EU Compliance
NIS2 Readiness
NIS2 is no longer a big-company matter. With its transposition into Portuguese law and the CNCS regulation, many SMEs now have concrete obligations — and their larger customers will demand evidence. This page explains the essentials, without replacing legal advice.
The calendar driving the pressure
These are the dates your customers and regulators are already working to. Commercial talking points, not legal advice — verify each date against the official source.
- In force22 Jun 2026
NIS2 — implementing regulation
Following DL 125/2025, the CNCS regulation introduces compliance levels, a risk matrix, asset inventory and reporting duties.
Where it fits: NIS2 Readiness
- In force2 Aug 2026
AI Act — transparency
Largely applicable since 2 August. People must be told when they are interacting with an AI system.
Where it fits: AI Assessment · Shadow AI Audit
- Upcoming11 Sep 2026
Cyber Resilience Act — reporting
Reporting obligations begin for manufacturers of products with digital elements, ahead of full application in 2027.
Where it fits: CRA service for software manufacturers
- OngoingSupply chain
Supplier questionnaires
Large companies demand security evidence from their suppliers — and those who cannot answer lose the contract.
Where it fits: ZoomGuard Pro — questionnaire support
The minimum measures, in plain terms
What an SME needs to be able to show. We help you get there with a plan prioritised by effort and impact.
- Risk analysis and an information security policy
- Incident handling and a reporting workflow
- Business continuity and backups
- Supply-chain security
- Access control and use of MFA
- A named person responsible for cybersecurity
Ready for NIS2?
We assess your situation against the minimum measures and deliver a clear action plan.



