PORTUGAL Trends and Developments Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados
contractual operations under national and European law. Leonor also provides support on advertising documentation and risk analysis. Additionally, she brings expertise in space and satellite law, serving as Delegate to the Space Generation Advisory Council, further broadening her advisory capabilities in innovative and emerging legal sectors.
Abreu Advogados Av. Infante Dom Henrique 26 1149-096, Lisbon Portugal
Tel: +351 217 231 800 Fax: +351 217 231 899 Email: lisboa@abreuadvogados.com Web: abreuadvogados.com/en/
Navigating Compliance Challenges in 2026 Introduction In Portugal, the production of legislation towards the end of 2025 – which included statutes address - ing cybersecurity requirements – contributed to an increasingly complex regulatory landscape. Focus - ing on safety, resilience and robustness of ICT sys - tems and on the integrity and availability of the data feeding into them, Law No 73/2025 of December 23rd and Decree-Law No 125/2025 of December 4th (the former being a sectoral instrument for the finan - cial sector, and the latter a horizontal framework for cybersecurity in the EU) further built on the applicable legal framework, in addition to providing for personal liability of managers and other individuals with seats at administration boards of the entities subject to each regime. This article provides ICT services providers and receivers with an overview of the scope, content and responsibility schemes in Law No 73/2025 and Decree-Law No 125/2025. The article concludes with an introduction to compliance methodologies to implement these statutes.
Law No 73/2025 Law No 73/2025, applicable from 28 December 2025, executes in the national order Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 (the “Digital Opera - tional Resilience Act” – DORA) concerning the opera - tional resilience of the financial sector. It additionally transposes Directive (EU) 2022/2556 of the European Parliament and of the Council of 14 December 2022, which amends Directives 2009/65/EC, 2009/138/EC, 2011/61/EU and 2014/65/EU (containing additional requirements relating to ICT risk). Going beyond what was required under the strict terms of DORA, which is directed at financial insti - tutions, Law No 73/2025 extends its obligations to insurance and reinsurance companies and pension funds management companies – although it excluded savings banks, with the exception of those savings banks that are incorporated as public limited com - panies. As competent supervisory authorities under DORA, Law No 73/2025 appoints the Bank of Portugal ( Banco de Portugal or BdP), the pension funds man - agement companies’ supervisory authority ( Autori- dade de Supervisão de Seguros e Fundos de Pensões or ASF), and the Securities Commission ( Comissão do
274 CHAMBERS.COM
Powered by FlippingBook