PT
Cybersecurity in Portugal: The New Cybersecurity Legal Framework
Notícia

Cybersecurity in Portugal: The New Cybersecurity Legal Framework

Cybersecurity in Portugal: The New Cybersecurity Legal Framework

Decree-Law No. 125/2025 entered into force in April, transposing the NIS2 Directive into Portuguese law and establishing the new Cybersecurity Legal Framework (Regime Jurídico da Cibersegurança – RJC).

The NIS2 Directive was introduced to strengthen cybersecurity across the European Union.

Its main objectives are to:

  1. Increase the digital resilience of organizations;
  2. Harmonize cybersecurity rules across Member States;
  3. Strengthen the response to cybersecurity incidents. 

 

Who is covered by the Cybersecurity Legal Framework (RJC)?

Essential entities: Organizations operating in sectors considered highly critical to society and the economy, such as energy, transport, healthcare, digital infrastructure, electronic communications, banking, certain financial services, and other sectors specified by law.

Important entities: Organizations covered by the RJC that are not classified as essential. Their classification depends on factors such as the sector in which they operate, their size, and other legal criteria.

Relevant public entities: Public organizations that do not qualify as essential or important entities but meet the specific criteria established under the RJC, taking into account, in particular, the nature of their functions or their size.

Although the framework generally applies to medium-sized and large organizations, it may also apply to smaller entities where they meet specific legal criteria, particularly in light of the critical nature or importance of the services they provide.

 

So, what changes for organizations?

1. New responsibilities for senior management

Senior management is now expected to play an active role in cybersecurity. They must:

  • Approve cybersecurity risk management measures;
  • Oversee their implementation;
  • Ensure appropriate training;
  • Ensure compliance with legal obligations.

 

2. Risk management is no longer optional

Essential and important entities must implement cybersecurity measures covering, among other areas:

  • Incident handling;
  • Business continuity;
  • Supply chain security;
  • Basic cyber hygiene practices and cybersecurity awareness training;
  • Human resources security;
  • Other appropriate cybersecurity measures.

Relevant public entities must implement the cybersecurity measures established by the National Cybersecurity Centre (CNCS) under Regulation No. 756/2026 of 22 June.

 

3. Cybersecurity Officer

Essential and important entities must appoint a Cybersecurity Officer, whose responsibilities include:

  • Proposing cybersecurity risk management measures;
  • Providing information on cybersecurity risk management measures;
  • Assisting with supervisory and enforcement requirements;
  • Promoting a cybersecurity culture;
  • Managing residual cybersecurity risk;
  • Ensuring the preparation of the annual report;
  • Coordinating the activities of the permanent point of contact.

 

4. Incident notification

Entities covered by the RJC must notify the competent cybersecurity authority of significant cybersecurity incidents.

The reporting process includes:

  • Initial notification;
  • Interim reports, where applicable;
  • Notification that the significant impact has ended;
  • Final report.

 

What happens in case of non-compliance?

The new framework provides for administrative fines of up to:

  • €10 million or 2% of the organization's total worldwide annual turnover, whichever is higher, for legal entities;
  • €200,000 for natural persons.

Additional enforcement measures may also be imposed, including:

  • Ancillary sanctions, such as restrictions on business activities and the implementation of mandatory cybersecurity action plans; and
  • Periodic penalty payments.

 

The Decree-Law has been in force since 3 April 2026.

 

Until 3 April 2027, entities subject to the Cybersecurity Legal Framework (RJC) may, upon submitting a reasoned request, apply for a waiver of imposed administrative fines.

On 23 June 2026, Regulation No. 756/2026 entered into force, establishing the practical implementation of the Cybersecurity Legal Framework in areas such as incident reporting and communication with the competent cybersecurity authority.

 

Is your organisation prepared?

Identifying the applicable obligations at an early stage and preparing your organisation accordingly are essential to ensuring compliance and strengthening digital resilience.