Friday, 5:30 p.m., knitwear factory in the Vale do Ave. The industrial director takes a call from the German customer: "your technical data sheet server hasn't responded for two hours". It's not a network fault. It's ransomware. The following week's production orders are encrypted, the ERP won't start, and the last backup is from Wednesday because the NAS filled up on Thursday and no one saw the alert on the console screen. On Monday morning, the CEO discovers that the company is, under NIS2 as transposed by DL 65/2025, classified as an important entity — and that it will have to notify the CNCS within 24 hours.
What follows is the operational manual that should have been in the drawer before that call. No theory. Just what really must be done, in what order, and what it costs not to do it.
1. Why NIS2 is not "another GDPR"
When the GDPR came into force in 2018, most Portuguese industrial SMEs treated it as a paper exercise: processing contract signed, privacy policy on the website, cookie banner copied from the neighbour. It worked — for a few years — because the CNPD has limited resources and focuses on cases of public exposure.
NIS2 won't play out like that. And there are three operational reasons.
1.1 The regulator has technical teeth
The National Cybersecurity Centre is not the CNPD. It has a technical team, exchanges indicators of compromise with ENISA and CERT-EU, and DL 65/2025 confers inspection powers. Fines go up to 10 million euros or 2% of worldwide turnover for essential entities, and up to 7 million or 1.4% for important entities. For a Famalicão garment maker with 18 million in turnover, we're talking about figures that wipe out two years of EBITDA.
1.2 Liability falls personally on the management body
This is the part no one read carefully. Article 20 of Directive (EU) 2022/2555 requires members of the management body to approve the measures, oversee their implementation, and establishes that they may be held personally liable for non-compliance. Mandatory training. Attendance record. In practice: the CEO and CFO sign off the programme, undertake documented training, and answer personally if there is a breach through gross negligence.
1.3 The subcontracting chain is in the crosshairs
A garment maker producing for Inditex, Decathlon or Tom Tailor is, in practice, a critical supplier of an essential entity. NIS2 requires the entities covered to assess and control supply chain risk — subcontractors included. The result: technical questionnaires sent by parent companies to Portuguese garment makers are already circulating throughout the North. Whoever fails to respond, or responds poorly, loses the following season's order.
NIS2 is not an IT project. It's a market condition. Whoever is not compliant in 2026 loses customers before losing fines.
1.4 Concrete sector scenarios
- Textiles/clothing (Vale do Ave): compromised technical data sheet server. The SS26 collections that the German brand sent via PLM are exposed. The confidentiality clause triggers penalties.
- Footwear (Felgueiras): attack in the week before Micam. Digital samples and 3D moulds inaccessible. Months of design office work at risk, and buyers scheduled.
- Distribution (Lousada/Paços corridor): WMS down for 48 hours. Cross-docking halted. Vehicles idle in the yard. Cold chain break in fresh produce with contractual penalties.
- Regional food retail: POS synchronised over a single VPN. Compromise one, compromise all fourteen. The AT requires justification for inconsistencies in the SAF-T.
- Moulds (Marinha Grande): exfiltrated CAD/CAM files. The German automotive customer demands an independent forensic audit paid for by the supplier.
2. What NIS2 is and who is covered
2.1 Definition
Directive (EU) 2022/2555, known as NIS2, replaces the NIS of 2016 and was transposed into Portuguese law by Decree-Law No. 65/2025, of 2 June. It establishes harmonised obligations for cybersecurity risk management, incident notification and supervision for entities in 18 critical and important sectors.
Two categories:
- Essential entities (Annex I): energy, transport, banking, health, water, digital infrastructure, public administration. Proactive supervision, fines up to €10M or 2% of turnover.
- Important entities (Annex II): production and manufacturing (chemicals, food, electrical equipment, machinery), postal services, waste management, digital providers, research. Reactive supervision, fines up to €7M or 1.4%.
2.2 Who is covered in Portugal
The size cap rule covers, by default, medium and large companies — ≥50 employees OR ≥€10M turnover. But there are traps:
- Even below the threshold, it is covered if it is a sole or critical supplier of an essential entity.
- Even below, if it provides a service to a public administration entity.
- Even below, if an incident could have a significant cross-border impact.
Translation: a 45-employee garment maker in Barcelos that produces for Inditex may be covered by the criticality of the chain, even without reaching the size threshold.
2.3 Terms you will hear
- CNCS: National Cybersecurity Centre, the competent authority in Portugal.
- National CSIRT: incident response team, within the CNCS.
- Significant incident: one that causes, or is liable to cause, severe operational disruption or financial loss to the entity, or that affects third parties causing considerable damage.
- 24/72/30 notification: initial alert within 24 hours, detailed notification within 72 hours, final report within 1 month.
- SBOM: Software Bill of Materials, a list of software components, required in public procurement and critical chains.
- MFA: multi-factor authentication, mandatory for privileged access.
3. The landscape in Portugal: what is known and what is not
3.1 The real maturity of the industrial fabric
European reports on the Digital Decade place Portugal below the EU average in the adoption of cybersecurity measures by SMEs — particularly in the dimensions of training, formal policy and continuity testing. The CNCS publishes the Cybersecurity in Portugal Report, which documents the sustained increase in incidents reported in industrial environments. Without specific figures I cannot verify as at the date of this article, the trend is unequivocal: ransomware against industrial SMEs is today the most active vector, and manufacturing consistently appears among the most targeted sectors in Portugal.
3.2 What is missing from the data
There is no granular public sector data on NIS2 maturity in Portuguese textiles, footwear or distribution. The best proxies are the ENISA Threat Landscape, at European level, and the annual CNCS report, at national level.
3.3 The three myths circulating in factories
- "We're too small to be a target." Wrong. Ransomware-as-a-service sells kits that sweep entire IP ranges at random. There is no "selected target" — there is an open door found.
- "We have antivirus and a firewall, we're covered." Wrong. Most successful attacks on SMEs come in through phishing and abuse of legitimate credentials. The traditional perimeter no longer exists.
- "Our ERP is in a datacentre, it's not our problem." Partly wrong. NIS2 liability does not transfer to the hosting provider — it is shared. The contract has to reflect that.
The attack doesn't arrive through the firewall's front door. It arrives via an email opened at 2:45 p.m. by someone who's hungry and eating lunch at their desk.
4. Implementation models for industrial SMEs
There are five recurring approaches in the Portuguese market. Not all are valid. Some are counterproductive.
4.1 Comparison of the five models
| Model | Typical duration | Relative cost | Residual risk | Suitability |
|---|---|---|---|---|
| 1. DIY with in-house IT | 12-18 months | Low (CAPEX) | High | IT ≥3 people and maturity |
| 2. Generalist consultancy | 6-9 months | Medium-high | Medium (paper compliance) | Those who need a stamp |
| 3. Managed MSSP | 3-6 months to start | Medium OPEX | Low | SME 50-250 employees without a CISO |
| 4. Vertical integrator | 4-8 months | Medium | Low | Industry with ERP/MES already in operation |
| 5. Hybrid | 6-12 months | Medium-high | Very low | >250 employees or critical chain |
4.2 Model 1: DIY with in-house IT
It works when there is an IT manager with at least 5 years of operational practice, plus a junior technician, and management frees up 30% of the senior's time for a year. It fails when the "IT manager" is the CEO's son who studied computing and keeps the server running on heroics. Characteristic symptom: the backup has never been tested in a real restore.
4.3 Model 2: generalist consultancy
It produces a 180-page report, an information security policy that no one will read, and an action plan that ends up on a shared drive. The stamp exists on paper. Real maturity doesn't change. For quick pre-contractual audits with a demanding customer, it serves. For reducing operational risk, it doesn't.
4.4 Model 3: managed MSSP
The Managed Security Service Provider operates SIEM, EDR and incident management 24×7. It's the most technically defensible model for SMEs of 50-250 employees without their own CISO. The risk is in the contract: confirm the incident response SLA (≤4h for sev1), an explicit RACI matrix, and an exit clause with the transfer of logs and configurations.
4.5 Model 4: vertical integrator with embedded cybersecurity
Whoever supplies the MULTI ERP, KORA Productivity or MAXIRETAIL knows the business's critical flows. Network segmentation, hardening of the ERP servers, access control to the shop-floor terminals and immutable backup of the master production file are done with operational knowledge. It fails when the integrator is merely a licence reseller with no security practice.
4.6 Model 5: hybrid
This is what we recommend for companies with more than 250 employees or in the automotive/aeronautics chain. In-house IT maintains the operation. The MSSP provides the SOC and incident response. The vertical integrator handles application hardening. An external auditor performs an annual review. It costs more. It's worth more.
Beware of anyone who sells NIS2 in a checklist sheet and three workshops. Compliance that fits into a PowerPoint does not survive a penetration test.
5. How to assess whether your company needs it: step-by-step diagnosis
5.1 Prerequisites
Before starting, gather: the current organisation chart, list of critical applications (ERP, MES, WMS, POS, CRM, HR), inventory of servers and endpoints, contracts with cloud and hosting providers, a copy of the latest information security policy (if one exists) and incident reports from the last 24 months.
5.2 Step by step
- Determine coverage: check sector (Annexes I and II), size and critical dependencies. If you are a supplier to an essential entity, even below 50 employees, you are probably covered. Document the conclusion in a memorandum signed by management.
- Map critical assets: inventory systems by criticality (RTO/RPO defined), identify personal data and trade secrets, map flows with third parties. This stage takes 2-4 weeks if done properly.
- Assess technical gaps: review 10 key controls — MFA on privileged access, OT/IT segmentation, EDR on endpoints, patch management with SLA, tested immutable backup, centralised logging, privileged access management, annual training, tested continuity plan, supplier management. Score from 0 to 5.
- Assess governance gaps: is there a policy approved by management? Who is the formal owner? Is there a change approval process? Is there a training record? Are there NIS2 clauses in the contracts with IT subcontractors?
- Estimate effort and cost: translate each gap into a project, with hours and CAPEX/OPEX. Group them into waves (quick wins 0-3 months, structural 3-12, evolutionary 12-24).
- Validate with management: present a risk vs. effort matrix. Obtain formal approval of the programme, the budget and the owner. Without the CEO's signature, the programme dies on a shared drive.
5.3 Red flags that speed up the diagnosis
- The backup has never been tested in a full restore in the last 12 months.
- There is a single domain administrator with a password "that everyone knows".
- The ERP server runs on an out-of-support operating system (Windows Server 2012, for example).
- Remote access is done via VPN without MFA — or, worse, via RDP exposed to the internet.
- There is no separation between the management network and the shop-floor network (PLCs and CNC machines in the same broadcast domain as the administrative PCs).
- Remote maintenance providers access with shared credentials.
- There is a single Wi-Fi network for employees, visitors and industrial equipment.
If you identify three or more of these signs, the company is at high risk regardless of NIS2 — and the programme should start with the technical controls before the documentary governance.
6. What to choose and why: decision by size
6.1 Decision matrix
| Profile | Size | In-house IT | Recommended model | Priority focus |
|---|---|---|---|---|
| Small garment/footwear maker in the chain | 30-80 employees | 0-1 person | Vertical integrator + basic MSSP | MFA, immutable backup, segmentation |
| Medium textile finishing | 80-200 employees | 1-2 people | MSSP + vertical integrator | SOC, EDR, supplier management |
| Metal/plastics industry | 100-300 employees | 2-3 people | Hybrid with OT/IT segmentation | OT security, SBOM, continuity |
| Regional distribution | 150-400 employees | 2-4 people | Hybrid with logistics focus | WMS hardening, MFA, 24×7 monitoring |
| Multi-store retail | 200-600 employees | 3-5 people | Hybrid with POS/PCI focus | Segregated POS, e-Invoice, secure omnichannel |
| Multi-site industrial group | >500 employees | ≥5 people + CISO | Full hybrid + external auditor | ISO 27001, in-house SOC, supply chain |
6.2 How much to invest, in orders of magnitude
In industrial SMEs with 50-250 employees, the typical investment is distributed across three blocks: tools and licences (EDR, MFA, immutable backup, SIEM/centralised logging), services (start-up consultancy, hardening, training, audit) and recurring operation (MSSP, monitoring). The absolute values vary greatly according to size and prior maturity, but year 1 concentrates most of the financial effort, stabilising into recurring OPEX from year 2.
There are PRR and PT2030 funds that cover part of the investment — in particular COMPETE 2030 calls for the digital transition and cybersecurity calls from Norte 2030 and Centro 2030. Don't count on 80% co-financing. Count on something between 30% and 50%, well documented.
6.3 What NOT to buy
- A "next-gen" firewall appliance without someone who knows how to configure it: an expensive box, default rules, a false sense of security.
- A 30-minute online training package: it doesn't count as NIS2 training. There has to be documented attendance, assessment and periodicity.
- A backup solution that snapshots on the same storage: modern ransomware deletes snapshots. The backup has to be immutable and off-site. See our guide on cybersecurity, NIS2 and immutable backup.
- A security policy copied from the internet: the auditor spots it in 15 minutes. Worse than not having one.
Investment in cybersecurity is not measured in equipment bought. It's measured in the hours the factory stays idle when the incident comes — and it will come.
7. Applicable regulatory framework
7.1 NIS2 and Portuguese transposition
Directive (EU) 2022/2555 was adopted on 14 December 2022 with a transposition deadline of 17 October 2024. Portugal transposed it through Decree-Law No. 65/2025. The critical operational points:
- Registration: the entities covered must register with the CNCS.
- Minimum measures (Art. 21 of the Directive): risk analysis and systems security policies, incident management, continuity and backups, supply chain security, secure acquisition and development, effectiveness of the measures, cyber hygiene and training, cryptography, HR security and access control, MFA and secure communications.
- Notification (Art. 23): early alert within 24h, notification within 72h, final report within 1 month.
- Sanctions: essential entities up to €10M or 2% of annual worldwide turnover; important entities up to €7M or 1.4%.
7.2 GDPR and Law 58/2019 — the intersection
NIS2 does not replace the GDPR. If an incident involves personal data (and it almost always does), there is a dual notification: the CNCS under NIS2, the CNPD under the GDPR. The timings are similar but not identical. The internal process has to provide for both channels.
7.3 ISO 27001 — is it worth it?
It's worth it when the customer requires it. DL 65/2025 does not require ISO 27001 certification, but the NIS2 minimum measures annex has strong overlap with the standard. For suppliers in the automotive, aeronautics or pharmaceutical chain, ISO 27001 is increasingly a condition for listing. For a medium fashion garment maker, it is over-engineering — the NIS2 management system is enough.
7.4 DL 28/2019, SAF-T and the tax frontier
Electronic invoicing, the ATCUD and SAF-T reporting to the AT require certified software and periodic reporting. This creates two critical assets from the NIS2 point of view: the invoicing server (which holds the private signing key) and the reporting channel to the AT. Both have to be within the reinforced perimeter — not on "the accountant's PC".
7.5 eIDAS 2, Law 93/2021 and the AI Act
- eIDAS 2 (Regulation EU 910/2014 as revised): qualified signature for digital contracts and communications with the administration. It implies the management of qualified certificates and compliant document management.
- Law 93/2021: mandatory whistleblowing channel for entities with ≥50 employees. A guarantee of confidentiality, which intersects with NIS2 access control.
- AI Act (Regulation EU 2024/1689): if you use AI in production planning, quality control or predictive absenteeism modules, there are additional governance and technical documentation obligations.
7.6 Map of cross-cutting obligations
| Obligation | NIS2 | GDPR | DL 28/2019 | ISO 27001 |
|---|---|---|---|---|
| Documented risk analysis | Yes | Yes (DPIA) | No | Yes |
| 72h incident notification | Yes | Yes | No | Recommended |
| Annual training | Yes (management) | Yes | No | Yes |
| Supplier management | Yes | Yes (processors) | No | Yes (A.5.19-A.5.23) |
| MFA on critical access | Yes | Recommended | No | Yes (A.5.17) |
| Tested backup | Yes | Indirect | No | Yes (A.8.13) |
8. How INFOS approaches this
INFOS is not a pure cybersecurity consultancy. It's a vertical integrator of industrial software with 35 years of hands-on practice on the Portuguese shop floor — and that changes the way we look at NIS2. When we segment the network in a footwear factory in Felgueiras, we know that the injection KORA Productivity terminals cannot lose their connection to the MES for more than 90 seconds without stopping the cell. When we harden the MULTI ERP server, we know that the nightly production close jobs start at 11:15 p.m. and that the backup has to finish before then — not in the middle of the snapshot.
What we offer under cybersecurity services and datacentre is the integration between the NIS2 controls and the real operation of the ERP, MES, WMS and POS. Immutable ERP backup in our own datacentre. Hardening of the application servers. OT/IT segmentation designed not to halt production. Log monitoring of MULTI Connect and of the shop-floor terminals. Training of key users — warehouse supervisors, shift leaders, invoicing clerks — in the context of the systems they use every day.
We do not replace an MSSP specialised in companies with a 24×7 SOC. We complement it, ensuring that the industrial application layer — where the value lies — remains defensible. For multi-site scenarios in a regulated chain (automotive, aeronautics, pharmaceutical), we work in a hybrid model with the customer.
9. 30/60/90-day roadmap
A complete NIS2 programme takes between 6 and 18 months, depending on the initial maturity. But there are 90 decisive days at the start — where you demonstrate to management that the programme is advancing and where you close the gaps that are low-hanging fruit and high residual risk.
9.1 Days 1-30: governance and visibility
- Executive sponsor appointed by a formal act of management. Without this, nothing advances.
- Determination of NIS2 coverage with a signed legal memorandum.
- Inventory of critical assets (systems, data, flows) with RTO/RPO defined per system.
- Inventory of critical IT suppliers with revised contractual clauses.
- Initial assessment of the 10 key controls (section 5.2).
- Registration of the entity with the CNCS where applicable.
- Internal communication of the programme to the entire company.
9.2 Days 31-60: technical quick wins
- MFA enabled on 100% of privileged access (administrators, ERP, VPN, email).
- Inventory of accounts with elevated privileges; elimination of orphan and shared accounts.
- Emergency patching of critical systems with known vulnerabilities (CVE ≥7.0).
- Real restore test of the most recent ERP backup in an isolated environment.
- Blocking of internet-exposed RDP; replacement with VPN with MFA or ZTNA.
- Initial segmentation: separate the shop-floor network from the administrative network by VLAN and firewall.
- Basic incident management policy approved and disseminated — who reports to whom, in what timeframe.
9.3 Days 61-90: structuring and training
- EDR (Endpoint Detection and Response) deployed on critical servers and endpoints.
- Immutable backup configured for ERP, WMS, POS and critical operational files, with a minimum 30-day retention and an off-site copy.
- Mandatory initial training of management and department heads (≥4h documented with assessment).
- Phishing simulation campaign across the whole company; analysis of results; remediation plan.
- Documented incident notification procedure: CNCS contacts, 24h/72h/1-month notification templates, internal escalation flow.
- Review of the contracts with the three most critical IT suppliers to include NIS2 clauses (notification, audit, subcontracting).
- Draft business continuity plan, with test scenarios scheduled for the following 6 months.
At the end of the 90 days you should have a NIS2 programme dossier with: minutes of executive approval, coverage memorandum, asset inventory, risk matrix, action plan with owners and deadlines, training record, evidence of the controls implemented, and a quarterly review schedule. That dossier is what you will present when the German customer sends the 120-question questionnaire — or when the CNCS gets in touch.
To go deeper into the technical control layer in a factory environment, read our guide to NIS2 technical controls for Portuguese factories. If you are in textiles or clothing and your chain includes customers already sending technical questionnaires, complement it with Connect@Fashion: digitalising collections and textile collaboration, which addresses the sensitive data flows between garment maker and brand. For the operational visibility that underpins audits, it is worth reviewing how Qlik Sense consolidates IT, production and HR indicators on the same screen — and the cross-reading with Business Intelligence in the textile industry.
NIS2 is not achieved in 90 days. But in 90 days it is decided whether the programme will exist or whether it will die on a shared drive.
Sources
- Directive (EU) 2022/2555 of the European Parliament and of the Council, of 14 December 2022, on measures for a high common level of cybersecurity across the Union (NIS2). EUR-Lex.
- Decree-Law No. 65/2025, of 2 June — transposition of the NIS2 Directive into Portuguese law. Diário da República.
- Regulation (EU) 2016/679 (GDPR) and Law No. 58/2019, of 8 August — national implementation of the GDPR. Diário da República.
- Decree-Law No. 28/2019, of 15 February — obligations regarding the processing of invoices and other tax-relevant documents (ATCUD, SAF-T). Diário da República.
- Law No. 93/2021, of 20 December — general regime for the protection of whistleblowers. Diário da República.
- Regulation (EU) 2024/1689 — Artificial Intelligence Regulation (AI Act). EUR-Lex.
- ENISA — Threat Landscape Report (annual publication). European Union Agency for Cybersecurity.
- CNCS — Cybersecurity in Portugal Report: Risks and Conflicts (annual publication). National Cybersecurity Centre.
- European Commission — Report on the state of the Digital Decade (annual publication), DESI indicators.
- Standard ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements. International Organization for Standardization.
