PORTUGAL Law and Practice Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados
2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation The NIS2 Directive has substantially reshaped the EU’s cybersecurity regulatory landscape, prompting the adoption of a new Cybersecurity Legal Framework in Portugal (Decree-Law No 125/2025 of December 4th). This framework significantly broadens both the range of critical sectors and the categories of entities subject to its obligations. Its scope of application refers to an exhaustive list of entities (Annexes I and II) that operate in critical sec - tors (eg, digital infrastructures and providers of digital services), and which are deemed medium-sized pur - suant to Recommendation (2003/361/EC) or which exceed those thresholds, and which provide their services or carry out their activities in the Union and have an establishment in national territory. In addition, the Cybersecurity Legal Framework also applies to: • qualified trust service providers and top-level domain name registries as well as DNS service providers; • providers of public electronic communications networks or of publicly available electronic com - munications services; • public administration entities, which may be classi - fied as Group A or Group B public relevant entities; • higher education institutions; • entities qualified by the competent authority as having a relevant role for society at the national level; and • entities identified by national authorities as critical pursuant to Decree-Law No 22/2025. As there are four potential qualifications of in-scope entities, the Portuguese Cybersecurity Legal Frame - work establishes a hierarchy to determine the appli - cable category. Where an entity simultaneously meets the criteria for more than one category, the most strin - gent classification prevails, following the order set out below:
competent authorities new supervisory and enforce - ment powers. With respect to essential entities, these authorities may, as a measure of last resort, request that the competent bodies or courts temporarily pro - hibit any natural person with executive-level manage - ment responsibilities or acting as a legal representa - tive from exercising management functions within that entity. In addition, beyond its role as a sectoral cybersecurity authority under the NIS2 framework, ANACOM also acts as the competent authority for enforcing Regula - tion No 303/2019. Similarly, the Portuguese legislation transposing the DORA framework assigns supervisory responsibilities and regulatory and sanctioning powers to the ASF, the CMVM and the Bank of Portugal. Under Law No 73/2025, these authorities are granted broad regula - tory powers, including the ability to define specific operational channels and procedures for reporting severe ICT incidents as well as for the voluntary noti - fication of significant cyber-threats. In addition, the competent authorities hold significant supervisory and sanctioning powers, enabling them to oversee compli - ance and enforce the obligations set out in the DORA framework. Regarding critical entities and infrastructures, Decree- Law No 22/2025 indicates the National Civil Emergen - cy Planning Council and the Secretary-General of the Internal Security System as the competent authorities. The Decree-Law also provides that sectoral entities (such as the Portuguese Space Agency) are entrusted with specific responsibilities, particularly regarding the designation of national and European critical entities and infrastructures. Finally, with respect to data breach notifications, the CNPD ( Comissão Nacional de Proteção de Dados ) must also be identified as a competent authority in matters relating to cybersecurity.
262 CHAMBERS.COM
Powered by FlippingBook