Cybersecurity 2026

PORTUGAL Trends and Developments Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados

responsibility for cybersecurity – or a function inde - pendent from management, reporting directly to it, provided that they report organically to them. It should be noted, however, that the allocation of specific tasks to a specific person responsible for cybersecurity does not exempt the other management bodies from their responsibilities under the Directive and the respective transposition law. In this context, the responsibility attributable to the heads of management bodies should not be over - looked. This is because both the Directive and the national transposition law provide for the possibility of imposing fines of considerable amounts. Specifi - cally, for essential entities, among other penalties, fines of up to EUR10 million or 2% of annual global turnover are envisaged; for members of management bodies, individual and direct financial penalties of up to EUR250,000 are also envisaged. Article 3 of Cybersecurity Legal Framework deter - mines its applicability to entities that, regardless of their size, are on a case-by-case identification as criti - cal (within the meaning of Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities, and Decree-Law No 22/2025 of March 19th, which transposes it into national law) by the National Civil Emergency Planning Council (by 17 July 2026, the deadline for this identification). The National Civil Emergency Planning Council is competent to approve the criteria and methodology applicable to the identi - fication of critical entities and their respective critical infrastructure. The supervision and enforcement of the National Cybersecurity Framework – carried out through on- site inspections, targeted security audits, security checks and requests for information, among others – is the responsibility of the CNCS or the national sectoral cybersecurity authorities, which may also take the necessary measures to ensure such compli - ance, guided always by the principles of pursuit of the public interest, legality, efficiency, effectiveness and proportionality, and whenever possible minimising its impact on the activities of the supervised entities. Essential and important entities are subject to different supervisory regimes: essential entities are subject to a

more comprehensive ex ante and ex post supervisory regime, while important entities are subject to a more simplified ex post supervisory regime. Under this new Cybersecurity Legal Framework, essential and important entities relate to: • the management of cybersecurity risks; • approving and supervising the implementation of cybersecurity risk-management measures; • ensuring compliance with supervision and enforce - ment measures; • ensuring that cybersecurity training is provided on a regular basis; • ensuring the security of networks and information systems through the implementation of a cyberse - curity risk-management system; • preparing annual reports; • taking the technical, operational and organisational measures that are appropriate to manage the risks to the security of the networks and informa - tion systems they use in their operations, and to prevent or minimise the impact of incidents on the recipients of their services and other services; and • adopting specific cybersecurity measures, which include incident handling and reporting, business continuity (such as back-up management and dis - aster recovery) and crisis management; and • supply chain security, including security aspects relating to the relationships between each entity and its suppliers or direct service providers. It is important to note that the responsibility and pow - ers necessary to fulfil these obligations cannot be del - egated, except to another member of the manage - ment, direction and administration bodies. Breach of the obligations and duties described above may result in the application of the following penalties. For very serious infractions: • if offender is an essential entity, the fine shall range from EUR2,000 to EUR10 million or 2% of the total worldwide annual turnover in the preceding finan - cial year, whichever is higher;

277 CHAMBERS.COM

Powered by