The publication of Decree-Law No. 125/2025 of 4 Decembermarks an important step in the evolution of the legal framework for cybersecurity in Portugal.
The decree approves the new Cybersecurity Legal Frameworkand transposes Directive (EU) 2022/2555, known as the NIS 2 Directive, into Portuguese law..
In practice, this new framework broadens the scope of entities covered, strengthens obligations relating to risk management and incident notification, and reinforces the role of the National Cybersecurity Centre (CNCS) as the national cybersecurity authority.
The decree establishes the new legal framework applicable to cybersecurity in Portugal and defines the legal basis for the national implementation of NIS 2. In addition to the main framework, it also provides for complementary instruments that will be key to its practical implementation.
The new framework will be complemented by three central instruments of Portugal’s Cybersecurity architecture:
The new Cybersecurity Legal Framework applies to different types of entities, depending on their sector of activity, size, level of exposure to risk and operational relevance. Broadly speaking, the framework distinguishes between essential entities, important entities and relevant public entities.
Where an entity may fall into more than one category, the most demanding classification prevails in terms of the applicable requirements, in the following order:
The following are considered essential entities, among others:
The following are considered important entities:
Public entities that are not classified as essential or important entities are considered Relevant Public Entities.
For the purposes of the Cybersecurity Legal Framework, these entities are divided into two groups.
The following fall within Group A:
The following fall within Group B:
This decree significantly broadens the range of entities covered and strengthens three core areas:
In addition, the decree enters into force 20 days after publication, that is, on 3 April 2026, and provides for fines that may reach €10 million or 2% of annual turnover, whichever is higher.
Annex I – Sectors of high criticality
Annex II – Other critical sectors
Qualification of entities electronic platform made available by the CNCS. As a rule, this identification must take place within 30 days of the start of activity or, in the case of entities already in operation, within 60 days of the platform becoming available, with the information then kept up to date. The draft regulation currently under public consultation sets out the functions of this platform in detail, including the registration of entities, the submission of the annual report, the indication of the cybersecurity officer, the permanent contact point and the notification of incidents.
The classification of entities as essential or important is carried out by the CNCS and must be duly reasoned in accordance with the mechanisms laid down in the decree.
The management, executive and administrative bodies of essential and important entities will have direct responsibilities, namely to:
In addition:
Cybersecurity risk management system:
These measures must:
The framework also refers to CNCS regulation for:
The areas to be covered by cybersecurity measures include:
In the case of relevant public entities:
The decree gives specific attention to supply chain security. The measures to be adopted must take into account:
Essential and important entities must:
Based on that assessment, they must also:
Essential and important entities must prepare and maintain an annual report including, among other elements:
As regards the submission of the report:
Essential and important entities must appoint a cybersecurity officer responsible for managing cybersecurity and information security.
This person must:
Entities that were already in operation when the decree entered into force have:
In practice, this deadline falls:
The minimum duties of this officer include:
Essential and important entities must ensure and notify CNCS of a permanent contact point with continuous availability.
This contact point must ensure:
As with the cybersecurity officer:
CNCS may require essential, important and relevant public entities to obtain:
Essential, important and relevant public entities must notify CNCS of any significant incident.
For this assessment, factors such as the following must be taken into account:
The framework provides for:
In addition:
The framework distinguishes the intensity of supervision according to the type of entity.
Essential entities are subject to broader supervisory measures, including:
Important entities and relevant public entities are subject to an ex postsupervisory regime, applicable where there is evidence, indication or information of non-compliance.
This regime may include:
Failure to comply with the obligations laid down in the new Cybersecurity Legal Framework may give rise to significant fines.
In the case of essential entities, very serious administrative offences may lead to fines of:
CNCS has also highlighted this strengthening of the sanctions framework as one of the clearest signs of greater accountability.
In addition:
Although the decree is already in force, a significant part of its implementation still depends on supplementary regulation from CNCS. The draft regulation of the Cybersecurity Legal Framework is currently under public consultationand covers matters such as the electronic platform, compliance levels, verification criteria and the measures applicable to relevant public entities.
In addition, the decree itself provides that some provisions will only take effect 24 months after the publication of the regulation referred to in several of its articles. This makes it particularly important to follow the regulatory developments closely and prepare the organisation in advance.
For that reason, the most important step at this stage is to determine whether the organisation is directly or indirectly covered by the decree, ensure its identification before CNCS where applicable, and assess, in an integrated way, its level of legal, procedural, organisational and technological compliance. Only after that assessment will it be possible to define a realistic adaptation roadmap, with clear priorities, proportionate measures and lower exposure to non-compliance.
Early preparation will be decisive. In a framework that strengthens obligations, supervision and sanctions, acting early remains the smartest way to reduce risk and create room to execute properly.
Get in touch with us at info@orbcom.pt.
Sign up to our newsletter and keep up with the latest insights.
If you would like to get to know ORBCOM better and understand how our products, consulting services and outsourcing, fit your reality, speak to a specialist.