Open-source · AGPL-3.0 100% free QNRCS 2026 · DL 125/2025

NIS2 compliance within your SME's reach

The first gap-analysis platform designed for Portuguese SMEs, aligned with the new National Cybersecurity Reference Framework. Guided assessment, controls tailored to your organisation and reports ready to present. No consultants, no costs.

Free 14-day demo · No credit card · On-premises deployment is free forever

app.nis2pme.pt
NIS2PME platform dashboard: compliance overview, maturity per domain and priority actions
107
QNRCS controls
3
compliance levels
6
QNRCS domains
€0
cost, forever

The challenge

NIS2 has reached SMEs. Consultancies haven't.

Decree-Law 125/2025 extends cybersecurity obligations to thousands of Portuguese small and medium-sized enterprises, companies without the budget for specialised consulting or dedicated security teams.

Complex regulation

A European directive, a decree-law, a national reference framework: just understanding what applies to your company is a project in itself.

Real fines

Non-compliance can cost up to millions of euros and make management bodies directly accountable. Ignoring it is no longer an option.

Limited resources

No CISO, no security team, no consulting budget. SMEs need a clear, affordable path, not another 200-page report.

The solution

From uncertainty to an action plan, in one place

NIS2PME turns the regulatory framework into a concrete journey: assessment, controls, evidence and reports, all in language management understands.

Guided self-assessment

A 10-question, plain-language questionnaire mapped to the most common vulnerabilities in SMEs. At the end, you receive a priority action plan: the controls to address first.

Controls tailored to your level

You only see the controls the regulatory framework requires of your organisation, from the Basic to the High level, with statuses, priorities and progress per domain.

Evidence management

Attach documents and proof to each implemented control. When supervision comes knocking, everything is organised and ready to present.

Compliance reports

Track maturity per domain, identify priority actions and export reports for management, auditors or the competent authorities.

Document templates

Pre-filled policies, plans and procedures: your incident response plan no longer starts from a blank page.

Multi-user and audit trail

Multiple users with distinct roles and a complete audit log of every action on the platform.

See all features

Proportional by law

The right level for your organisation, no more and no less

The compliance level (Basic, Substantial or High) results from the regulatory classification defined by the CNCS, not from the platform. The entity indicates its level and NIS2PME presents only the applicable minimum measures.

43 minimum measures

Basic

The QNRCS entry level: the fundamental cybersecurity hygiene practices.

75 minimum measures

Substantial

Reinforced requirements for entities with greater risk exposure and impact.

92 minimum measures

High

The most demanding level, for the largest and most critical entities.

The QNRCS defines 107 controls in total. Each compliance level requires a minimum subset (43, 75 or 92 measures); the remaining ones are available to those who want to go beyond the required minimum. The platform covers all 107.

The 6 QNRCS domains

Govern Identify Protect Detect Respond Recover

Transparency note: NIS2PME is aligned with Regulation no. 756/2026 (in force), which establishes the QNRCS and the minimum cybersecurity measures per compliance level. The detailed technical document of the QNRCS 2026 has yet to be published — we track its evolution and reflect it in the platform, instead of pretending the regulation is already settled.

How it works

Four steps to demonstrable compliance

Answer the assessment questionnaire

10 simple questions, mapped to the most common vulnerabilities in SMEs. No technical knowledge required.

Receive your priority action plan

Each answer is linked to QNRCS controls. At the end, you know exactly which ones to review and implement first.

Implement the controls with guidance

Each control explains the what, the why and the how, with document templates and built-in evidence management.

Track, demonstrate and improve

Progress dashboards and exportable reports that demonstrate your compliance to management and authorities.

Explore the process in detail

Verifiable trust

In a cybersecurity platform, seeing the code is the argument

NIS2PME is open-source under the AGPL-3.0 licence. No black boxes, no vendor lock-in, no pricing surprises, because there is no pricing.

Auditable code

All the code is published on GitHub. Anyone, including your IT staff, can verify exactly what the platform does with your data.

On-premises with Docker

Deploy on your own infrastructure with a simple docker compose up. Your company's data never leaves your control.

Actively developed

Continuous updates, including alignment with the detailed technical document of the QNRCS 2026 as soon as it is published. Follow and contribute on GitHub.

Explore the repository

Frequently asked questions

Questions? That's natural: the regulation is new for everyone

Is my company covered by NIS2?

NIS2 covers entities across 18 sectors, including many medium-sized companies (and some small ones in specific cases). Our guide on NIS2 and Decree-Law 125/2025 helps you understand how the law applies to your organisation.

How much does the platform cost?

Zero. NIS2PME is open-source (AGPL-3.0) and free. You can deploy it on your own infrastructure with Docker and keep it fully under your control.

What is the QNRCS 2026?

The Portuguese National Cybersecurity Reference Framework is the technical reference that operationalises the requirements of Decree-Law 125/2025, organised into 6 domains and 3 compliance levels. The platform is aligned with Regulation no. 756/2026 (in force); the detailed technical document of the QNRCS 2026 has yet to be published and we track its evolution.

Is my data safe?

With the on-premises deployment, your data never leaves your infrastructure. Demo accounts on our hosting are for evaluation only: we recommend representative data, not real sensitive data.

See all questions

Start your path to compliance today

Find out in minutes where your company stands and what is left to do. Free, open-source, available in Portuguese and English.