NIS2 · DECRETO-LEI N.º 125/2025 · REGULAMENTO N.º 756/2026

NIS2 is already in force.
The clock is running.

A technical readiness assessment for Portugal’s new Cybersecurity Legal Framework — evidence-based, mapped to QNRCS v2 and Anexo III, ready for the board.

Check whether I’m in scope
Illustrative extract — gap table
01Multi-factor authentication for privileged accessMet
02Privileged access management with just-in-time elevationPartial
03Legacy authentication protocols eliminatedMet
04Audit log retention and centralisationPartial
05Backup segregation and restore testingNot assessed

An illustrative extract of the output format. Anything the tooling cannot collect is recorded as “Not assessed” — never passed by omission.

24 months

The legal deadline for essential entities’ cybersecurity measures — running from June 2026.

up to €10M or 2%

Fines for essential entities — whichever is higher against worldwide turnover.

Personal accountability

Management bodies answer for non-compliance — a responsibility that cannot be delegated.

The framework

What changed

DL 125/2025

A new Cybersecurity Legal Framework

In force since April 2026, transposing the EU NIS2 Directive into Portuguese law.

Regulamento 756/2026

Conformity levels and minimum measures

Defines the Básico, Substancial and Elevado levels and the mandatory minimum measures set out in Anexo III.

QNRCS v2

A new national reference framework

Govern · Identify · Protect · Detect · Respond · Recover.

MyCiber platform

Registration and reporting to the authority

Registration, self-identification, incident notification, the Annual Report and the exposed-asset list (art. 32.º).

Indicative estimate

First things first — where do you sit?

Am I in scope for NIS2?

Entity size

The applicable conformity level is stated in the competent authority’s qualification notice — the readiness assessment covers all three levels.

Indicative estimate — qualification and conformity level are determined by the competent authority.

The method

How we demonstrate readiness

228

228 evidence-based checks

Automated, read-only collection across Microsoft 365 and Azure. Nothing is stated without evidence.

Anexo III

Mapped to Anexo III

Every measure at your conformity level with a clear status: Met, Partial, Not met, Not assessable by tooling — never “green” by omission.

Deliverables

Ready for the board and for the authority

Executive summary, gap table with verification criteria, evidence annex and a remediation plan.

The engagement

Fixed scope. A defensible result.

Anexo III Readiness Assessment

  • Anexo III gap table by measure and verification criterion
  • Executive summary for the board (EN + PT)
  • Full technical report + evidence
  • Prioritised remediation plan (Word + Excel)
  • Exposed-asset list (art. 32.º) in submission format
From €1,950

Express — €750: essential M365 posture check, HTML dashboard + findings CSV (no board pack, no Anexo III gap table, no remediation runbook).

Technical readiness assessment — not legal advice nor a determination of compliance.

The process

How it runs

01

Scope

A 30-minute call to fix the perimeter and the level to assess.

02

Collection (read-only)

Dedicated read-only access; collection runs without changing anything in your environment.

03

Analysis and mapping

Every finding validated and mapped to Anexo III and QNRCS v2.

04

Reports

Executive summary, gap table, evidence and remediation plan.

05

Executive session

Findings and priorities presented to the management body.

The sample

See the format before you decide

Sample — dashboard
Sample of the assessment HTML dashboard
Sample — executive summary
Sample of the executive summary for the board
Sample — Zero Trust maturity
Sample of the Zero Trust maturity report

Get the sample report

We’ll send a full sample report to your inbox — no commitment.

Your email is used only to send the sample. Privacy Policy

Solutions Architect Specialising In
Microsoft 365
·
Azure
·
Exchange Online
·
Defender XDR
·
Entra ID
·
Microsoft Sentinel
·
Intune / MEM
·
PowerShell
·
Microsoft 365
·
Azure
·
Exchange Online
·
Defender XDR
·
Entra ID
·
Microsoft Sentinel
·
Intune / MEM
·
PowerShell
·
Frequently asked

What people usually ask

It depends on your sector of activity and the size of the entity. The estimator above gives an indicative reading, but qualification as an essential or important entity is determined by the competent authority and communicated by notice. If in doubt, talk to us before assuming you are out of scope.

Regulamento n.º 756/2026 defines three levels — Básico, Substancial and Elevado — each with different minimum measures in Anexo III. The applicable level is stated in the competent authority’s qualification notice. The readiness assessment covers all three levels, so you do not need to know your level before starting.

Read-only. A dedicated Microsoft Entra app registration is created, authenticating with a certificate and requesting least-privilege scopes module by module. No write permissions are granted and nothing in your environment is changed. Before collection starts, a preflight lists every permission that will be used.

No. They are different things: ISO/IEC 27001 certification can carry a presumption of compliance with part of the obligations, while this assessment measures technical readiness against Anexo III. The results can feed that path, though — the gaps identified are the same ones an ISMS will have to close.

Collection takes hours. Validated reports and the executive session follow in days — not months. The scope is fixed up front, so the schedule does not drift.

When you’re ready

Know exactly where you stand —
before the authority asks.