Skip to content
ZoomTarget
Contact

EU Compliance

NIS2 Readiness

NIS2 is no longer a big-company matter. With its transposition into Portuguese law and the CNCS regulation, many SMEs now have concrete obligations — and their larger customers will demand evidence. This page explains the essentials, without replacing legal advice.

The calendar driving the pressure

These are the dates your customers and regulators are already working to. Commercial talking points, not legal advice — verify each date against the official source.

  1. In force22 Jun 2026

    NIS2 — implementing regulation

    Following DL 125/2025, the CNCS regulation introduces compliance levels, a risk matrix, asset inventory and reporting duties.

    Where it fits: NIS2 Readiness

  2. In force2 Aug 2026

    AI Act — transparency

    Largely applicable since 2 August. People must be told when they are interacting with an AI system.

    Where it fits: AI Assessment · Shadow AI Audit

  3. Upcoming11 Sep 2026

    Cyber Resilience Act — reporting

    Reporting obligations begin for manufacturers of products with digital elements, ahead of full application in 2027.

    Where it fits: CRA service for software manufacturers

  4. OngoingSupply chain

    Supplier questionnaires

    Large companies demand security evidence from their suppliers — and those who cannot answer lose the contract.

    Where it fits: ZoomGuard Pro — questionnaire support

The minimum measures, in plain terms

What an SME needs to be able to show. We help you get there with a plan prioritised by effort and impact.

  • Risk analysis and an information security policy
  • Incident handling and a reporting workflow
  • Business continuity and backups
  • Supply-chain security
  • Access control and use of MFA
  • A named person responsible for cybersecurity

Ready for NIS2?

We assess your situation against the minimum measures and deliver a clear action plan.

Talk to us