NIS2: practical checklist to achieve compliance in 90 days
Segurança · 1 min
Articles by Fábio Ribeiro
Asset inventory, risk management, incident response, and governance. Understand the main NIS2 requirements and the necessary steps to strengthen your organization's compliance.

TL;DR
- Critical asset and supplier inventory is one of the first steps towards compliance
- Risk management, access control and incident response gain greater relevance
- Notification processes must be aligned with NIS2 requirements
- Top management has increased responsibilities in cybersecurity oversight
What changed compared to NIS1
The NIS2 Directive significantly expanded the number of covered entities and strengthened requirements related to risk management, operational resilience, and incident notification. The legislation also provides for a more stringent sanctioning regime and greater involvement of top management in supervising cybersecurity measures.
The main points of the checklist
Among the most relevant aspects for preparing organizations are asset inventory, [risk management](/en/blog/navegar-na-complexidade-gestao-de-riscos-na-supply-chain-digital), access control, protection of systems and data, [incident response](/en/blog/como-a-observability-e-o-aiops-ajudam-a-acelerar-a-resposta-a-incidentes), [supplier management](/en/blog/gerir-riscos-supply-chain-ai-generativa), employee training, notification processes, and periodic evaluations of implemented measures.
Our implementation roadmap
A phased approach allows accelerating the adoption of NIS2 requirements. The process normally begins with identifying assets and assessing the existing maturity level, followed by the implementation of priority measures and, subsequently, the formalization of procedures, training, and [incident response exercises](/en/solutions/soc-noc-as-a-service).
NIS2 Assessment in 2 Weeks
We map your gap and deliver an executable plan.
Related
- Physical & Logical Security
- SOC/NOC as a Service
- Backup & Disaster Recovery
References
- NIS2 Directive (EU) 2022/2555 — full text (EUR-Lex)
- NIS2 Article 34 — Administrative fines for essential and important entities
- Decreto-Lei n.º 125/2025 — Regime Jurídico da Cibersegurança (transposição NIS2)
- CNCS — Diretiva NIS 2 (página oficial)
- Regulamento n.º 756/2026, de 22 de junho - Regulamento do Regime Jurídico da Cibersegurança