policy NIS 2 Compliance

NIS 2 is now law. Cybersecurity has become a board responsibility.

The NIS 2 Directive requires companies operating in the European Union to manage risk and report incidents within 24 hours. Portugal's Decree-Law 125/2025 is already in force, supervised by the CNCS.

A specialist replies within 1 business day. No commitment.

NIS2_scope.exe
$ nis2 --scope --country=PT
sectors covered18
size threshold50+ staff or €10M+
fine · essentialup to €10M or 2%
fine · importantup to €7M or 1.4%
managerspersonal liability
> in force in Portugal · April 2026_
Source: Decree-Law 125/2025 · Directive (EU) 2022/2555 · CNCS

Companies that already trust us

Electrolux Hypera Pharma Grupo Soma La Moda Grupo Boticário Metropolitano de Lisboa Grupo Supley L'Oreal MediaProbe Grupo Aço Cearense Grupo DPSP Grupo Tempus Obramax IOTA.HUB Diageo MEDX
How NIS 2 reaches you

Three routes bring NIS 2 to a company outside the EU.

  1. 01

    You operate in Europe

    A branch, subsidiary or office in an EU country. The company answers to that country's law when it works in one of the 18 sectors and is medium-sized or large.

  2. 02

    You supply those who do

    Covered European customers must secure their supply chain, so they ask their suppliers for evidence and contractual guarantees.

  3. 03

    You offer digital services in the EU

    Cloud, data centre, managed service and other digital providers based outside the EU must appoint a representative in the bloc.

What changed with NIS 2

Compliance is no longer just a matter for the technical team.

Europe is already reviewing how well countries cooperate and demanding faster incident detection and reporting. Waiting for the incident to get organised means arriving late.

gavel

The board is personally accountable

Management bodies approve and oversee cybersecurity measures, must receive training and can be held personally liable (Art. 20).

Who NIS 2 covers

Essential and important entities: your sector and size set your category.

Essential entities

€10Mor 2% of worldwide annual turnover, whichever is higher

Large companies in the high-criticality sectors. Supervision is active, with regular audits.

  • Energy
  • Transport
  • Banking
  • Financial markets
  • Healthcare
  • Drinking water
  • Waste water
  • Digital infrastructure
  • ICT service management (B2B)
  • Public administration
  • Space
Important entities

€7Mor 1.4% of worldwide annual turnover, whichever is higher

Medium-sized companies in the high-criticality sectors and companies in the other critical sectors. Supervision follows signs of non-compliance.

  • Postal services
  • Waste management
  • Chemicals
  • Food
  • Manufacturing
  • Digital providers
  • Research

Your category depends on sector and size, and each country may designate additional entities. B10SEC confirms yours.

The clock is ticking

A serious incident has deadlines in hours, not weeks.

Select each deadline to see what the law asks for and how B10SEC prepares your company to meet it.

notifications_active
24 hours
Early warning
fact_check
72 hours
Notification
summarize
1 month
Final report
What the law asks

Early warning to the competent authority.

Within 24 hours of becoming aware of a significant incident, the entity must send an early warning, stating whether it suspects unlawful action or cross-border impact.

T+24h To: CNCS
How we work

Continuous detection, so the clock doesn't start late.

The B10SEC SOC monitors your environment and triggers the response as soon as the incident is confirmed.

checkContinuous monitoring and alert triage
checkCoordinated incident containment
checkEarly warning ready for submission
What the law asks

Notification with an initial assessment.

Within 72 hours, the warning is updated with an initial assessment of the incident's severity and impact and, where available, indicators of compromise.

T+72h Severity and impact
How we work

Technical analysis that backs the notification.

The response team gathers the evidence and turns the technical analysis into the information the authority asks for.

checkSeverity and impact assessment
checkDocumented indicators of compromise
checkCommunication aligned with the board
What the law asks

Final incident report.

Within one month of the notification, the final report describes the incident, its likely root cause, the measures applied and any cross-border impact.

T+1 month Cause and measures
How we work

Lessons learned that lower the next risk.

We close the cycle with the report and with fixes prioritised in your security plan.

checkFinal report with cause and measures
checkRisk-prioritised remediation
checkUpdated incident response plan
Improvising or preparing

Improvise when the incident hits, or arrive prepared?

Unprepared
With B10SEC
Weeks of spreadsheets before every audit
Evidence organised and ready when the authority or auditor asks
Finds out it is in scope only when a European customer asks
Scoping done upfront, by country and category
An incident with no idea who reports it, or by when
A defined reporting flow, with the SOC monitoring
Suppliers with no risk assessment
Third-party risk assessed and monitored continuously

From qualification to evidence,
in a single programme.

hub

Three teams, one defence cycle

Red, Blue and Compliance Teams work on the same requirements: offence validates, defence detects and compliance documents.

fact_check

Audit-ready evidence

Documentation is ready when the CNCS or the auditor asks for it, with no last-minute rush.

shield_person

A named cybersecurity officer

CISO as a Service takes on the role the law requires and reports directly to the board.

autorenew

An ongoing model, not one-off projects

Compliance is reviewed over time, keeping pace with new threats, suppliers and CNCS guidance.

travel_explore
STEP_01 Diagnose context and exposure
priority_high
STEP_02 Prioritise risk into a practical agenda
build_circle
STEP_03 Implement technical and governance measures
trending_up
STEP_04 Evolve through continuous review
Before you decide

What you need to know about NIS 2

01
Scope

Is my company in scope?

NIS 2 covers 18 sectors. As a rule, it applies to entities with 50 or more employees or an annual turnover or balance sheet above €10M, and some entities are covered regardless of size.

check_circleQualification as an essential or important entity
check_circleCNCS registration
02
Penalties

What happens if we don't comply?

Fines reach €10M or 2% of annual turnover for essential entities and €7M or 1.4% for important ones. Managers can be held personally liable.

check_circleNIS 2 / ISO 27001 gap assessment
check_circleBoard training
03
Supply chain

I supply an entity covered by NIS 2. Does this affect me?

Yes, indirectly. Supply chain security is one of the mandatory measures, so covered entities will ask their suppliers for assurances.

check_circleThird-party risk assessment
check_circleEvidence for customer questionnaires
check_circleOngoing support with Cyber & Privacy Supply Chain
NIS 2 READY

Find out where your company stands on NIS 2.

Talk to a B10SEC specialist: we confirm whether your company is in scope, in which category, and what is missing to comply.

  • Scoping by country and category
  • Map of the obligations that apply to your company
  • A prioritised remediation plan, no commitment
NIS 2EU Directive24h72h1 month
Take the first step

Check if your company is in scope.

Fill in the form and a B10SEC specialist will get in touch to assess your company's position and propose a plan, with no commitment.

Your data is processed by B10SEC Proteção de Dados e Cibersegurança Ltda. to respond to your enquiry, on the basis of pre-contractual steps and legitimate interest. We keep the data for 12 months. You can exercise your rights of access, rectification, erasure, objection and portability by contacting our Data Protection Officer at dpo@b10sec.pt. Find out more in our Privacy Policy and exercise your Data Subject Rights.

B10SEC

B10SEC: Security that protects what you cannot see yet.

comercial@b10sec.com
Most visited
Social
© 2026 B10SEC Proteção de Dados e Cibersegurança Ltda. All rights reserved.