercial advantage.
Pitfalls that cost dearly at audit time
- Having measures in place but no dated evidence: the auditor only considers what is documented.
- MFA enabled but legacy authentication still open: the protection is illusory.
- Policies assigned to incomplete groups: some devices escape the baseline unnoticed.
- No periodic review: compliance observed one day silently drifts in the following months.
- Confusing deployment with real coverage: a policy can be assigned without being applied everywhere.
Producing the evidence with AuPoint
This is often the missing step. AuPoint generates a compliance report per framework — ISO 27001, NIS2, GDPR — with a coverage score, the list of covered and missing controls, and recent activity. Each control is tied to the requirement it satisfies, so the report reads as a direct answer to the directive rather than a raw configuration dump. The report is exportable as PDF, dated, and ready to answer an audit or a client security questionnaire without starting from scratch or reconstructing the history by hand.
Beyond evidence, AuPoint reduces risk at every deployment: a plain-language catalog, impact preview before applying, an 'exclude me' option and break-glass account to avoid any lockout, and one-click reversibility. You move toward NIS2 compliance without ever putting production at risk, and you track configuration drift continuously rather than at the fateful moment of the audit.
FAQ
Is my SMB in scope for NIS2?
NIS2 targets entities in the listed sectors above certain size thresholds, but also, in practice, their suppliers through the contractual requirements of their clients. Even outside direct scope, a client security questionnaire will often impose the same technical baseline.
Does NIS2 mandate specific tools?
No. The directive mandates risk-management objectives, not products. Microsoft Intune and Conditional Access are enough to cover the technical baseline on endpoints, provided they are correctly configured and documented. What matters to an auditor is that the measures are appropriate, effective and evidenced, not the brand name on the console.
How often should I review compliance?
A quarterly review is a good rhythm. AuPoint tracks drift continuously, so you catch a device that fell out of compliance or an unassigned policy early, before it becomes a finding flagged at audit.
Start with a free diagnostic: connect your tenant to AuPoint, get your NIS2 score in minutes, and see exactly which controls to enable and document. You turn a regulatory obligation into a concrete, prioritized action plan today, and keep the evidence current as your fleet evolves.