NIS2 in Portugal: the Regime Jurídico da Cibersegurança

Who is covered, the timeline and what to do first, with every date linked to the article that sets it.

What the RJC is

Decreto-Lei n.º 125/2025, of 4 December, approves the Regime Jurídico da Cibersegurança (RJC) and with it transposes Directive (EU) 2022/2555, NIS2, into Portuguese law (art. 1). It came into force on 3 April 2026, 120 days after publication (art. 11), and repealed Lei n.º 46/2018 and Decreto-Lei n.º 65/2021, which had governed the security of cyberspace until then (art. 9).

Regulamento n.º 756/2026 of the CNCS (Centro Nacional de Cibersegurança), published on 22 June 2026 and in force since the following day (art. 34), puts the regime into practice. It has four annexes: Annex I is the Quadro Nacional de Referência para a Cibersegurança (QNRCS); Annex II is the risk matrix that sets each entity's compliance level; Annex III gathers the minimum cybersecurity measures for essential and important entities, by level; and Annex IV, those for relevant public entities, by group, which the note Annex IV, group by group reads measure by measure.

Verified on 26 September 2026 against the text of Decreto-Lei n.º 125/2025 and Regulamento n.º 756/2026 as published in the Diário da República. The sources are at the end of the page.

Who is covered

Three categories: essential entities, important entities and relevant public entities (entidades públicas relevantes), the last in two groups. An entity that fits more than one falls into the most demanding (RJC, art. 9).

Sectors of high criticality (Annex I)

Energy; transport; banking; financial market infrastructure; health; drinking water; waste water; digital infrastructure; ICT service management (business-to-business); space.

Other critical sectors (Annex II)

Postal and courier services; waste management; chemicals; food; manufacturing; digital providers; research.

Essential and important entities

As a rule, medium-sized and large companies in those 17 sectors (RJC, art. 3(1)). Large companies in Annex I are essential, as are some providers whatever their size, such as qualified trust service providers, DNS service providers and top-level domain name registries; the rest are important (art. 6).

Relevant public entities

Group A: direct administration with 250 or more employees, indirect and autonomous administration with more than 250, independent administrative entities and other bodies the article lists. Group B: direct, indirect and autonomous administration with 75 to 249 employees (RJC, art. 7). Banco de Portugal, the CMVM and the ASF are excluded (art. 3(3)).

Which category does your entity fall into?

An indication in three questions. The qualification is made by the CNCS and notified to the entity; this answer does not replace it. The answers are neither stored nor sent to anyone.

1. The entity is
2. If private, the sector
3. The size

Private, under Recommendation 2003/361/EC (RJC, Annex III):

Public, by number of employees:

The timeline

The fixed dates and the deadlines that run from an act of the CNCS, in the order they arrive.

When What happens Where it is
3 Apr 2026 The RJC comes into force. DL 125/2025, art. 11
23 Jun 2026 Regulamento n.º 756/2026 comes into force. Reg. 756/2026, art. 34
60 days after the platform opens Entities already operating register on the CNCS electronic platform (MyCiber). Those that start later have 30 days from the start of their activity. The CNCS counts these deadlines in working days (dias úteis). RJC, art. 8(1)
Within 30 days of qualification The CNCS notifies the entity of its qualification, with the compliance level and the applicable measures. RJC, art. 8(5); Reg., art. 9
20 working days after notification Essential and important entities communicate their Responsável de Cibersegurança (cybersecurity officer); entities also communicate their Ponto de Contacto Permanente (permanent point of contact). RJC, arts. 31 and 32; Reg., arts. 14 and 15
The following 31 January, or 6 months First Lista de Ativos (list of publicly accessible assets): every asset directly reachable from the internet. Due on whichever date comes first, counted from notification. Reg., art. 32
3 Apr 2027 The 12-month period ends during which an entity may request, with grounds, exemption from fines. RJC, art. 65
22 Jun 2028 The cybersecurity measures and the annual report take effect: 24 months after the implementing regulation. DL 125/2025, art. 10(2)
Every year, by the last working day of January Annual report of essential entities, signed by the Responsável de Cibersegurança. RJC, art. 30; Reg., art. 13

When there is a significant incident

Essential, important and relevant public entities notify the CNCS (RJC, art. 40). An incident resolved in less than two hours only needs the end-of-impact notification (art. 41(2)).

24 hours

Initial notification, without undue delay (art. 42(1)).

72 hours

Update of the initial notification, where necessary (art. 42(3)).

24 hours after the end

Notification of the end of the significant impact (art. 43).

30 working days

Final report, counted from the end-of-impact notification (art. 44).

The thresholds that make an incident significant for entities outside Implementing Regulation (EU) 2024/2690 are to be set by a CNCS technical instruction, not yet published at the date of this page.

Where we come in

We do not do the qualification or manage the regime. We produce the technical evidence that some obligations call for.

Obligation What it requires What we bring
Lista de AtivosReg., art. 32 Every asset directly reachable from the internet, updated every year. Buteo keeps the inventory of what your domain shows the internet: subdomains, services, ports and certificates, scan after scan.
Secure developmentRJC, art. 27(1)(d) Security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure. The source code audit and Goshawk read the code, yours and your suppliers', and each flaw is linked to the measure it touches.
Knowing the internal assetsQNRCS (Annex I), Identify objective Knowing what is on the network, including where no cloud service reaches. Ibex discovers the hosts on each segment from a sealed appliance inside the perimeter, with no connection to the outside.

Frequently asked questions

Do I have to register?

If the entity is covered, yes: it is the entity that identifies itself on the CNCS electronic platform, and failing to register is a serious administrative offence (RJC, arts. 8 and 62).

Who can be the Responsável de Cibersegurança?

In essential and important entities, a member of the management body or someone who reports directly to it (RJC, art. 31).

What is the Lista de Ativos?

The list of every asset directly reachable from the internet, classified as "reservado" (restricted), submitted for the first time by 31 January of the year after notification or six months after it, and then every year (Regulamento n.º 756/2026, art. 32).

How is the compliance level set?

By sector, by size and by the risk matrix in Annex II of the Regulamento: a risk value of 0 to 99 gives the basic level, 100 to 199 the substantial level, 200 to 1200 the high level. The levels are cumulative (Regulamento, arts. 28 and 30).

Does an ISO/IEC 27001 certification count?

Compliance is presumed when the scope of the certification covers all the systems in scope. For relevant public entities, DNP TS 4577-1, the Selo Digital, also counts (Regulamento, art. 27(3)).

What if the entity is also subject to DORA?

The RJC is without prejudice to Regulation (EU) 2022/2554, applicable since 17 January 2025 (RJC, art. 3(9)). DORA-related incidents go to the financial authorities, but the RJC obligations on the Responsável, the Ponto de Contacto and incident notification remain (Regulamento, art. 10).

What are the fines?

For very serious offences: for essential entities, from €2,000 to €10 million or 2% of worldwide turnover, whichever is higher; for important entities, from €1,250 to €7 million or 1.4%; for relevant public entities, up to €4 million in Group A and up to €350,000 in Group B (RJC, art. 61). Members of the management body may be liable for acts or omissions, with intent or gross negligence (art. 25).

Is there still time before fines apply?

Until 3 April 2027, an entity may request exemption from fines, on the grounds that it had no internal adaptation procedures (RJC, art. 65). And, save in cases of intent, the proceedings require a prior warning to comply within a reasonable period (art. 66(5)).

Sources

This page explains the regime and is not legal advice.

Which measure can you not yet evidence?

Tell us your sector and size, and we will tell you what we can already evidence for you, and what we cannot.