Most SME managers have heard of NIS2 as “that European cybersecurity law for large companies”. Half of that sentence is wrong. NIS2 is indeed a European directive, but in Portugal it is already national law — Decree-Law no. 125/2025, in force since 4 May 2026 — and covers many medium-sized companies and a significant number of small ones, either directly or through the clients they supply. This article explains, without legal jargon, who is covered, what needs to be done and by when, and where an SME should start. For full and up-to-date details, we have the page NIS2 in Portugal: is your company covered?.
A NIS2 is a European Union directive designed to achieve a high common level of cybersecurity across member states. It modernises existing legislation to address increased digitalisation and an evolving landscape of cyber threats. The directive imposes stricter security requirements, mandatory incident reporting, and harsher penalties for non-compliance on essential and important entities.
It is the European framework that obliges organisations in sectors considered critical to manage cybersecurity risk in a demonstrable way: knowing what they have, protecting it with minimum measures, reporting incidents and being held accountable for compliance. In Portugal, it is called the Legal Regime for Cybersecurity and is overseen by the National Cybersecurity Centre (CNCS). The major difference from the previous version is the scope — covering many more sectors and company sizes — and the direct accountability of management bodies.
Who is covered
Two categories: essential entities (energy, transport, banking, health, water, digital infrastructure, public administration, among others, especially medium and large-sized ones) and important entities (postal services, waste management, chemicals, food, various types of manufacturing, digital services, research, and smaller companies in essential sectors). The general size rule is 50 or more employees or a 10 million euro turnover, but there are exceptions where size does not matter. And there is an indirect effect that catches many SMEs: suppliers to covered entities they are required to demonstrate their own security measures, because supply chain security is one of the customer's obligations.
The most important point: no-one is coming to vet him
The CNCS will not send a letter saying “your company is covered”. The burden of self-assessment lies with the organisation: each entity has to check whether it fits, identify itself and register on the MyCiber platform. Failing to register when one should is, in itself, an offence. This is what makes NIS2 different from almost all the obligations an SME is used to — one does not wait for notification.
The deadlines that are already running
- Mid-September 2026auto-identification and registration on MyCiber, for entities already operating (60 working days from 23 June, the date the platform opened). Those that commenced activity afterwards have 30 working days.
- 20 days after qualificationnotify the cybersecurity lead and the permanent point of contact.
- 31 January 2027 (or six months after final qualification): asset inventory — servers, workstations, network equipment, cloud services and access rights.
- June 2028minimum measures of the assigned level implemented and first annual report submitted.
The minimum measurements, translated
The regime defines levels of measures depending on the classification of the entity, but the core is the same that any well-managed company should have: an inventory of what exists; written security policies; access control and multi-factor authentication; data encryption; network segmentation; backups and a continuity plan; vulnerability management and updates; monitoring and event logging; incident response and notification procedures; supply chain security; and training — including for management bodies. If you read our articles on MFA, Zero Trust for SMEs and is seven internal policies, already knows most of it.
Fines and management liability
Up to 10 million euros or 2% of global turnover for essential organisations, and up to 7 million or 1.4% for important organisations. More relevant to an SME than the maximum amount is the principle: the regime holds management bodies directly accountable for compliance. Cybersecurity is no longer an “IT” issue but has become a management issue — involving the approval of measures, compulsory training and supervision.
Where to start this week
- Check the framingsector, size and clients. If there is any doubt, the doubt is resolved now, not in October.
- Register on MyCiber if covered. It is an act by the entity itself — we do not do it for you, but we help to gather the information.
- Take stock: it is the document required until January 2027 and what almost no SME has. Ours IT hardware audit checklist it is the starting point.
- Close the three measures with the highest returnMFA on all access points, off-site and tested backups, actively managed firewall.
- Appoint the person in charge and involve management — forming management bodies is an obligation, not a suggestion.
What if it is not covered?
Two things. First: confirm it and keep the analysis, because an in-scope customer might ask you for proof. Second: minimum measures are good practice regardless of the law — most attacks on Portuguese SMEs would exploit the exact flaws that NIS2 makes compulsory to fix. Doing the essentials without being forced to costs less than doing them in a rush when a customer demands it.
What DataRoad does — and what it doesn't do
We are not lawyers and we do not carry out the registration for you. What we do is what comes after: the asset inventory, the implementation of minimum measures with documentary evidence (access control, encryption, segmentation, backups, monitoring with stored logs), the incident response plan and annual support, as part of the service of managed cybersecurity. For the entities covered, the first step is a written diagnosis detailing what is in place, what is missing, deadlines and costs — order it on the NIS2 page.
Frequently Asked Questions
Could a company with 30 people be covered?
Directly, only in specific cases where size does not matter. Indirectly, yes: if it provides services to covered entities, they will demand proof of its security measures.
What happens if I don't register by September?
Failure to register is, in itself, an offence. If you are covered and have not registered, the advice is to register immediately and document the reason for the delay.
Does NIS2 replace the GDPR?
No. They are different regimes: the GDPR protects personal data; NIS2 protects the continuity and security of services. Many measures overlap, and complying with one helps comply with the other.
How much does it cost to comply with NIS2 in an SME?
It depends on what is already in place. Businesses with MFA, tested backups and a managed firewall have much of the work done; the cost is concentrated on inventory, documentation and log monitoring. An assessment provides a fixed price.
Not sure if your company is covered?
We carry out the assessment, tell you in writing what you have, what is missing and by when, and implement the measures within the contract. See our page on NIS2 in Portugal or call 211 459 950.






































