Governance and accountability
Management approval and oversight, clear responsibilities, training and executive reporting.
NIS2 in Portugal
Regime in force
Decree-Law 125/2025 transposed the NIS2 Directive and approved Portugal’s new Cybersecurity Legal Framework. Preparation requires scoping, governance, risk management, response capability and evidence — not just new tools.
Editorial update
Reviewed on 10 August 2026 against official sources.
Portuguese framework
The new regime broadens the reach of cybersecurity requirements and reinforces accountability, with proportionate obligations based on entity size and the importance of its activities.
The law was published on 4 December 2025 and transposes Directive (EU) 2022/2555 into Portuguese law. Regulation 756/2026 further specifies requirements for essential, important and relevant public entities.
Compliance should be managed as a continuous governance and resilience programme. Entity classification, services, size, sector and any special regimes shape the obligations that apply.
Scope
NIS2 covers public and private entities performing critical activities. Assessment must consider the actual activity, size rules, exceptions and entities covered regardless of size.
Core obligations
The programme must combine proportionate technical, operational and organisational measures. These workstreams normally need to be assessed together.
Management approval and oversight, clear responsibilities, training and executive reporting.
Policies, risk analysis, system security, vulnerability management, cryptography and access control.
Severity criteria, detection, escalation, evidence preservation and the ability to meet applicable deadlines.
Backups, recovery, crisis management, exercises and validation of RTO and RPO for critical services.
Dependencies and supplier assessment, contractual requirements, third-party risk and continuous monitoring.
Cybersecurity hygiene, role-appropriate training and procedures that work in day-to-day operations.
Preparation roadmap
Shore structures preparation so that scoping becomes a measurable operational plan aligned with risk and the organisation’s technology reality.
Map entities, services, sectors, size, dependencies and applicable requirements.
Collect evidence and compare governance, processes and controls with the framework and regulation.
Define gaps, risk, owners, effort, dependencies and the remediation sequence.
Execute organisational and technical measures while preserving operational continuity.
Run exercises, measure effectiveness, organise evidence and maintain an improvement cycle.
Official sources
The legal framework and regulation can evolve. Assessments should always use the current versions of official sources.
This page is for information only and does not constitute legal advice. The specific scope should be confirmed with appropriate legal and technical support.
NIS2 assessment
We assess your context, identify gaps and organise governance, process and technology priorities.