NIS 2 is now law. Cybersecurity has become a board responsibility.
The NIS 2 Directive requires companies operating in the European Union to manage risk and report incidents within 24 hours. Portugal's Decree-Law 125/2025 is already in force, supervised by the CNCS.
A specialist replies within 1 business day. No commitment.
Companies that already trust us
Three routes bring NIS 2 to a company outside the EU.
- 01
You operate in Europe
A branch, subsidiary or office in an EU country. The company answers to that country's law when it works in one of the 18 sectors and is medium-sized or large.
- 02
You supply those who do
Covered European customers must secure their supply chain, so they ask their suppliers for evidence and contractual guarantees.
- 03
You offer digital services in the EU
Cloud, data centre, managed service and other digital providers based outside the EU must appoint a representative in the bloc.
Compliance is no longer just a matter for the technical team.
Europe is already reviewing how well countries cooperate and demanding faster incident detection and reporting. Waiting for the incident to get organised means arriving late.
The board is personally accountable
Management bodies approve and oversee cybersecurity measures, must receive training and can be held personally liable (Art. 20).
Essential and important entities: your sector and size set your category.
€10Mor 2% of worldwide annual turnover, whichever is higher
Large companies in the high-criticality sectors. Supervision is active, with regular audits.
- Energy
- Transport
- Banking
- Financial markets
- Healthcare
- Drinking water
- Waste water
- Digital infrastructure
- ICT service management (B2B)
- Public administration
- Space
€7Mor 1.4% of worldwide annual turnover, whichever is higher
Medium-sized companies in the high-criticality sectors and companies in the other critical sectors. Supervision follows signs of non-compliance.
- Postal services
- Waste management
- Chemicals
- Food
- Manufacturing
- Digital providers
- Research
Your category depends on sector and size, and each country may designate additional entities. B10SEC confirms yours.
NIS 2 requires it. B10SEC delivers compliance.
Every obligation in the new regime has an owner and a matching B10SEC service, with evidence ready for the CNCS and the auditor.
A serious incident has deadlines in hours, not weeks.
Select each deadline to see what the law asks for and how B10SEC prepares your company to meet it.
Early warning to the competent authority.
Within 24 hours of becoming aware of a significant incident, the entity must send an early warning, stating whether it suspects unlawful action or cross-border impact.
Continuous detection, so the clock doesn't start late.
The B10SEC SOC monitors your environment and triggers the response as soon as the incident is confirmed.
Notification with an initial assessment.
Within 72 hours, the warning is updated with an initial assessment of the incident's severity and impact and, where available, indicators of compromise.
Technical analysis that backs the notification.
The response team gathers the evidence and turns the technical analysis into the information the authority asks for.
Final incident report.
Within one month of the notification, the final report describes the incident, its likely root cause, the measures applied and any cross-border impact.
Lessons learned that lower the next risk.
We close the cycle with the report and with fixes prioritised in your security plan.
Improvise when the incident hits, or arrive prepared?
From qualification to evidence,
in a single programme.
Three teams, one defence cycle
Red, Blue and Compliance Teams work on the same requirements: offence validates, defence detects and compliance documents.
Audit-ready evidence
Documentation is ready when the CNCS or the auditor asks for it, with no last-minute rush.
A named cybersecurity officer
CISO as a Service takes on the role the law requires and reports directly to the board.
An ongoing model, not one-off projects
Compliance is reviewed over time, keeping pace with new threats, suppliers and CNCS guidance.
What you need to know about NIS 2
Is my company in scope?
NIS 2 covers 18 sectors. As a rule, it applies to entities with 50 or more employees or an annual turnover or balance sheet above €10M, and some entities are covered regardless of size.
What happens if we don't comply?
Fines reach €10M or 2% of annual turnover for essential entities and €7M or 1.4% for important ones. Managers can be held personally liable.
I supply an entity covered by NIS 2. Does this affect me?
Yes, indirectly. Supply chain security is one of the mandatory measures, so covered entities will ask their suppliers for assurances.
Find out where your company stands on NIS 2.
Talk to a B10SEC specialist: we confirm whether your company is in scope, in which category, and what is missing to comply.
- Scoping by country and category
- Map of the obligations that apply to your company
- A prioritised remediation plan, no commitment
Check if your company is in scope.
Fill in the form and a B10SEC specialist will get in touch to assess your company's position and propose a plan, with no commitment.