NIS2 in Portugal: What Changes for Suppliers of an Essential Entity
NIS2 does not only bind the organisations inside its scope. It reaches their suppliers through contract clauses, and that is where most Portuguese companies meet it for the first time.
There is a question that tends to surface halfway through a contract renewal, almost never at the start: "does this NIS2 thing apply to us?" Whoever asks it usually expects a no. Keep that expectation in mind. It comes back at the end.
Does NIS2 apply to my company?
Under the law, probably not. Under the contract, almost certainly yes.
Directive (EU) 2022/2555, known as NIS2, defines a closed set of sectors and size thresholds that determine who counts as an essential entity or an important entity. In Portugal, the directive was transposed through Decree-Law no. 125/2025, published on 4 December 2025 and in force since 3 April 2026. A niche software company with thirty people, a regional systems integrator, or a mid-sized managed service provider fall outside that list in most cases.
Falling outside the list does not mean falling outside the problem. The legal obligation sits with the client. The contractual obligation shifts to whoever supplies them.
What the directive says about suppliers
Supply chain security is not an extended reading of NIS2. It is one of the ten risk management measures written into Article 21(2)(d), which requires every entity in scope to address security in its relationships with direct suppliers and service providers, including the specific vulnerabilities of each one and the overall quality of their cybersecurity practices.
And it reaches further than the direct supplier. Commission Implementing Regulation C(2024)7151, in force since 17 October 2024, establishes that contract clauses must include cybersecurity requirements for the subcontractors of direct suppliers as well. The European Union Agency for Cybersecurity's (ENISA) technical implementation guidance, version 1.0 from June 2025, develops the same point.
The practical effect is easy to describe and uncomfortable to manage: an essential entity that cannot show how it assesses its suppliers is out of compliance. The cheapest way to show it is to push the requirement into the contract.
How the requirement actually arrives
It does not arrive as a letter from the regulator. It arrives through three channels, and none of them look like enforcement.
The first is the supplier questionnaire, which grows from two pages to twelve and stops asking only whether a firewall exists. The second is the new clause in a familiar template, carrying audit rights, incident notification deadlines, and obligations that extend to whoever the supplier in turn subcontracts. The third is the request for evidence before signature, not for the policy itself, but for the record proving the policy was actually carried out.
Watch the calendar here. The clock is not the supplier's, it is the client's. When the essential entity has an audit scheduled, the request travels down the chain on the client's deadline, not on the availability of whoever has to answer it.
How many companies are already doing this
The NIS360 2026 report from ENISA, now in its third annual edition, published on 28 May 2026, puts a number on it. Among the organisations surveyed, 90% report having controls in place to manage supply chain risk. Within that group, the figures that matter to a supplier are these:
And supply chain attacks are the second most cited future concern among entities in scope, named by 47% of them.
Translated for a supplier: for every two clients covered by NIS2, one already has the contractual right to audit whoever supplies them. This is not a trend still being announced. It is a clause that has already been signed.
What the client is going to ask
The questions repeat, sector after sector, because they all derive from the same article. There are five of them.
Who can access what, and how is that proven. How is an incident detected, and how quickly. How quickly is the client notified, and through which channel. What happens to the service if the system goes down. And what is the date of the last recovery test, not whether a plan exists.
The last one is where most answers fail. Having a recovery plan is common. Having the date of the last test, with the recovery time actually measured, is rare.
What to answer, and with what evidence
The answer that survives an audit always has the same shape: a claim, an owner, and a record that backs it up.
A named owner per domain. Not a team, a person, with an identified backup. No auditor accepts "the systems team" as the answer to who authorises a privileged access grant.
Access with a record of both granting and revoking. Almost everyone logs the granting. Revoking is where the evidence usually breaks down, especially when someone leaves mid-project.
Timed recovery, with a date. The recovery time objective (RTO) and the recovery point objective (RPO) only count for something alongside the report of the test that verified them, with the day it was carried out.
An audit trail that survives departures. If the record of who changed what depends on a personal account that gets deleted when the person leaves, that is not an audit trail, it is memory.
None of these four things is expensive. All four are hard to improvise in the week the questionnaire arrives.
Whoever operates other people's systems sits in the risk zone
NIS360 assesses high-criticality sectors along two dimensions, maturity and criticality, and calls risk zone the sectors where maturity sits below average and criticality exceeds that maturity. In other words, sectors more important to society than they are prepared to defend themselves.
IT service management sits in that zone, alongside health, rail, maritime, space, public administration and water. It is precisely the sector of whoever operates systems that belong to other people.
The attacker's logic explains why, and ENISA states it plainly about healthcare: attacking a hundred hospitals one by one takes far more effort than compromising the provider that serves all hundred. The argument holds for any managed service provider (MSP). Whoever concentrates access concentrates risk, and that concentration is exactly what a client is trying to assess when it asks for evidence.
When this is not worth the effort
It is worth saying the opposite too, because not every company needs to rush into this.
If no current client is an essential or important entity, if there is no realistic prospect of entering a supply chain that includes one, and if the business does not depend on multi-year contracts with regulated organisations, then building a full compliance programme means solving a problem that does not yet exist. In that case, the priority sits elsewhere.
The right distinction is not between large and small companies. It is between whoever sells to entities in scope and whoever does not. A fifteen-person company supplying software to a hospital has this problem. A two-hundred-person company selling only to local retail does not.
Frequently asked questions
Does NIS2 directly bind the suppliers of an essential entity? No. The legal obligation sits with the entity in scope. The supplier becomes bound through the contract, because the client needs to show the regulator how it manages the risk in its supply chain.
What changes with Decree-Law no. 125/2025? It is Portugal's transposition of the directive, published on 4 December 2025 and in force since 3 April 2026. It sets the national framework, the competent authority, and the duties of entities in scope in Portugal.
Is an ISO 27001 certification enough to answer a client? It helps and shortens conversations, but it does not replace the specific evidence a client asks for. What gets audited is the service delivered to that client, not just the management system in the abstract.
Do subcontractors fall in scope too? They do. Implementing Regulation C(2024)7151 explicitly names cybersecurity requirements for the subcontractors of direct suppliers, pushing the requirement one level further down the chain.
How long does it take to be ready for a questionnaire like this? It depends on the starting point, and the variable that carries the most weight is not technical. It is having named owners and records that survive team changes. Without that, any timeline is optimistic.
Conclusion
Go back to the expectation from the start, the one where the answer was going to be no.
It is right about the law and wrong about the effect. NIS2 does not turn every supplier into an obligated entity. It turns every contract with an entity in scope into a place where those obligations get written down. The difference between the two is legal. Commercially, the outcome is the same: either the answer exists as evidence, or the contract is at risk at the next renewal.
Whoever deals with this before the first questionnaire arrives answers in days. Whoever waits answers on the client's timeline, which is rarely generous.
On continuity and proof of recovery, it is also worth reading why having copies of the data is not the same as being able to operate again, and on operating under a client's contractual demands, why an in-house team cannot run SAP AMS 24 hours a day.
To prepare the answer to the first supplier questionnaire, without improvising in the week it lands, xGrowth starts with a brief call, no commitment, on compliance and cloud operations: Book a Clarity Session.
