NIS2 compliance as a layer.
Sublyzer NIS2 is a dedicated product for the Portuguese cybersecurity regime — DL 125/2025, Regulamento 756/2026, MyCiber and the QNRCS framework.
Built for the regime. Evidence by default.
A dedicated product for the Portuguese cybersecurity regime — it can plug into the rest of the Sublyzer stack when you already run it, but it's made for NIS2/RJC first.
Asset inventory & risk
RJC art. 14.ºEvery asset discovered and classified, with risk graded against the regime's expectations — continuously, not once a year.
- Continuous asset discovery
- Risk classification
- Audit-ready inventory
Incident evidence
Art. 23.º · MyCiberTimestamped, evidence-backed finding packs ready to attach to MyCiber/QNRCS filings within the 72h / 24h notification windows.
- 72h notification packs
- 24h update packs
- QNRCS-ready exports
Resilience verification
RJC art. 16.ºReproducible technical resilience testing with PoC-verified results — the technical proof behind every compliance report.
- Deep scans with PoC verification
- TestingAI run evidence
- Repeatable test runs
Continuous monitoring
24/7Exposure drift, brand impersonation and anomaly watch that keeps the compliance evidence chain alive between assessments.
- 24/7 exposure watch
- Drift & impersonation alerts
- Continuous evidence feed
Every obligation. An answer.
Each RJC obligation maps to a concrete Sublyzer capability with evidence you can hand to your auditor or the CNCS.
Asset inventory & risk analysis
RJC art. 14.º — know your assets, map the risk.Automatic asset discovery, risk grading and drift monitoring keep the inventory current — continuously.
Incident notification (MyCiber)
RJC art. 23.º / Regulamento 756/2026 — notify within 72h, update within 24h.Every confirmed finding carries timestamped evidence ready to attach to MyCiber/QNRCS filings.
Resilience testing
RJC art. 16.º — regular testing of technical resilience.Deep scans and TestingAI agents deliver reproducible, PoC-verified test evidence.
Supply chain security
RJC art. 15.º — manage risk in direct suppliers.Dependency checks and GitHub PR provenance make third-party risk visible and provable.
Governance & evidence
RJC art. 12.º/13.º — measures proportionate to risk, documented.Every decision is logged — detected → confirmed → fixed → verified. Audit trail by default.
Choose your compliance tier.
Pick the tier that matches your entity class and scope.
NIS2 Essentials
For entities starting their RJC compliance journey.
- Core telemetry + security
- Instant asset capture on up to 5 assets
- Deep scans: 1/month per asset
- Asset inventory & risk report
- MyCiber-ready incident evidence pack
NIS2 Compliance
Everything the regime asks for, continuously.
- Everything in Essentials
- 24/7 exposure watch
- Deep scans: weekly per asset
- TestingAI resilience runs with evidence
- QNRCS self-assessment alignment
- Supply chain dependency watch
NIS2 Enterprise
For essential entities and groups with multi-entity scope.
- Everything in Compliance
- Unlimited entities & assets
- Dedicated evidence & audit exports
- Automated MyCiber/QNRCS filing support
- Priority security response
- Named success manager
NIS2 questions, answered.
What is the Portuguese NIS2 regime?
The Regime Jurídico da Cibersegurança (RJC), approved by Decreto-Lei 125/2025, transposes Directive (EU) 2022/2555 (NIS2) into Portuguese law, with implementation rules in Regulamento 756/2026 and notification via the MyCiber platform (QNRCS reference framework).
Is Sublyzer NIS2 a new product?
Yes — it is a dedicated product built specifically for the Portuguese regime. It can reuse capabilities from the Sublyzer stack when you already run them, but it is designed to stand on its own for NIS2/RJC.
Does it replace legal or audit advice?
No. Sublyzer NIS2 delivers the technical evidence, testing and continuous monitoring that support your compliance work. It does not issue legal opinions — coordinate with your DPO, auditor and the CNCS guidance.