Cybersecurity 2026

PORTUGAL Law and Practice Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados

• essential entities; • important entities; • Group A public relevant entities; and • Group B public relevant entities.

Moreover, at least the following points should be included in the measures: • incident handling; • business continuity, such as back-up management and disaster recovery, and crisis management; • supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers; • security in network and information systems acqui - sition, development and maintenance, including vulnerability handling and disclosure; • policies and procedures to assess the effective - ness of cybersecurity risk-management measures; • basic cyber hygiene practices and cybersecurity training, including the heads of senior management bodies and employees; • policies and procedures regarding the use of cryp - tography and, where appropriate, encryption; • human resources security, access control policies and asset management; and • the use of multi-factor authentication or continu - ous authentication solutions, secured voice, video and text communications, and secured emergency communication systems within the entity, where appropriate. Additionally, the CNCS is mandated to approve sec - tor-specific regulations that define the minimum and specific cybersecurity measures and conformity levels to be adopted by essential and important entities. On another note, entities are required to prepare an annual report under the supervision of the des - ignated cybersecurity officer. This officer has legally established functions and must be a member of the management, executive or administrative bodies, or must otherwise report to them directly and formal - ly. By contrast, the permanent point(s) of contact to be appointed by important or essential entities are responsible for ensuring the operational and technical flow of information with the competent cybersecurity authority, including sharing information when specific emergency, security or resilience plans are activated, and receiving any guidelines, recommendations, tech - nical instructions or orders issued by that authority.

Furthermore, Decree-Law No 125/2025 is comple - mented by Decree-Law No 22/2025 of March 19th, which transposes into Portuguese law the CER Direc - tive. To be considered a critical entity, the enterprise must be designated as such by the National Civil Emergency Planning Council (by 17 July 2026, the deadline for this identification), which is competent to approve the criteria and methodology applicable to the identification of critical entities and their respective critical infrastructure. Although the CER framework applies without preju - dice to the NIS2 regime, Decree-Law No 22/2025 expressly excludes certain categories of critical enti - ties, namely those operating in the banking sector, infrastructures of the financial, insurance or pension fund markets, and digital infrastructures, from the resilience and supervisory obligations set out therein. 2.2 Critical Infrastructure Cybersecurity Requirements Essential and important entities are required to adopt appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information sys - tems based on a systemic approach, which shall be developed considering the protection of all assets that ensure the continuity of the network and services that support the essential services. As such, the adopted measures must safeguard an appropriate level of security considering the risks involved, taking into account the latest technical developments and, where applicable, relevant Euro - pean and international standards (eg, standards included in the ISO/IEC 27000 series), as well as the costs of implementation and the financial viability thereof. The Portuguese Cybersecurity Legal Frame - work also accounts for the entity’s size and the likeli - hood and severity of incidents, including their social and economic impact, according to technical criteria to be defined by the CNCS.

263 CHAMBERS.COM

Powered by