NIS2 (EU Directive 2022/2555) is the European directive on the security of network and information systems, which replaces and expands the original NIS. It comes into force in Portugal via national transposition, with reinforced obligations for operators of essential services (energy, transport, health, banking, digital infrastructure) and important ones (food, chemical, component manufacturing).
The NIS2 obligations cover: documented risk analysis, incident management with notification to the national authority within 24h, business continuity, supply-chain security, training and awareness, access policies, encryption, security in acquisition and development. Fines can reach 2% of global annual turnover.
INFOS helps customers align their infrastructure with NIS2 — maturity audit, implementation of missing controls, auditable documentation, team training. Customers in essential sectors (for example, food or component manufacturing) find in NIS2 a regulatory requirement that justifies investment in cybersecurity that would otherwise be deferred.