About
Regulated cybersecurity should not be a privilege of large companies
NIS2PME exists so that any Portuguese SME can understand, plan and demonstrate its NIS2 compliance: with an open-source platform for those who go it alone, and specialised consulting for those who want guidance.
The mission
DL 125/2025 brought cybersecurity obligations to thousands of small and medium-sized companies that had never had to think about this in a structured way. Traditional consulting was designed for large organisations, with budgets and teams an SME does not have. Too many companies end up between ignoring it (risky) and paying what they cannot afford (impossible).
NIS2PME is the third way, in two movements. The platform translates the regulatory framework (the QNRCS 2026) into a guided journey of gap analysis, implementation and compliance demonstration, with a free, open-source core. And the consulting provides specialised remote guidance for those who want it, at prices designed for SMEs, using the platform itself as the work tool.
Who is behind it
NIS2PME was created by Daniel Barreiros, an information security specialist. The credentials, verifiable:
- Master's in Information Security: the platform was born from academic research on applying the QNRCS to Portuguese SMEs, carried out with methodological rigour, control by control;
- Audit experience in a military context: administrative audits of processes and documentation, plus operational readiness audits and training in a naval environment. NIS2 supervision demands exactly that discipline: verifying processes and evidence, and preparing teams for the day they are put to the test;
- Training experience: training teams in a military context, the foundation of the three NIS2 courses NIS2PME delivers;
- Public code: the platform core is on GitHub, under AGPL-3.0. In a field where everyone claims to be an expert, NIS2PME would rather you verified for yourself.
The consulting is delivered directly by the person who built the platform and studied the regulatory framework in detail: no junior teams, no intermediaries, no delegated work.
Why open-source?
Because in a cybersecurity tool, trust is not requested: it is demonstrated. The entire core is published on GitHub under the AGPL-3.0 licence:
- Auditable: anyone can verify what the platform does with the data;
- No vendor lock-in: you can deploy, modify and maintain the core on your own, forever;
- Business model in plain sight: the core is free; those who want more can subscribe to the Premium plan (automation, technical checks and AI analysis) or hire consulting. That is what funds the development, and it is written here, upfront;
- Improvable by everyone: code contributions, translations and feedback are welcome.
Commitments
Regulatory updates. The platform is aligned with Regulation 756/2026 (in force), which establishes the QNRCS and the minimum measures per compliance level, and follows CNCS updates and guidance.
Privacy on principle. This website uses no cookies and no analytics. The on-premises version of the platform keeps your data entirely on your infrastructure.
A genuinely free core. The core is free software and the on-premises deployment will always be free. What is paid (Premium and consulting) is identified as such, with a published price wherever the scope allows it, and fixed in a written proposal before any commitment.
Commercial honesty. The consulting states what it delivers and what it does not, in writing, before any commitment. If your company's problem is not one NIS2PME can solve, you will be told so upfront.
NIS2PME™ is a brand of Daniel Barreiros, with registration in progress.
Be part of this
Use the platform, contribute on GitHub or book a call about your company's compliance.