Cybersecurity 2026

PORTUGAL Law and Practice Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados

technology (ICT) services. In this context, it acts as a trusted intermediary, facilitating interaction between the reporting individual/entity and the manufacturer or supplier of potentially vulnerable ICT products or the ICT service provider, at the request of either party. Finally, within the public policy sphere, the Cyberse - curity Legal Framework reinforces three key initiatives: • the National Cyberspace Security Strategy, which sets national priorities and strategic goals for cybersecurity; • the National Plan for Responding to Large-Scale Cybersecurity Crises and Incidents, which governs and strengthens the management of major inci - dents; and • the National Reference Framework for Cybersecu - rity, designed to consolidate and promote norms, standards and best practices for effective cyberse - curity management. 3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation Please refer to 1.2 Cybersecurity Laws . 3.2 ICT Service Provider Contractual Requirements ICT services are defined as “digital and data services provided through ICT systems to one or more inter - nal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via soft - ware or firmware updates by the hardware provider, excluding traditional analogue telephone services” (Article 3 (21) of DORA). As such, an ICT service pro - vider is defined as “an undertaking providing ICT ser - vices” (Article 3 (19) of DORA). In turn, critical ICT third-party service providers shall be designated in line with Article 31 of the Regulation, which considers a series of criteria laid out in said article such as systemic impact on stability, continu - ity or quality of the service, or the systemic character

or importance of the financial entities that rely on the relevant ICT third-party service provider. When engaging ICT service providers, in-scope enti - ties are required to have due regard to the manda - tory contractual requirements laid down in Articles 28 and 30. Financial institutions, in particular, need to determine whether subcontracting ICT services that underpin critical or important functions is allowed and under which conditions. Any negotiation involv - ing subcontractors should reflect the requirements of Commission Delegated Regulation (EU) 2025/532, which outlines the factors that financial entities must evaluate when outsourcing ICT services that support such functions. They should also consider the Euro - pean Central Bank’s (ECB) guidance on cloud out - sourcing and the upcoming supervisory guidelines issued under DORA. For contracts involving ICT providers that support critical or important functions, financial entities must ensure that the agreement grants them full rights to monitor the provider’s performance. This includes unrestricted rights of access, inspection and audit by the financial entity or an appointed third party, and by the competent authority. Contracts must also include clear exit strategies and provider assistance obliga - tions, as required under Article 30 of DORA. 3.3 Key Operational Resilience Obligations Financial entities subject to DORA must establish an ICT governance and risk-management framework that includes documented strategies, policies, pro - cedures and technical measures to ensure the pro - tection, monitoring and resilience of all ICT systems and information assets. These measures must be kept current and continuously supervised. Entities must be able to promptly detect anomalous activities, ICT performance issues and incidents, and identify potential single points of failure. They must also maintain effective back-up, restoration and recovery arrangements to minimise downtime, dis - ruption and data loss. In addition, Article 17 requires financial entities to implement an ICT-related incident management pro - cess. DORA sets out the criteria for classifying ICT

266 CHAMBERS.COM

Powered by