Cybersecurity 2026

PORTUGAL Law and Practice Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados

regulatory environment of the destination country, ensuring enforceability of audit and access rights, and confirming that data-transfer arrangements do not compromise continuity of critical or important functions. 3.6 Threat-Led Penetration Testing Financial entities subject to DORA are required to conduct threat-led penetration testing (TLPT) at least once every three years. These advanced tests must be carried out on live production systems and must encompass several (or, where appropriate, all) critical or important functions of the entity. Once the exercise is completed, and after the testing reports and remediation measures have been agreed, the financial entity (together with any external testers involved) must submit to the competent authority a summary of key findings, the corresponding reme - diation plans, and evidence demonstrating that the TLPT was performed in full compliance with DORA’s requirements. Further details are provided in Commission Delegated Regulation (EU) 2025/1190, which sets out the regu - latory technical standards governing TLPT. These standards define: • the criteria for identifying which financial entities must perform TLPT; • the conditions for relying on internal testers; • the required scope and methodology for each phase of the testing process; • the stages for reporting, closure and remediation; and • the framework for supervisory co-operation and mutual recognition.

Regarding the CRA’s scope of application, note that a product with digital elements amounts to a software or hardware product and its remote data-processing solutions, including software or hardware compo - nents being placed on the market separately. In other words, this Regulation covers products such as baby monitors, smart washing machines, and products that include artificial intelligence (AI) systems. Conversely, cloud solutions and digital services such as Software as a Service (SaaS), Platform as a Service (PaaS) and Infrastructure as a Service (IaaS) are, in principle, outside the scope of the CRA. Instead, these services may fall under the Portuguese NIS2 Law, in line with the categories listed in Annex II. Additionally, due to its limited material scope, other legislation (such as Regulation (EU) 2023/988 on general product safety requirements) applies to prod - ucts with digital elements that pose safety risks not covered by the CRA. This Regulation also does not affect the health and safety requirements established in Regulation (EU) 2023/1230, when applicable. The Regulation also sets out different obligations for the different actors in the supply chain (ie, manu - facturers, importers and distributors) to ensure that the essential requirements for cybersecurity are met from the manufacturing stage onwards. This aligns with the primary aim of the CRA, which is to establish essential cybersecurity requirements for the design, development and manufacture of products with digital elements, as well as their monitoring once they are available on the market. 4.2 Key Obligations Under Legislation The CRA provides a robust level of cybersecurity for products with digital elements to be placed on the internal market. At the outset, it is essential to clarify that the Regulation identifies three categories of prod - ucts with digital elements: • products with digital elements not classified as important or critical; • important products with digital elements, which possess the core functionality of a product cate - gory outlined in Annex III, further subclassified into Class I and Class II; and

4. Cyber-Resilience 4.1 Cyber-Resilience Legislation

The CRA is directly applicable in Portugal and shall begin its phased application in September 2026. Despite the approaching application date, Portugal has not yet adopted a national implementation law designating the market surveillance authorities or con - solidating the provisions on penalties.

268 CHAMBERS.COM

Powered by