FAQ
Frequently asked questions
If your question is not here, talk to NIS2PME: every message gets an answer.
Is my company covered by NIS2?
It depends on your sector and size. NIS2 covers 18 sectors, from energy to digital services and transport to manufacturing of critical products, and applies mostly to medium and large companies, although some small companies are also covered in specific cases. The guide "Decree-Law 125/2025 explained for SMEs", in the Guides section, helps you understand how the law applies to your entity.
How much does NIS2PME cost?
The platform core is open-source under the AGPL-3.0 licence and free forever: you can deploy it on your own infrastructure with no licensing costs. The Premium plan (inventory, risk, suppliers, technical checks and AI analysis), the NIS2 diagnosis and the training courses have published prices on the pricing page. The longer consulting engagements are quoted according to scope, always with a written proposal before any commitment.
How is a free core sustainable? What is the catch?
There is no catch, and the business model is in plain sight: the core is and will always be free; development is funded by the Premium plan and the consulting services. The project was born in an academic context, with the mission of democratising access to NIS2 compliance for Portuguese SMEs. The core's code is public and auditable.
What is the QNRCS 2026 and why is the platform based on it?
The National Cybersecurity Reference Framework is the Portuguese technical reference that translates legal requirements into concrete controls. It defines 107 controls organised into six objectives (Govern, Identify, Protect, Detect, Respond and Recover) and three compliance levels (Basic, Substantial and High). The platform is up to date with Regulation 756/2026, in force, which establishes the QNRCS and the minimum measures per level, and follows CNCS updates and guidance, preserving your work.
How many controls will I have to implement?
It depends on the compliance level required of your entity: Basic (43 minimum measures), Substantial (75) or High (92). The QNRCS defines 107 controls in total; each level requires a minimum subset, and the remaining ones are available to those who want to go beyond the minimum. The platform does not decide your level: it results from the regulatory classification defined by the CNCS. You indicate your level at registration, and the platform measures compliance only against the measures that apply.
What does the diagnostic questionnaire consist of?
It is 10 questions, each mapped to one of the most common vulnerabilities in SMEs and, in turn, to one or more QNRCS controls. Based on your answers, the platform generates a priority action plan: the controls that should be reviewed and implemented first. You can redo the questionnaire whenever your company's reality changes.
Is my company data safe?
With the on-premises deployment, your data stays on your infrastructure, and that is how real compliance work is done. The only exception is Premium's AI analysis: the evidence for the control you send for analysis is sent encrypted to the NIS2PME AI service, hosted in Europe, which does not keep it. The evaluation trial is the only option NIS2PME hosts, on servers in the European Union from a European provider: it is exclusively for evaluating the platform, it is suspended after 14 days and deleted 5 days later, and it should not be used with sensitive or confidential company data.
What does the evaluation trial include?
The full core and AI analysis for 14 days, with no credit card and no commitment. It is there to evaluate the platform, so use demo data rather than real company data: at the end of the period the account is suspended, and 5 days later it is deleted with all its data. The other Premium modules are shown in a live demo. If you like it, deploy the core on your own infrastructure with Docker, for free. That is where the real work happens.
How do I deploy the platform at my company?
The GitHub repository includes everything you need for the on-premises deployment with Docker, including step-by-step documentation. If your company has someone capable of managing a server, you can run NIS2PME.
Does the platform replace a consultancy or legal advice?
The platform structures, guides and documents the compliance process, which for many SMEs is enough to move forward with confidence. It does not provide legal advice: for legal interpretation questions specific to your situation, seek specialised support. And for those who want guidance through implementation, NIS2PME also provides specialised remote consulting, using the platform itself as the work tool.
Does NIS2PME issue any certification?
No. The platform helps you implement and demonstrate compliance (gap analysis, controls, evidence and reports), but it does not replace formal audits or certifications where required. What it does is make preparing for those moments much simpler.
Which languages is it available in?
Both the platform and this website are available in Portuguese and English.
How can I contribute to the project?
The project is open-source and contributions are welcome: code, translations, content review, bug reports or simply usage feedback. Everything happens on GitHub.
Still have a question?
Write to NIS2PME: feedback and questions from real SMEs are what make the platform better.