Regime Jurídico da Cibersegurança, Cybersecurity Risk-Management Measures and Governance
Decreto-Lei n.º 125/2025, de 4 de dezembro, Artigos 25.º a 29.º
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 5 months, effective 3 April 2026.
A sector security regimes rule binding public and private bodies.
As of 15 September 2026.
What it requires
- This binds an essential or important entity of a type listed in Annex I or Annex II that exceeds the EU medium-enterprise thresholds of Commission Recommendation 2003/361/EC, or that Annex I or II names as essential regardless of size; Annex II's digital-services sector names an online marketplace provider, an online search engine provider and a social-networking-services-platform provider expressly, and Annex I's digital-infrastructure sector separately names a cloud-computing-service provider, a data-centre-service provider, a content-delivery-network provider, a trust-service provider and a top-level-domain registry, so a service in any of those eight lines is reached; the wider sector classes (energy, transport, banking, health, drinking water, public administration and the rest of the Annexes) are a designation and sector class no activity in this vocabulary expresses, and are not raised here on that account.
- Take appropriate technical, operational and organisational measures to manage the risks to the network and information systems you use in your operations, and to prevent or minimise the impact of an incident on the recipients of your services and on other services, at a level proportionate to your risk exposure, your size and the likelihood and severity of an incident.
- Cover at minimum: incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including your relationship with your direct suppliers and service providers; security in the acquisition, development and maintenance of your systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and cybersecurity training, including for your top management; cryptography and, where applicable, encryption policy; personnel security, access control and asset management; and multi-factor or continuous authentication, secure communications and secure emergency communication systems.
- Have your management, direction and administration body approve these measures, supervise their implementation, ensure compliance with supervision and enforcement obligations, and ensure regular cybersecurity training; know that a member of that body can be held personally liable, by act or omission, on a finding of intent or gross negligence, for an infringement of this Decree-Law, and that this responsibility cannot be delegated away.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 61 makes non-compliance with the Article 27 to 29 cybersecurity measures a contraordenação muito grave (very serious administrative offence) punished by an administrative fine; no provision reviewed here makes the infringement itself a criminal offence, though a management-body member found to have acted with intent or gross negligence under Article 25(2) may separately face civil liability under generally applicable law.
Penalty structure
Article 61(2)(a) sets the fine for an essential entity's infringement of, among other provisions, Articles 27 to 29, at EUR 2,000 to EUR 10,000,000 or 2 percent of the entity's total worldwide annual turnover in the preceding financial year, whichever is higher, for a legal person (EUR 350 to EUR 200,000 for a natural person). Article 61(2)(b), the mirror provision for an important entity, sets the equivalent range at EUR 1,250 to EUR 7,000,000 or a minimum of 1.4 percent of that turnover, whichever is higher, for a legal person. Both mirror NIS2 Article 34(4) and (5).
- Rule
- Higher of
- As of
- 15 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The Centro Nacional de Cibersegurança (CNCS), Portugal's national cybersecurity authority and single point of contact for EU and international cooperation, or the sectoral national cybersecurity authority the Decree-Law designates for your sector under Article 15, such as the Gabinete Nacional de Segurança (GNS) for trust services or the Autoridade Nacional de Comunicações (ANACOM) for electronic communications and postal services.
Settledness
- As of
- 15 September 2026
- Guidance link
- https://www.cncs.gov.pt/pt/regime-juridico/
- Guidance body
- Centro Nacional de Cibersegurança (CNCS)
- Open questions
- What further detail will the Article 27(5) CNCS regulation on minimum and sector-specific cybersecurity measures and compliance levels add once the CNCS approves it, since Article 27 itself sets only the general areas the measures must cover?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 26 requires an essential or important entity to take appropriate technical, operational and organisational measures to manage the risks to the network and information systems it uses in its operations, and to prevent or minimise an incident's impact on the recipients of its services and on other services, at a security level proportionate to the entity's risk exposure, size and the likelihood and severity of an incident, following a risk matrix the Centro Nacional de Cibersegurança (CNCS) defines and may update.
Article 27 lists the areas those measures must cover: incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security; security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure; policies to assess the effectiveness of the entity's risk-management measures; basic cyber-hygiene practices and staff training, including for members of top management bodies; cryptography and, where applicable, encryption policy; personnel security, access control and asset management; and multi-factor or continuous authentication, secure communications and secure emergency communication systems.
Article 25 requires the entity's management, direction and administration body to approve the Article 27 measures, supervise their application, ensure compliance with the supervision and enforcement measures of Chapter VI, and ensure regular cybersecurity training; a member of that body may be held liable, by act or omission, on a finding of intent (dolo) or gross negligence (culpa grave), for an infringement under this Decree-Law, and that responsibility may not be delegated except to another member of the same body.
This Decree-Law, Decreto-Lei n.º 125/2025, transposes NIS2 Directive Articles 20 and 21 and, by its own Article 9(b), repeals the Regime Jurídico da Segurança do Ciberespaço approved by Lei n.º 46/2018, de 13 de agosto, the predecessor NIS1 transposition.
When LexLint raises it
operates_social_platform
Read the law
Consolidated text
data.dre.pt, Decreto-Lei n.º 125/2025, de 4 de dezembro, ELI record, as published in Diário da República n.º 234/2025, Série I