Decree-Law No. 125/2025 entered into force in April, transposing the NIS2 Directive into Portuguese law and establishing the new Cybersecurity Legal Framework (Regime Jurídico da Cibersegurança – RJC).
The NIS2 Directive was introduced to strengthen cybersecurity across the European Union.
Its main objectives are to:
Who is covered by the Cybersecurity Legal Framework (RJC)?
Essential entities: Organizations operating in sectors considered highly critical to society and the economy, such as energy, transport, healthcare, digital infrastructure, electronic communications, banking, certain financial services, and other sectors specified by law.
Important entities: Organizations covered by the RJC that are not classified as essential. Their classification depends on factors such as the sector in which they operate, their size, and other legal criteria.
Relevant public entities: Public organizations that do not qualify as essential or important entities but meet the specific criteria established under the RJC, taking into account, in particular, the nature of their functions or their size.
Although the framework generally applies to medium-sized and large organizations, it may also apply to smaller entities where they meet specific legal criteria, particularly in light of the critical nature or importance of the services they provide.
So, what changes for organizations?
1. New responsibilities for senior management
Senior management is now expected to play an active role in cybersecurity. They must:
2. Risk management is no longer optional
Essential and important entities must implement cybersecurity measures covering, among other areas:
Relevant public entities must implement the cybersecurity measures established by the National Cybersecurity Centre (CNCS) under Regulation No. 756/2026 of 22 June.
3. Cybersecurity Officer
Essential and important entities must appoint a Cybersecurity Officer, whose responsibilities include:
4. Incident notification
Entities covered by the RJC must notify the competent cybersecurity authority of significant cybersecurity incidents.
The reporting process includes:
What happens in case of non-compliance?
The new framework provides for administrative fines of up to:
Additional enforcement measures may also be imposed, including:
The Decree-Law has been in force since 3 April 2026.
Until 3 April 2027, entities subject to the Cybersecurity Legal Framework (RJC) may, upon submitting a reasoned request, apply for a waiver of imposed administrative fines.
On 23 June 2026, Regulation No. 756/2026 entered into force, establishing the practical implementation of the Cybersecurity Legal Framework in areas such as incident reporting and communication with the competent cybersecurity authority.
Is your organisation prepared?
Identifying the applicable obligations at an early stage and preparing your organisation accordingly are essential to ensuring compliance and strengthening digital resilience.