Features

Everything an SME needs for NIS2. Nothing it does not.

Every feature answers a concrete question: what am I missing? How do I implement? How do I demonstrate it? All without unnecessary complexity.

Step zero

Guided diagnosis, in plain language

The starting point is a 10-question questionnaire written for people who run a business, not for auditors. Each question is mapped to one of the most common vulnerabilities in SMEs and, in turn, to one or more QNRCS controls.

  • 10 direct questions, no technical jargon
  • Mapped to the most common vulnerabilities in SMEs
  • Priority action plan generated from your answers
  • Redo the diagnosis whenever your company's reality changes
trial.nis2pme.pt
NIS2PME diagnostic questionnaire

The plan

Security controls tailored to your level

From the Basic level (43 minimum measures) to High (92): based on the level you indicate at registration, the platform measures compliance against what the QNRCS requires of your entity, organised across the 6 objectives (Govern, Identify, Protect, Detect, Respond and Recover). In total, the QNRCS defines 107 controls, with the remaining ones available for those who want to go beyond the minimum. Administrators delegate the measures for your level in one step, and whoever implements them sees only those.

  • Clear statuses: not started, in progress, implemented and approved
  • Priority actions derived from the diagnosis
  • A control that does not apply leaves the scoring, with its justification in plain view
  • Filters by status and level, with controls grouped by objective
trial.nis2pme.pt
Security controls list with statuses and filters

The implementation

Concrete guidance, control by control

Knowing what is missing is half the journey; the platform helps with the how. Each control includes a description of what is expected, why it is required and practical implementation guidance suited to the reality of an SME.

  • Concrete steps, suited to your compliance level
  • Ready-to-use evidence examples and a practical tip
  • Estimated effort: time, people and cost
  • Delegate the control to whoever will implement it
trial.nis2pme.pt
Control detail with implementation guidance

The response

Incidents: deadlines in plain sight when time counts

When an incident happens, it is not the time to read the law. Four simple questions help you assess whether it is significant: the platform suggests a classification and the decision is yours. From there, it tracks the deadlines for notifying the authority and warns you when they are about to expire. Everything is recorded, and the PDF report comes pre-filled.

  • Significance assessment in four plain-language questions
  • Notification deadlines tracked, with warnings before and after they expire
  • Append-only timeline: events cannot be edited or deleted
  • PDF report in Portuguese or English, with everything recorded, as a basis for the notification
trial.nis2pme.pt
Incident record with notification deadlines and timeline

The demonstration

Reports that speak the language of management and of authorities

Compliance you cannot demonstrate does not exist. Maturity dashboards per objective, progress against the required level, and exportable reports to present to management, auditors or the competent authorities.

  • Maturity radar across the 6 QNRCS objectives
  • Compliance percentage against the minimum required level
  • Compliance report in PDF, for management, auditors or authorities
  • Weekly compliance history
trial.nis2pme.pt
Compliance reports and export

And also, in the free core

Reusable evidence

One piece of evidence can support several controls and has versions; whoever views or downloads it is recorded in the audit log. Duplicates are detected, and anything removed stays in the recycle bin for 30 days, where it can be restored.

Recurring tasks

Nine periodic obligations already set up, such as reviewing access, testing backups or running exercises, plus your own. Every completed task can be attached as evidence in one click.

Training records

Record training sessions and participants, including the management-body training the law requires. The record can be attached as evidence in one click.

14 document templates

Policies and plans in Word, in Portuguese and English: cybersecurity, access, backups, incident response, business continuity, supply chain and more.

Roles and approvals

Five roles, from administrator to auditor and top management, with adjustable permissions. Delegate controls, and the auditor approves what has been implemented.

Tamper-evident audit log

Every action goes into a chained log, verified every day, where any change to the history is detected.

Security by default

Mandatory two-factor authentication, encrypted personal data and evidence content, and scheduled encrypted backups.

Email alerts

By email, incident deadlines and a weekly summary of what needs attention. Tasks send their reminders inside the platform.

Global search

Find controls, evidence, incidents, tasks and training records with Ctrl+K, by keyword and in any order.

System health

On an on-premises deployment, one page shows the state of the database, disk, email and backups, designed for non-technical staff.

Portuguese and English

Interface in PT and EN, useful for international teams or groups with a presence in Portugal.

On-premises with Docker

Free deployment on your infrastructure, fully prepared for Docker. Your data, your rules.

Premium

Automate what is manual. Verify what is declared.

The core tells you what to do and keeps the proof. Premium takes on the heaviest work: inventory, risk and suppliers with a ready-made method, import of what you already have in other tools, technical checks and AI analysis.

Asset inventory

Equipment, software, services, data and key people, with the dependencies between them. Criticality is classified through simple questions and explained in plain language.

Risk analysis

Over 30 ready-to-use risk scenarios, each linked to the QNRCS controls that reduce it. Residual risk follows control implementation, and the company sets its own risk appetite.

Suppliers

Due-diligence questionnaire and risk assessment for each supplier, with history. Supply-chain security is also required by the QNRCS.

Import what you already have

Bring in your GLPI inventory, your Monarc risk analysis and your OpenVAS and Wazuh reports. For inventory and risk, you see the result before applying it. All through exported files (CSV or JSON), without handing over credentials or opening ports.

Technical checks

Read-only connection to Microsoft 365 / Entra ID and Active Directory: MFA, administrators and password policies, plus inactive accounts in Active Directory. The platform confirms what is declared and warns you when reality contradicts it.

AI analysis

Reads the documentation and evidence for each control and suggests what is missing and how to strengthen it, before you present them to an auditor.

Everything in one place, and cross-checked. NIS2PME brings together what comes from each tool and shows what none of them sees alone: machines the scanners find that the inventory does not know, assets nobody is analysing, controls declared as implemented that the technical checks contradict, and serious Wazuh alerts gathered in a queue, so you can decide whether to open an incident.

Everything runs on your infrastructure. The only exception is AI analysis: the evidence for the control you send for analysis is sent encrypted to the NIS2PME AI service, hosted in Europe. It is not kept; the result stays encrypted, readable only by your installation, until it is delivered, for 24 hours at most.

Book a demo See pricing

Microsoft 365, Entra ID, Active Directory, GLPI, Monarc, OpenVAS, GVM and Wazuh are trademarks of their respective owners. NIS2PME is not affiliated with any of them.

What the platform does not do

A compliance tool that promises everything is not credible. These limits are stated upfront.

It does not submit notifications to the CNCS

It generates a report with what you recorded and tracks the deadlines; the notification is made on the official platform.

It is not a SIEM or an antivirus

It does not monitor your network in real time. It reads the reports from the tools you already have.

It does not run vulnerability scans

It imports the results from the tools that do.

It does not implement the measures for you

It tells you what to do, how, and what proof to keep; the execution is up to your team or your IT provider.

It does not determine your compliance level

That results from the classification defined by the CNCS.

It does not replace legal advice

Nor an audit. It is a tool that supports compliance.

See it with your own eyes

Try the core and AI analysis in the 14-day trial. To see the Premium modules with sample data, book a demo.