Skip to NIS2 content

NIS2 in Portugal

Regime in force

From obligation to action plan.

Decree-Law 125/2025 transposed the NIS2 Directive and approved Portugal’s new Cybersecurity Legal Framework. Preparation requires scoping, governance, risk management, response capability and evidence — not just new tools.

Editorial update

Reviewed on 10 August 2026 against official sources.

Portuguese framework

NIS2 has been transposed in Portugal.

The new regime broadens the reach of cybersecurity requirements and reinforces accountability, with proportionate obligations based on entity size and the importance of its activities.

DL 125/2025
New Portuguese Cybersecurity Legal Framework
03.04.2026
Entry into force, 120 days after publication
17 sectors
Scope stated by Portugal’s National Cybersecurity Centre

The law was published on 4 December 2025 and transposes Directive (EU) 2022/2555 into Portuguese law. Regulation 756/2026 further specifies requirements for essential, important and relevant public entities.

Compliance should be managed as a continuous governance and resilience programme. Entity classification, services, size, sector and any special regimes shape the obligations that apply.

Scope

Sector is the starting point, not the complete answer.

NIS2 covers public and private entities performing critical activities. Assessment must consider the actual activity, size rules, exceptions and entities covered regardless of size.

A generic checklist does not replace an assessment of the organisation’s legal and operational context.
See who is in scope

Examples of covered areas

  • Energy
  • Transport
  • Banking and financial markets
  • Healthcare
  • Drinking water and wastewater
  • Digital infrastructure
  • B2B ICT managed services
  • Public administration
  • Postal services
  • Waste management
  • Critical manufacturing
  • Research

Questions the assessment should answer

  • Which services and activities fall within the framework?
  • Is the organisation essential, important or a relevant public entity?
  • Are there special sector rules or critical third-party dependencies?
  • Which systems, suppliers and processes support the covered services?
  • Who approves, oversees and evidences risk-management measures?

Core obligations

Compliance connects leadership, operations and evidence.

The programme must combine proportionate technical, operational and organisational measures. These workstreams normally need to be assessed together.

Governance and accountability

Management approval and oversight, clear responsibilities, training and executive reporting.

Risk management

Policies, risk analysis, system security, vulnerability management, cryptography and access control.

Incident reporting

Severity criteria, detection, escalation, evidence preservation and the ability to meet applicable deadlines.

Continuity and recovery

Backups, recovery, crisis management, exercises and validation of RTO and RPO for critical services.

Supply-chain security

Dependencies and supplier assessment, contractual requirements, third-party risk and continuous monitoring.

People and culture

Cybersecurity hygiene, role-appropriate training and procedures that work in day-to-day operations.

Preparation roadmap

An executable journey with priorities and owners.

Shore structures preparation so that scoping becomes a measurable operational plan aligned with risk and the organisation’s technology reality.

  1. 01

    Scope

    Map entities, services, sectors, size, dependencies and applicable requirements.

  2. 02

    Assess

    Collect evidence and compare governance, processes and controls with the framework and regulation.

  3. 03

    Prioritise

    Define gaps, risk, owners, effort, dependencies and the remediation sequence.

  4. 04

    Implement

    Execute organisational and technical measures while preserving operational continuity.

  5. 05

    Test and evidence

    Run exercises, measure effectiveness, organise evidence and maintain an improvement cycle.

Official sources

Follow the framework through authoritative sources.

The legal framework and regulation can evolve. Assessments should always use the current versions of official sources.

This page is for information only and does not constitute legal advice. The specific scope should be confirmed with appropriate legal and technical support.

NIS2 assessment

Turn requirements into a concrete action plan.

We assess your context, identify gaps and organise governance, process and technology priorities.