Cybersecurity 2026

PORTUGAL Trends and Developments Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados

• if the offender is a natural person within the essen - tial entity, the fine shall range from EUR350 to EUR200,000; • if the offender is an important entity, the fine shall range from EUR1,250 to EUR700,000 or a maxi - mum amount of no less than 1.4% of total world - wide annual turnover in the preceding financial year, whichever is higher; and • if the offender is a natural person within the impor - tant entity, the fine shall range from EUR350 to EUR200,000. For serious infractions: • if the offender is an essential entity, the fine shall range from EUR1,250 to EUR5 million or 1% of the total worldwide annual turnover in the preceding financial year, whichever is higher; • if the offender is a natural person within the essen - tial entity, the fine shall range from EUR250 to EUR125,000); • if the offender is an important entity, the fine shall range from EUR875 to EUR3.5 million or a maxi - mum amount of no less than 0.7% of the total worldwide annual turnover in the preceding finan - cial year, whichever is higher; and • if the offender is a natural person within the impor - tant entity, the fine shall range from EUR250 to EUR125,000. For minor infractions: • if the offender is a legal person (an essential or an important entity), the fine shall range from EUR875 to EUR45,000; and • if the offender is a natural person within the essen - tial or important entity, the fine shall range from EUR250 to EUR3,750. In addition to the economic penalties described above, the CNCS may issue binding orders or instructions to take the necessary measures to prevent, impede or correct an incident, setting deadlines for their imple - mentation and reporting, and even appoint a super - visor with appropriately defined duties, for a limited period, to oversee compliance with the provisions of the regime relating to cybersecurity measures and incident notifications by the entity concerned.

In the event of non-compliance by essential entities with any of the above measures within the time limit set by the competent cybersecurity authority, the lat - ter may, to the extent strictly necessary: • suspend a certification, authorisation or licence relating to part or all of the relevant services pro - vided or activities carried out by the entity, or order a certification body to suspend it; or • request the competent body to suspend the authorisation or licence relating to part or all of the relevant services provided or activities carried out by the entity. Such suspensions and prohibitions shall remain in force until compliance is restored. Conclusion Based on the above, Law No 73/2025 and Decree- Law No 125/2025 share common actionable takea - ways for 2026: • self-identification and registration – legal persons should determine their status under the new stat- utes, compile required registration data and, after submission, update the registry as required; • governance measures and maintenance of evi - dence/documentation of compliance – legal persons should appoint a cybersecurity seat, draft internal policies and create a centralised registry of evidence of compliance; • design and implementation of incident-reporting processes – legal persons should map incident thresholds that trigger reporting, build a report - ing workflow and draft templates, and test their incident-reporting processes; and • supplier risk assessment and managed service providers – legal persons should create a risk- based supplier categorisation model, establish exit plans and perform due diligence over suppliers before onboarding. Given the substantial penalties, a robust compliance methodology (understood as adherence to all relevant laws, regulations, industry standards, and own inter - nal policies) is essential. Compliance, however, can only be achieved following a case-by-case assess - ment and the preparation of implementation projects

278 CHAMBERS.COM

Powered by