Start with what you can verify on your own, before speaking to anyone. The public IAPMEI list of PME Líder companies, the public contracts record on the Base portal, the open source the company publishes, and its filed accounts. Four sources independent of any sales conversation.
Then assess what changed in 2026. Portugal transposed NIS2 through Decreto-Lei n.º 125/2025 of 4 December, which approved the Regime Jurídico da Cibersegurança and entered into force on 3 April 2026. The obligations attach to the covered entity, which means the security posture of whoever builds and maintains your software became part of your own exposure. Very serious administrative offences reach 10 million euros.
The second date is 11 September 2026, when the reporting obligations in Article 14 of the Cyber Resilience Act started applying to anyone placing products with digital elements on the EU market, including those bundling open source components. We covered what that requires in 24-hour vulnerability reporting under the CRA and in cyber resilience with open source and secure by design. The practical effect is simple. The question of whose name goes in the contract stopped being purely commercial.
What can you verify before the first meeting?
More than most buyers attempt. Four checks, all in public sources, all independent of what the company says about itself.
None of these checks tells you whether the company is good at writing software. They tell you whether it is a serious company, which eliminates a considerable part of the market before spending a meeting.
One note on PME Líder: it is a financial status, not a technical one. In the 2025 edition 14,133 companies across all sectors were recognised, so it is neither rare nor distinctive in itself. The value is the inverse. If a company with ten years of trading does not hold it, that is worth two questions.
What does NIS2 require you to demand from a software supplier?
The supply chain management obligation attaches to the covered entity. That is, to the client. If you are in scope and your supplier cannot demonstrate its security posture, the finding is yours. Eight clauses are worth a contract review at the next renewal.
And there is a consequence almost nobody anticipates. Contracts signed before April 2026 contain none of this, because no obligation existed. That is nobody’s failure. It is work outstanding.
Which questions separate suppliers who look identical?
Every proposal says the team is senior and the methodology is agile. These five produce different answers.
Which contracting model matches your problem?
How do you compare proposals without comparing only price?
Two proposals for the same request rarely cover the same scope, which makes direct value comparison misleading. Normalise first.
On figures, an honest position. We do not publish price ranges in this article because the answer depends on scope, the number of platforms, audit requirements and what already exists. Any published range would be too wide to decide with or too narrow to be true. Describe the scope and ask for a number, not a range.


