Guide

NIS2 compliance: where to start

A first-steps plan for SMEs: confirm your regulatory framing, assess what already exists, follow an order of priority and turn compliance into routine.

The previous guides explain what the law requires and how the compliance levels work. That leaves the question that matters: what do you actually do tomorrow morning?

This guide is a first-steps plan, written for the manager or IT lead of an SME that already knows it is covered and feels the weight of dozens of measures ahead. The central message: this is manageable for a normal company, as long as it is done in the right order.

Step 1: Confirm your regulatory framing

Before investing a single euro, know what the law requires of you specifically. That means answering three questions:

  • Is my company covered by the framework? (sector + size);
  • Is it an essential or important entity?
  • What is my compliance level (Basic, Substantial or High)?

The answers are not the company’s choice: they result from the regulatory framing defined by the CNCS, and are formalised when the entity registers with the CNCS. If you still have doubts about your case, the two previous guides give you the map.

Why this comes first: the compliance level defines the legal minimum required of you, and that minimum is what an inspection will measure you against. Without knowing the minimum, you risk investing in optional areas while leaving mandatory measures unmet. Not because doing more is wrong (it isn’t, and we’ll get there), but because the right order is: first what is required, then what adds on top.

Step 2: Photograph your starting point

The second step is an honest assessment of what already exists and what is missing (the so-called gap analysis). Take the list of minimum measures for your level and, for each one, answer: do we already do this? Partly? Not at all?

Two things tend to be pleasant surprises:

  • You already comply with more than you think. Many SMEs already have backups, antivirus, contracts with their IT provider, some access management. It isn’t formalised, but it exists; formalising what exists is much faster than creating from scratch.
  • What’s missing is often organisation, not technology. At the Basic level, a good share of the measures are policies, inventories, plans and training. They cost time and method, not expensive licences.

The classic mistake at this step is the reverse: buying tools before knowing what is missing. First the diagnosis, then the purchases, if any are needed.

Step 3: Don’t try to do everything at once: follow an order of priority

43 minimum measures (or 75, or 92) are not implemented simultaneously, and it makes no sense to try. What separates a manageable process from chaos is the sequence: tackling first what reduces the most risk.

The good news is that you don’t have to invent that prioritisation yourself. The QNRCS itself is organised for it, and the sensible order is well known: the most exploited vulnerabilities in Portuguese SMEs repeat themselves, and they are almost always the same: poorly managed accounts and access, no multi-factor authentication, backups that were never tested, unpatched systems, employees with no basic training.

Start there. Each of these fronts corresponds to measures at your level, closes real entry points and produces visible progress in the first weeks, which helps keep the company motivated for the rest of the journey.

Step 4: Implement with records

Under NIS2, doing is not enough: you must be able to show that it was done. Every QNRCS measure has a verification criterion stating exactly what evidence is expected: an approved policy, an up-to-date inventory, a training record, a test report.

So get the company used to documenting as it implements, not on the eve of an inspection:

  • Decided on a rule? Write it down and date it.
  • Implemented a measure? Keep the evidence (a screenshot, a record, meeting minutes).
  • Ran training? Record who, when and on what.

Documenting in the moment costs minutes; reconstructing months later costs days and always comes out worse. And this habit feeds directly into the annual report the law requires.

Step 5: Treat compliance as routine, not as a project

Compliance doesn’t “end”: risks change, employees come and go, suppliers change, and the regulatory framework itself evolves. What the law lays out (periodic risk assessments, regular training, an annual report, review of measures) is a cycle, not a finish line.

For an SME, a realistic cadence is enough:

  • Quarterly: a light review: any incidents or near misses? Were leavers’ accesses removed? Backups tested?
  • Yearly: risk assessment, annual report, review of policies and training.

Half a day per quarter, done consistently, is worth more than an intensive three-month project followed by two years of neglect.

The mistakes to avoid

  • Postponing until “there’s news”. The framework is in force and the adaptation deadlines run from qualification. Whoever starts the assessment before being notified gains months of advantage.
  • Delegating everything “to the IT person” without involving management. The law gives management obligations of its own, which cannot be delegated outside it, and provides for personal liability in cases of intent or gross negligence. Management doesn’t need to know how to configure a firewall; it needs to approve, follow up and provide resources.
  • Buying before diagnosing. Tools bought to “become compliant” without a prior assessment tend to cover what was already covered and miss what was missing.
  • Investing in optional measures while minimums go unmet. Going beyond the minimum is commendable and reduces real risk, but the sequence matters: first the minimum for your level, which is what an inspection measures; then, with the minimum secured, climb further as an informed risk management decision.

What support to take on this journey

Everything in this guide can be done with paper, spreadsheets and discipline. It is laborious, but it is possible.

If you prefer structured support, the NIS2PME platform was built precisely for this journey, and its core is free and open-source, deployed on your company’s own infrastructure: you indicate your regulatory framing at registration, answer a short diagnosis focused on the most common vulnerabilities in SMEs, receive a prioritised action plan, and implement each measure with guidance, attaching evidence and generating reports as you go. In other words, steps 2 to 5 of this guide, organised in one place.

And if you’d rather make the journey accompanied, the 30-minute intro call exists precisely to work out where to start in your specific case.

In summary

  • First the framing: know the legal minimum required of you before investing.
  • Then the assessment: formalise what already exists and identify what is missing.
  • Follow an order of priority instead of attacking everything: start with the most common vulnerabilities.
  • Document as you implement: complying also means demonstrating.
  • Turn it into routine: light, regular reviews instead of heroic projects.
  • And with the minimum secured, going beyond it is good risk management, not waste.

This guide is informational and does not constitute legal advice. It reflects Decree-Law 125/2025 and Regulation 756/2026 as of September 2026; NIS2PME tracks regulatory developments and updates this content accordingly.

Frequently asked questions

Where should an SME start with NIS2 compliance?

With scope: knowing whether you are covered, whether you are an essential or important entity, and what your compliance level is. Only then does it make sense to take stock of what exists and plan what is missing. Investing before knowing the legal minimum is the most expensive mistake.

Do I need to buy tools to comply with NIS2?

Not necessarily, especially at the Basic level. Most minimum measures are policies, inventories, plans and training, which cost time and method rather than licences. The diagnosis comes first; purchases, if they are really needed, come after.

How long does compliance take?

It depends on the level and the starting point. The legal adaptation period after qualification is six months, extendable to one year on a reasoned request. An SME that already has backups, antivirus and some access management usually finds it complies with more than it thought.

Who is responsible for compliance inside the company?

Company management has its own obligations that cannot be delegated outside it: approving risk management measures, overseeing their application and ensuring regular training. There is also a designated cybersecurity officer, who must belong to management or report directly to it.

Sources

This guide is based on the legislation published in the Diário da República and on the framework defined by the CNCS.

View as Markdown

From reading to doing?

Try the platform's free diagnosis or book a 30-minute call about your situation.