DataRoad · IT Services and ConsultancyWe do IT right

NIS2 in Portugal

Who is covered?

There is a deadline for registration on MyCiber, which ends in mid-September 2026.

Decree-Law 125/2025 is now in force; fines can reach 10 million euros and the legislation holds management personally liable. Find out who is covered, what you need to do and by when.

Request a NIS2 assessment
DataRoad
Portuguese Cybersecurity Legal Framework

NIS2 in Portugal: is your company covered?

Decree-Law No. 125/2025 has been in force since 4 May 2026, and the CNCS MyCiber platform was launched on 23 June. Entities already trading have 60 working days to identify and register themselves — the deadline is in mid-September 2026. Failure to register is an offence in its own right.

It is your responsibility to register. The CNCS does not classify anyone on its own initiative: the responsibility for self-assessment lies with the organisation. If you haven’t looked into this yet, please do so this week.

What you need to do, and by when

  • Already in forceCybersecurity Legal FrameworkDecree-Law No. 125/2025 of 4 December came into force on 4 May 2026. Regulation No. 756/2026 of 22 June sets out how it works in practice.
  • ~15 September 2026Self-identification and registration on MyCiber60 working days from 23 June, the date on which the CNCS platform became available. Entities that commenced trading at a later date have 30 working days. Failure to meet this deadline is, in itself, an offence.
  • 20 days after classificationCybersecurity officer and point of contactOnce the CNCS has confirmed your organisation’s classification, you must specify who is responsible for cybersecurity and appoint a permanent point of contact.
  • 31 January 2027Asset inventoryOr six months after the final classification notice, whichever comes first.
  • June 2028Minimum measures and annual reportYou have two years to implement the security measures for your assigned level and to submit the first report.

Fines reach 10 million euros or 2% of global turnover for essential entities, and 7 million or 1.4% for important entities. The framework also holds management bodies directly accountable.

What DataRoad does — and what it does not do

We are not lawyers and we do not carry out registration on your behalf: the self-assessment and the MyCiber submission are carried out by the organisation itself. What we do is everything that comes afterwards, which is where the real work lies.

  • Asset inventoryA comprehensive survey of servers, workstations, network equipment, cloud services and access rights — the document required by the framework by January 2027, which almost nobody has prepared.
  • Minimum requirements for your levelImplementation and documented evidence: access control, encryption, network segmentation, firewalls, endpoint protection, tested backups and patch management.
  • Detection and logging24/7 monitoring with retained logs. Without it, there is no way to meet the 24-hour notification requirement, because you would not even know that an incident had occurred.
  • Incident responseA written procedure, named individuals and a rehearsal. When this happens, the 24-hour clock is already ticking.
  • Continuity and recoveryBackups that have been tested and defined recovery times — not a promise that copies exist somewhere.
  • Training for staff and managementThe framework holds management bodies accountable. Short sessions and phishing simulations, with a record of who took part.
A NIS2 assessment in two weeks’ time.We assess what you have, compare it against the criteria for your assigned level and provide you with a written report setting out what is missing, what is urgent and what it will cost. It is yours to keep — you can use it with us or with anyone else.Request a NIS2 assessment

Frequently asked questions about NIS2

Is my company covered by NIS2?

As a rule, medium-sized and large organisations in the sectors listed in the framework fall within the scope — energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration, postal services, waste, chemicals, food, manufacturing and research, amongst others. There are cases where size is irrelevant and the organisation falls within the scope regardless. The official determination is made through self-assessment on the MyCiber platform, and the responsibility for that assessment lies with the organisation itself — not with the CNCS.

What if my company is not covered?

You are still affected, via the supply chain. Entities within the scope of the regulation are required to manage the risk posed by their suppliers, which involves security questionnaires, contractual requirements and, increasingly, documented evidence. If you sell to hospitals, banks, the energy sector, public administration or industry, NIS2 will affect you through your customers.

What are the fines?

For essential entities, up to 10 million euros or 2% of global annual turnover, whichever is higher. For important entities, up to 7 million euros or 1.4%. In addition, the framework holds management bodies directly accountable.

How long do I have to report an incident?

An early warning within 24 hours, a notification with an assessment within 72 hours and a final report within 30 days. In practice, this means you need detection and logging — without monitoring, there is no way to meet the 24-hour deadline, because you would never notice the incident in the first place.

What technical measures are required?

The framework defines three levels — basic, substantial and high — with 39, 75 and 91 measures, assigned according to the organisation’s risk profile. The methodology is based on the Portuguese National Cybersecurity Reference Framework, which is aligned with NIST CSF 2.0.

Does DataRoad handle the registration for us?

Registration and self-assessment are carried out by the organisation itself, and nobody can do them on your behalf — we guide you and prepare the information, but it is up to you to submit it. What we do manage from start to finish is the technical side: asset inventory, security measures, monitoring, logging and the ability to respond to an incident within the specified timeframes.

This page is for information purposes only and does not constitute legal advice. How your entity is classified is determined by the self-assessment on the CNCS MyCiber platform.

Latest news

DataRoad's latest news and articles.

DataRoad — IT services for businesses
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.