Cybersecurity 2026

PORTUGAL Law and Practice Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados

Assessment of the cybersecurity risks Manufacturers of products with digital elements must carry out and document an assessment of the cyber - security risks of the product, and demonstrate that it complies with the essential cybersecurity require - ments listed in Annex I. This assessment should be integrated into the technical documentation of the product. Reporting obligations The Regulation mandates that manufacturers of prod - ucts with digital elements must report to both the des - ignated Computer Security Incident Response Team (CSIRT) and ENISA, via a single platform to be estab - lished by the latter authority. The reporting comprises a notification on: • actively exploited vulnerabilities in their products; and • serious incidents impacting the security of these products. Vulnerability handling Manufacturers must ensure that, from the moment a product with digital elements is placed on the market and throughout its entire support period, any vulner - abilities in that product are properly managed. This handling must comply with the essential cybersecurity requirements established in Part II of Annex I. Upon identifying a vulnerability in a component, man - ufacturers must notify such vulnerability to the person or entity manufacturing or maintaining the component. Then, they are required to address and remediate the vulnerability in accordance with the vulnerability-han - dling requirements set out in Part II of Annex I. In this regard, special attention should be given to Article 14 of the CRA, which delineates the reporting obligations of manufacturers whenever they become aware of an actively exploited vulnerability. Conversely, importers and distributors are not subject to such stringent obligations. Upon becoming aware of a vulnerability, they should inform the manufacturer without undue delay about that vulnerability. Where the product presents a significant cybersecurity risk, they should immediately inform the competent market surveillance authorities.

• critical products with digital elements, which pos - sess the core functionality of a product category outlined in Annex IV. Key Obligations Although the level of compliance varies, products with digital elements that are subject to this Regula - tion must comply with the following key obligations. Presentation of the CE marking It is mandatory for products with digital elements covered by this Regulation to bear the CE marking as the visible proof for users of conformity with the essential cybersecurity requirements set out in Annex I. The application of the CE marking on the products is anticipated by a conformity assessment procedure, harmonised by the Regulation. Conformity assessment procedure The conformity assessment of products with digital elements, which are not listed as important or criti - cal products with digital elements in this Regulation, can be carried out by the manufacturer under its own responsibility, according to the procedure laid down in Decision No 768/2008/EC. By contrast, due to the high impact of products with digital elements classified as “important”, they are subject to different procedures. • For important Class I products, the product may be assessed by the manufacturer on its own respon - sibility, provided that it applies harmonised stand - ards or common specifications, or complies with a European cybersecurity certification. If the manu - facturer chooses not to apply the above security measures, it must undergo a third-party conformity assessment. • For important Class II products, the conformity assessment must always involve a third party. For critical products with digital elements, and in accordance with their importance for society, it is mandatory that they have a certification under the European Cybersecurity Certification Scheme with a minimum level of “substantial”. If this condition is not met, critical products are subject to the conformity assessment defined for Class II important products.

269 CHAMBERS.COM

Powered by