Checked on September 27, 2026
NIS2 in Portugal
How Portugal applies the NIS2 cybersecurity directive: the national law, who supervises, and how to register and report incidents.
- Transposition status
- In force
- National law
- Decree-Law 125/2025 (Cybersecurity Legal Framework) transposing NIS2 · Decreto-Lei n.º 125/2025, de 4 de dezembro · from April 3, 2026
- Competent authority
- National Cybersecurity Centre (CNCS) (Centro Nacional de Cibersegurança)
- National CSIRT
- CERT.PT (operated by CNCS)
- Registration
- Required · Portal
Self-identification on MyCiber (opened 23 Jun 2026 under CNCS Regulation 756/2026) within 60 days of platform availability; sources differ on calendar vs business days.
- Incident reporting
- To CNCS via MyCiber: initial notification within 24h, notification within 72h, final report within 30 days (Regulation 756/2026).
- National specifics
- Entities must designate a cybersecurity officer and a permanent 24/7 contact point (20 business days after qualification).
- CNCS Regulation 756/2026 sets the National Cybersecurity Reference Framework (QNRCS) with basic, substantial and high levels.
Where does your company stand?
The free assessment applies these national rules to your answers and scores every area of the law.
Sources
- www.cncs.gov.pt/pt/diretiva-nis-2/
- digital.gov.pt/pt/noticias/ciberseguranca-novas-obrigacoes-entram-em-vigor
- www.garrigues.com/pt/pt-PT/news/novo-regulamento-ciberseguranca-define-obrigacoes-e-ativa-plataforma-myciber
- www.vda.pt/en/publications/newsletters-and-flashes/nis-2-directive-transposed-in-portugal-decree-law-no-1252025-published/28172/
- www.ciberseguranca.pt/myciber-a-plataforma-de-registo-da-nis2-ja-esta-disponivel-conheca-os-prazos-que-ja-estao-a-contar/
National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.