PORTUGAL Law and Practice Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados
Mechanism to support member states in preparing for, responding to, mitigating the impact of and initiat - ing recovery from significant cybersecurity incidents and large-scale cybersecurity incidents, and to sup - port other users. Finally, a European mechanism for analysing cybersecurity incidents is also being estab - lished. (Extra)territorial reach The Regulation is directed at member states, EU bodies and entities participating in EU cybersecurity mechanisms, having only a reflexive application to legal entities not established in the EU. Law No 16/2022 of August 16th Transposing the European Electronic Communications Code (the “ECS Portuguese Law”) The ECS Portuguese Law is implemented by Regu - lation No 303/2019 of April 1st on the security and integrity of electronic communications networks and services. Subject matter The ECS Portuguese Law provides that entities offer - ing public electronic communications networks or publicly available electronic communications services must take proportionate technical and organisational measures to adequately manage risks to the security of networks and services. Scope Regulation No 303/2019 applies to enterprises that offer public communications networks or publicly available electronic communications services, as defined in the ECS Portuguese Law. (Extra)territorial reach The criteria for the registration as an electronic com - munication services provider in Portugal relates to the offer and/or operation of electronic communication services or networks in Portugal, regardless of wheth - er the provider has an establishment in Portugal. 1.3 Cybersecurity Regulators The transposition of the NIS2 Directive has strength - ened the role of the CNCS as the national cyberse - curity authority. Beyond this mandate, the CNCS also performs the following functions:
• it operates within the framework of the National Security Office, and its mission is to ensure the safe and free use of cyberspace in Portugal; • it is responsible for developing national capacity to prevent and detect cybersecurity incidents; • it is responsible for ensuring the security of govern - ment information and communication systems and critical national infrastructures; • it is the national single point of contact for inter - national co-ordination, and plays a central role in liaising with other national actors in the field of cybersecurity; • it assumes the role of the National Cybersecurity Certification Authority; and • it is part of the national Cybersecurity Incident Response Team. From a regulatory standpoint, the CNCS has powers to (among others) adopt regulations and issue guide - lines, recommendations and technical instructions relating to cybersecurity, including the prerogative to physically access the premises of in-scope entities. In this regard, it should be noted that the Cybersecu - rity Incident Response Team, “CERT.PT”, is integrat - ed into the CNCS and has technical and operational autonomy. In addition, the Portuguese Law transposing the NIS2 Directive created a complex institutional framework, including the creation of the following authorities. • National sectoral cybersecurity authorities: (a) the National Security Office (GNS), with regard to trust services in electronic transactions in the internal market; and (b) the National Communications Authority (ANA - COM), with regard to electronic communica - tions and the postal service. • Special national cybersecurity authorities on digital operational resilience in the financial sector: (a) the Insurance and Pensions Authority (ASF); (b) the Portuguese Securities Market Commission (CMVM); and (c) the Bank of Portugal. It is important to highlight that the transposition of the NIS2 Directive into Portuguese law grants the
261 CHAMBERS.COM
Powered by FlippingBook