Cybersecurity 2026

PORTUGAL Law and Practice Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados

With respect to critical entities and critical infrastruc - ture designated under Decree-Law No 22/2025, there is a requirement to carry out a comprehensive risk evaluation within nine months following notification of designation as a critical entity, as well as the develop - ment of the corresponding resilience plan. 2.3 Incident Response and Notification Obligations Pursuant to the new Cybersecurity Legal Framework, essential and important entities must notify the com - petent cybersecurity authority of any significant inci - dent via the CNCS electronic platform. Accordingly, the relevant Decree-Law stipulates that the classification of an incident as significantly impact - ful shall be guided by the parameters outlined below: • number of users affected by the service disruption; • total number of users of the disrupted service; • duration of the incident; • level of severity of the disruption to the functioning of the service; and • extent of the impact on economic and social activi - ties. Notification For each incident subject to mandatory notification, the following must be submitted to the competent cybersecurity authority by in-scope entities. Initial notification – within 24 hours (except when the incident is resolved within two hours of its detection, in which case only notification of the end of the significant impact is required) This notification must contain at least the following information. • Name, telephone number and email address of a representative of the entity, when different from the permanent point of contact, for the purpose of possible contact by the competent cybersecurity authority. • Date and time of the start – or, if this cannot be determined, of the detection – of the incident. • Brief description of the incident, including an indi - cation of the category of the cause and the effects produced.

• Possible estimate of the impact, considering: (a) the number of users affected by the service disruption; (b) duration of the incident; (c) geographical distribution, with regard to the area affected by the incident, including an indi - cation of the cross-border impact; and (d) other information that the entity considers relevant. • Where necessary, an update within 72 hours of the verification of the significant incident. The competent cybersecurity authority should respond to the notifying entity without undue delay and, if possible, within 24 hours of receiving the initial notification. In situations of serious and proven risk of impact from the notified incident, the competent cybersecurity authority may also impose, as an imme - diate enforcement measure, the interruption of service provision to the entity concerned, or the cessation of conduct that infringes the Cybersecurity Legal Frame - work, if the entity does not do so voluntarily. Notification of the end of the significant impact – within 24 hours after the end of the significant impact This notification must contain at least the following information. • Update of the information provided in the initial notification, if any. • Description of the measures taken to resolve the incident. • Description of the impact situation at the time of the loss of significant impact, namely: (a) number of users affected by the service disrup - tion; (b) duration of the incident; (c) geographical distribution of the area affected by the incident, including an indication of any cross-border impact; and (d) estimated time for full recovery of services. The final report – within 30 working days of the date of notification of the end of the significant impact of the incident This notification should include at least the following information.

264 CHAMBERS.COM

Powered by