NIS2 is already in force.
The clock is running.
A technical readiness assessment for Portugal’s new Cybersecurity Legal Framework — evidence-based, mapped to QNRCS v2 and Anexo III, ready for the board.
An illustrative extract of the output format. Anything the tooling cannot collect is recorded as “Not assessed” — never passed by omission.
The legal deadline for essential entities’ cybersecurity measures — running from June 2026.
Fines for essential entities — whichever is higher against worldwide turnover.
Management bodies answer for non-compliance — a responsibility that cannot be delegated.
What changed
A new Cybersecurity Legal Framework
In force since April 2026, transposing the EU NIS2 Directive into Portuguese law.
Conformity levels and minimum measures
Defines the Básico, Substancial and Elevado levels and the mandatory minimum measures set out in Anexo III.
A new national reference framework
Govern · Identify · Protect · Detect · Respond · Recover.
Registration and reporting to the authority
Registration, self-identification, incident notification, the Annual Report and the exposed-asset list (art. 32.º).
First things first — where do you sit?
Am I in scope for NIS2?
The applicable conformity level is stated in the competent authority’s qualification notice — the readiness assessment covers all three levels.
Indicative estimate — qualification and conformity level are determined by the competent authority.
How we demonstrate readiness
228 evidence-based checks
Automated, read-only collection across Microsoft 365 and Azure. Nothing is stated without evidence.
Mapped to Anexo III
Every measure at your conformity level with a clear status: Met, Partial, Not met, Not assessable by tooling — never “green” by omission.
Ready for the board and for the authority
Executive summary, gap table with verification criteria, evidence annex and a remediation plan.
Fixed scope. A defensible result.
Anexo III Readiness Assessment
- Anexo III gap table by measure and verification criterion
- Executive summary for the board (EN + PT)
- Full technical report + evidence
- Prioritised remediation plan (Word + Excel)
- Exposed-asset list (art. 32.º) in submission format
Express — €750: essential M365 posture check, HTML dashboard + findings CSV (no board pack, no Anexo III gap table, no remediation runbook).
Technical readiness assessment — not legal advice nor a determination of compliance.
How it runs
Scope
A 30-minute call to fix the perimeter and the level to assess.
Collection (read-only)
Dedicated read-only access; collection runs without changing anything in your environment.
Analysis and mapping
Every finding validated and mapped to Anexo III and QNRCS v2.
Reports
Executive summary, gap table, evidence and remediation plan.
Executive session
Findings and priorities presented to the management body.
See the format before you decide



Get the sample report
We’ll send a full sample report to your inbox — no commitment.
Your email is used only to send the sample. Privacy Policy
What people usually ask
It depends on your sector of activity and the size of the entity. The estimator above gives an indicative reading, but qualification as an essential or important entity is determined by the competent authority and communicated by notice. If in doubt, talk to us before assuming you are out of scope.
Regulamento n.º 756/2026 defines three levels — Básico, Substancial and Elevado — each with different minimum measures in Anexo III. The applicable level is stated in the competent authority’s qualification notice. The readiness assessment covers all three levels, so you do not need to know your level before starting.
Read-only. A dedicated Microsoft Entra app registration is created, authenticating with a certificate and requesting least-privilege scopes module by module. No write permissions are granted and nothing in your environment is changed. Before collection starts, a preflight lists every permission that will be used.
No. They are different things: ISO/IEC 27001 certification can carry a presumption of compliance with part of the obligations, while this assessment measures technical readiness against Anexo III. The results can feed that path, though — the gaps identified are the same ones an ISMS will have to close.
Collection takes hours. Validated reports and the executive session follow in days — not months. The scope is fixed up front, so the schedule does not drift.