The law is here and the questionnaires are coming. If you start now you do not have to do everything at once: the requirements differ sharply in how much they return per hour you put in. This is the order we would keep.
What gives the most return for the least effort?
Multi-factor authentication. It is the first question on virtually every questionnaire, it is the one measure that makes a stolen password worthless in most cases, and switching it on takes an afternoon on most cloud platforms. Require MFA on email, VPN and every system reachable from the internet, including the access your IT supplier uses. More on that in Is MFA mandatory under NIS2?
What protects my own business most?
Your backup, and above all the question of whether it survives a ransomware attack. Three checks: are backups made automatically, is at least one copy out of reach of your network, and have you tested in the past year that restoring actually works? That last one is where most companies come unstuck. See What requirements apply to backups and continuity?
What has to be on paper before something goes wrong?
An incident procedure. The law works with a first report within 24 hours and your customers pass that deadline on to you in their contracts. Reporting within 24 hours only works if it is settled in advance who calls, who may decide to shut systems down, and which contacts there are per customer. Print the procedure too: during an incident your own network may be unreachable. See How does the 24-hour report for a cyber incident work?
What else fits in the same week?
Three things that cost little and come back on every list. Clean up the accounts of people who have left, because that is a classic way in and a check you can do today; see access control. Verify that disk encryption is on across all laptops, which on Windows and macOS is a setting rather than a purchase; see encryption. And switch on automatic updates on everything that has them, from laptops to firewalls; see patch policy.
Together these three cost a day, and they cover a good part of four of the ten topics.
What is better left until later?
The paperwork that only gains value once the technology is in place. An extensive information security policy, a risk assessment with likelihoods and impacts, a supplier register: it all belongs, and it is exactly the kind of work that can take months without anything becoming safer in the meantime.
So the order we keep is: first the measures that stop an attack, then recording them. With one exception, the incident procedure, because it is only usable if it exists before you need it. The full picture is in risk analysis and security policy.
What is this going to cost roughly?
For a company of up to fifty people it breaks down into three items. The measures themselves usually cost nothing extra, because MFA, disk encryption and automatic updates are part of what you already buy. Your IT provider needs time to switch it on and resolve the exceptions, and that is typically a few days of work spread over some weeks. And internal hours go into it: the figuring out, the recording and the filling in.
The item you control is the third. Record the answers properly once and you do that work once; start over per customer and you pay for it per customer. That is also the item that rises fastest as soon as you have several customers who fall under the law.
How do I stop every questionnaire being work all over again?
By recording your answers properly once. Virtually every questionnaire is a translation of the same ten duty of care measures; once you have your own situation clear, you fill in every next list in a fraction of the time.