A garment manufacturer in the Vale do Ave with 67 employees received the notification three months ago. It was not a fine. It was not an audit. It was classification: it entered the Portuguese list of operators of essential services under NIS2. The IT director, who for 15 years had managed a server in a cupboard, read "critical cybersecurity" and thought about budget. The CEO thought about compliance. Nobody thought about the truth: this is not an IT project. It is an operational change.
Directive (EU) 2022/2555 NIS2, transposed in Portugal by Decree-Law 65/2025, does not bring new technology. It brings an obligation to organise. And that obligation touches everything: from who can access the ERP to how backups are done, from who trains employees to who responds when there is an incident. The difference between "having security" and "demonstrating that you have security" is operational, not technical.
Who is affected and why
NIS2 does not touch every Portuguese industrial SME. It touches those that are "operators of essential services" in critical sectors: energy, transport, water, health, digital, food, physical infrastructure, public administration. In Portuguese industrial practice, this means:
- Food distributors with a logistics network above certain thresholds (central warehouse + distribution to retail chains).
- Food processing industry (milling, dairy, processed meats).
- Suppliers of critical components for essential sectors (e.g. car parts for commercial vehicle assemblers).
- Operators of telecommunications infrastructure or data centres.
Most garment makers, shoe factories and textile mills in the North do not fall in. But — and this is important — they are one step behind. If they supply a classified company, that company will require you to comply with NIS2 too. Subcontracting is a chain, not a silo.
NIS2 is not about having a firewall. It is about proving that the firewall exists, who manages it, when it was tested, and what you do when it fails.
What changes on the shop floor and in the back office
Let's be concrete. A typical textile factory with 120 employees, 3 shifts, cloud ERP and integrated WMS.
Access control
Today: 8 people have the ERP password written on a post-it on the warehouse desk. Tomorrow: each access is named, traceable, with multi-factor authentication if remote access, and auditable by a third party. This means different onboarding (how long until a new worker has justified access?), mandatory offboarding (when they leave, at what time is it removed?), and quarterly review of who still needs what. This is operational — it becomes an HR task, not an IT one. In a factory with shifts, this becomes complicated: if a worker leaves at night, who removes the access? What procedure exists to ensure removal is done before the next shift? NIS2 requires a written answer.
Security incidents
Today: if the ERP slows down because someone ran a heavy query, the warehouse manager calls IT and it gets resolved. Tomorrow: if there is a suspicion of unauthorised access, there is an obligation to notify the authority (CNCS — National Cybersecurity Command) within 72 hours. This requires a written procedure, a designated person responsible, and coordinated communication with legal/communications. A false start can cost a fine. Worse: a real incident that is not notified in time becomes a breach of law. Who is responsible for deciding whether it is an "incident"? Who calls the CNCS? What documentation is kept?
Backup and recovery
Today: we back up at the weekend, save it on a USB stick in a cupboard, and test it "when we have time". Tomorrow: backups are daily, immutable (cannot be deleted or altered, not even by the administrator, for X days), and recovery is tested quarterly with the date/time recorded. This affects IT planning — it needs different infrastructure, perhaps cloud with dedicated backup SaaS. A factory using MULTI ERP in the cloud has an advantage here — the vendor already manages backup — but the immutability configuration and the quarterly test remain your responsibility.
Training and awareness
NIS2 requires employees to have "cybersecurity awareness". This is not "sending an email about not clicking links". It is documented, annual training with assessment. Who delivers it? Who records it? Who proves it? This touches HR, touches operations, touches IT. In a garment maker with 67 employees and an ageing workforce, this is a real challenge: how do you train digital security to workers who learned the trade 30 years ago without a computer?
Data classification and protection
Today: customer data, production data, HR data — all on the same server. Tomorrow: you have to classify what is "critical", what is "sensitive", what is "public". Critical data has different protection: more restricted access, more frequent backup, encryption at rest and in transit. This requires data mapping — a task most SMEs have never done. How many customer files are on open network shares? How many system passwords are in Excel? NIS2 forces the answer.
The mistake we saw being made (and that you should not repeat)
Five years ago, we saw companies treating security as a pure IT project. They bought a firewall, installed antivirus, ran vulnerability scans. Then they got confused when auditors asked: "Who is responsible for security?", "How do you report incidents?", "What is the continuity plan?", "Who authorises access to customer data?". They were wrong — and we helped them be wrong because we focused on technology.
NIS2 is not technology. It is governance. Technology is a tool, but the change is organisational. A company that buys a €50,000 firewall but has no written incident procedure remains vulnerable — and in breach of the law.
So when a CEO asks us "How much does it cost to be compliant with NIS2?", the honest answer is: "It depends. The technology perhaps costs 15-20% of the effort. The other 80% is processes, paperwork, responsibilities, training, internal audit." And this is not sold by software vendors — it is done internally or with cybersecurity consultants, not IT consultants.
Practical planning for the next 12 months
If you have been classified, or if you expect to be, the sequence is this:
Months 1-2: Internal audit
Hire a certified cybersecurity auditor (ISO 27001) to map the current state: who accesses what, how the backup is stored, what the continuity plan is, is there incident documentation? This costs €3,000-8,000 and takes 2-3 weeks. It is an investment, not a cost. The auditor is not there to "pass an external audit" — it is to know where you stand. If you are in a bad way, better to know now than to find out when the CNCS inspection arrives.
Months 3-6: Governance
Define formal responsibilities. Who is the "person responsible for cybersecurity"? It need not be the CTO — it can be the IT director with external support. Document: access policy, incident policy, continuity plan, data classification matrix. This is internal work, with a template from consultants. This is also when you create the "security committee" — a monthly meeting between IT, operations, HR, legal — which will oversee implementation. Without a committee, each department does it its own way.
Months 7-10: Technical implementation
Now, yes, technology. Strengthen authentication (multi-factor for remote access), implement immutable backup, configure logging and alerts, test disaster recovery. If you use MULTI ERP or QAD Adaptive, these platforms have native audit and access control features — but configuration is not automatic. You need a specialist who knows the system and your business. This is when cybersecurity consultancy makes a difference: it is not generic consultancy, it is concrete implementation in your ERP.
Months 11-12: Training and validation
Train employees (documented), do an external penetration test (simulate an attack), validate that procedures work under pressure, document everything for future audit. The penetration test is important: it is not "running a tool". It is hiring an external specialist who tries to get into your system — and then reports real vulnerabilities. It costs €5,000-15,000, but it is proof that you tested.
Total cost and timeline
This is not "90 days". This is 12 months, with a total cost (audit, consultancy, technology, training) between €30,000 and €80,000 for an SME of 100-150 employees. A lot? Perhaps. But the fine for non-compliance ranges from €10 million to €20 million or 4% of turnover — whichever is greater. A garment maker with €5 million in annual turnover pays a €200,000 fine just for not having an incident procedure. This changes the perspective.
NIS2 is a business project disguised as an IT project. Treat it as such.
Questions for the next board meeting
If your company is classified (or suspects it may be), ask the IT director this:
- "Do we have documented who accesses each system, when, and why?"
- "Can we recover from backup in less than 24 hours?"
- "Do we have a written procedure to notify incidents to the CNCS?"
- "Who is responsible for cybersecurity — first name, surname, contact?"
- "When was the last time we tested disaster recovery?"
If the answer to any of them is "more or less" or "no", you are at operational risk — not just legal. This is not to frighten — it is to act.
Next steps
NIS2 does not bring magic technology. It brings an obligation to organise. And organisation, in a Portuguese factory with 80 employees and three shifts, is harder than buying a firewall.
If you need help mapping the current state of security, or designing technical controls for an ERP platform, talk to us. We have experience with cybersecurity services and a partnership with certified auditors. But the decision — and the work — is yours.
References
- Directive (EU) 2022/2555 — NIS2 (Directive on measures for a high common level of cybersecurity across the Union).
- Decree-Law 65/2025 (Portugal) — National transposition of NIS2.
- ENISA — Cybersecurity and Threat Reports (European Union Agency for Cybersecurity).
- CNCS — National Cybersecurity Command (Portugal) — Documentation on incident notification and essential operators.
- ISO 27001:2022 — International Information Security standard (reference for good audit practice).
