Cybersecurity 2026

PORTUGAL Law and Practice Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados

(Extra)territorial reach Decree-Law No 22/2025 also applies to critical enti - ties of particular European relevance, namely those that have been designated as critical entities and that provide identical or comparable essential services in six or more member states. Regulation (EU) 2024/2847 of 23 October 2024 (the “Cyber-Resilience Act” – CRA) and Commission Implementing Regulation (EU) 2025/2392 of 28 The CRA aims to establish the framework conditions necessary for the development of secure products with digital components, ensuring that hardware and software are placed on the market with reduced vul - nerabilities and that manufacturers address security throughout the entire life cycle of their products. Scope The CRA covers products with digital components that are placed on the EU market and whose intend - ed purpose or reasonably foreseeable use involves a direct or indirect logical or physical data connec - tion to a device or network. The Regulation also limits its scope of application negatively, providing for the exclusion of, inter alia, medical devices with digital elements. (Extra)territorial reach As this Regulation applies to all in-scope products with digital elements, the requirements laid down thereof apply to all economic operators involved in the manufacturing, importation, distribution and making available of products with digital elements on the mar - ket, regardless of whether they are based in the EU. Regulation (EU) 2025/38 of 19 December 2024 (the “Cyber Solidarity Act”) Subject matter and scope The Cyber Solidarity Act aims to strengthen the EU’s solidarity and capabilities in detecting, preparing for and responding to cyber-threats and cybersecurity incidents. To achieve these objectives, the Regulation establishes the European Cybersecurity Alert System to enhance capabilities for detecting, preventing and managing data related to cyber-threats. The Regu - lation also establishes a Cybersecurity Emergency November 2025 Subject matter

electronic communications services accessible to the public, that make them available on national territory. Furthermore, the Decree-Law is applicable to in- scope domain name system (DNS) service providers, top-level domain name registries, domain name regis - trars, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security ser - vice providers, and providers of online marketplaces, online search engines or social media service plat - forms that have their main establishment in Portugal or, alternatively, that have a representative established in Portugal. Concerning extraterritoriality, the CNCS may, after consulting the High Council for Cyberspace Security, adopt corrective or restrictive enforcement measures directed at a service provider without an establish - ment or representation in the national territory that does not provide adequate cybersecurity measures. Directive (EU) 2022/2557 of 14 December 2022 (Resilience of Critical Entities – CER) This was transposed by Decree-Law No 22/2025 of March 19th. Subject matter Decree-Law No 22/2025 aims to establish a robust framework for the resilience of critical entities in Por - tugal, by defining procedures for identifying, designat - ing and strengthening the resilience of national critical entities and those of particular European relevance. Scope The enterprise must be designated as critical by the National Civil Emergency Planning Council. The pro - cess for identification of critical entities must consider several criteria, inter alia: • the results of the national risk evaluation; • the results of the national strategy for the resilience of critical entities; and • the provision of services that are considered essential.

260 CHAMBERS.COM

Powered by