Cybersecurity is no longer optional.
With the entry into force of Decree-Law no. 125/2025, Portugal has definitively transposed the European NIS2 Directive — and the companies covered already have concrete obligations to fulfil.
What is the NIS2 Directive?
NIS2 (Network and Information Security Directive 2) is the new European cybersecurity framework, published by the European Union on 27 December 2022 and in force since 16 January 2023. In Portugal, it was transposed through Decree-Law no. 125/2025, published on 4 December 2025, entering into force on 3 April 2026.
The aim is to raise the level of digital protection across the European Union, harmonise requirements between countries and ensure that organisations are prepared to respond to incidents quickly and effectively.
Compared with the previous NIS Directive of 2016, NIS2 goes much further — it covers roughly 10 times more entities, increases technical requirements and, for the first time, holds management bodies directly accountable for compliance with cybersecurity measures.
Is your company covered?
In Portugal, the law organises entities into three categories:
- Essential entities — critical operators with high systemic impact (energy, healthcare, banking, digital infrastructure, among others).
- Important entities — organisations in strategic sectors with relevant, but lesser, impact in the event of disruption.
- Relevant public entities — public administration bodies with specific criteria.
In general, a company is covered if it operates in one of the 18 sectors defined in Annexes I and II of the Directive and is classified as a medium or large company (≥ 50 employees and turnover ≥ 10 million euros). There are exceptions for certain critical service providers, regardless of their size.
If you have doubts about whether your organisation is included, do not wait for the CNCS notification — get ahead of it.
What changes in practice?
NIS2 introduces a set of concrete obligations that go beyond simple paper compliance. The most relevant include:
- Cybersecurity risk management — organisations must identify, assess and mitigate risks on an ongoing basis, with documented policies and clear processes.
- Incident notification — in the event of a significant incident, essential entities have strict deadlines for reporting to the CNCS. The final report must be submitted within 30 working days of the end-of-impact notification.
- Accountability of top management — this is perhaps the most disruptive point. Cybersecurity is no longer “an IT problem”. Directors and members of management bodies are personally responsible for compliance with the obligations, and that responsibility cannot be delegated outside the management bodies.
- 9 mandatory minimum measures — defined in Article 21 of the Directive, they include access control policies, business continuity management, supply chain security, encryption, among others.
- Continuous training — organisations must promote and ensure regular cybersecurity training for the relevant teams.
What are the consequences of non-compliance?
The fines provided for in Decree-Law no. 125/2025 are significant:
- Very serious offences: up to 10 million euros or 2% of worldwide annual turnover, whichever is higher.
There is, however, a grace period: during the first 12 months, companies that demonstrate to the CNCS that they have started an internal adaptation process may avoid the application of fines — although they remain obliged to notify incidents.
What actions should you take now?
There are immediate obligations that do not allow delay:
- Registration on the MyCiber platform (myciber.gov.pt) — the initial deadline was 4 May 2026.
- Appointment of a cybersecurity officer.
- Implementation of the 9 measures of Article 21.
- Internal assessment of the current level of compliance.
If you have not yet started this process, the time to act is now.
How INFOS can help
At INFOS, we work closely with our customers throughout this transition. To support organisations that need to understand exactly where they stand — and what they need to do —, we offer a rapid-response service:
NIS2 Quick-Diagnosis (3 days)
In just three working days, our team carries out a focused and objective assessment, which includes:
- ✅ Assessment of existing security policies and mechanisms
- ✅ Identification of vulnerabilities and compliance gaps
- ✅ Compliance report against the requirements of Decree-Law no. 125/2025
- ✅ Clear and prioritised recommendations for risk mitigation
The result is a concrete action plan so that your organisation increases its digital resilience and is prepared for CNCS inspections — no surprises, no penalties.
Do not wait for the inspection. Get ahead of it.
NIS2 is not just another directive that can be postponed. The obligations are real, the deadlines are already running and the responsibility is personal for those who lead organisations.
Sources: Decree-Law no. 125/2025, CNCS (cncs.gov.pt), Directive (EU) 2022/2555 of the European Parliament and of the Council.
