NIS2: practical checklist to achieve compliance in 90 days

Segurança · 1 min

Articles by Fábio Ribeiro

Asset inventory, risk management, incident response, and governance. Understand the main NIS2 requirements and the necessary steps to strengthen your organization's compliance.

NIS2: practical checklist to achieve compliance in 90 days

TL;DR

What changed compared to NIS1

The NIS2 Directive significantly expanded the number of covered entities and strengthened requirements related to risk management, operational resilience, and incident notification. The legislation also provides for a more stringent sanctioning regime and greater involvement of top management in supervising cybersecurity measures.

The main points of the checklist

Among the most relevant aspects for preparing organizations are asset inventory, [risk management](/en/blog/navegar-na-complexidade-gestao-de-riscos-na-supply-chain-digital), access control, protection of systems and data, [incident response](/en/blog/como-a-observability-e-o-aiops-ajudam-a-acelerar-a-resposta-a-incidentes), [supplier management](/en/blog/gerir-riscos-supply-chain-ai-generativa), employee training, notification processes, and periodic evaluations of implemented measures.

Our implementation roadmap

A phased approach allows accelerating the adoption of NIS2 requirements. The process normally begins with identifying assets and assessing the existing maturity level, followed by the implementation of priority measures and, subsequently, the formalization of procedures, training, and [incident response exercises](/en/solutions/soc-noc-as-a-service).

NIS2 Assessment in 2 Weeks

We map your gap and deliver an executable plan.

Related

References

  1. NIS2 Directive (EU) 2022/2555 — full text (EUR-Lex)
  2. NIS2 Article 34 — Administrative fines for essential and important entities
  3. Decreto-Lei n.º 125/2025 — Regime Jurídico da Cibersegurança (transposição NIS2)
  4. CNCS — Diretiva NIS 2 (página oficial)
  5. Regulamento n.º 756/2026, de 22 de junho - Regulamento do Regime Jurídico da Cibersegurança