In their capacity as a regulator, the Portuguese National Cybersecurity Centre (CNCS) is at the forefront of adapting to NIS2 requirements and ensuring that entities under their purview are compliant. They provide strategic oversight and support for organisations navigating the complexities of the new directive, which introduces stricter standards for risk management, incident response, and supply chain security.
As the single point of contact and national competent authority for NIS in Portugal, the CNCS oversees cybersecurity for public administration entities, critical infrastructure operators, operators of essential services, and digital service providers, while also working to raise cybersecurity awareness across society.
In this Q&A, CNCS shares valuable insights into the challenges, requirements, and best practices surrounding NIS2 compliance, providing a real-world perspective on how organisations can align with the regulation and build stronger cybersecurity frameworks.
Q: What are the main challenges organisations are encountering in the implementation of NIS2? Are there specific areas or requirements within NIS2 that raise significant concerns or doubts from organisations?
A: The transposing of NIS2 directive into the national legal framework is still ongoing, so it is not easy to identify current challenges and concerns. However, from an analytical perspective of the foundations of NIS2 and, mainly, the conceptual differences comparing with the first directive, we can state that the compliance effort by essential and important entities, especially those already covered by NIS1, will not be substantial.
NIS2 reinforces the importance of the principle of proportionality indexed to the risk of each covered entity, but this was precisely the Portuguese approach in 2018 with Law No. 46/2018, later reinforced by Decree-Law No. 65/2021. For this reason, significant methodological changes are not expected.
On the other hand, NIS2 aims to harmonise and, therefore, correct significant asymmetries between the various Member States in the values of pecuniary sanctions for non-compliance with their obligations. This approach, coupled with greater accountability of the leadership within regulated entities, aims to place cybersecurity as a top concern in the decision-making chain.
Q: In your opinion, which specific NIS2 Security requirement (Article 21) poses the greatest challenge for companies to address, and why?
A: The challenges that companies face are closely linked to the threat landscape, volatile by nature, and their degree of digital exposure to the outside world, including their supply chain. In this context, the best approach involves continuous risk assessment, where each company evaluates its risks and adopts the most effective cybersecurity controls to mitigate them.
These controls should be aligned with available cybersecurity frameworks, whether it be the National Cybersecurity Framework of CNCS or other recognized cybersecurity frameworks, such as ISO 27001 or the NIST CSF. The sector, the size of the organisation, the level of digital exposure, and trends in cyber threats will influence the risk assessment and the controls necessary to address them. The message to convey is that each case is unique, and the challenges will always be a result of the specific circumstances of each organisation.