Law / Portugal

Regime Jurídico da Cibersegurança, Significant-Incident Reporting Obligations

Decreto-Lei n.º 125/2025, de 4 de dezembro, Artigos 40.º a 44.º

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 5 months, effective 3 April 2026.

A vulnerability and incident reporting rule binding public and private bodies.

As of 15 September 2026.

What it requires

  • This binds an essential, important or relevant public entity on the same scope as this jurisdiction's companion risk-management row: Annex II's digital-services sector names an online marketplace provider, an online search engine provider and a social-networking-services-platform provider, and Annex I's digital-infrastructure sector separately names a cloud-computing-service provider, a data-centre-service provider, a content-delivery-network provider, a trust-service provider and a top-level-domain registry; the wider sector classes are not raised here for the same reason.
  • Notify the competent cybersecurity authority of any significant incident, weighing the number and share of users affected, the incident's duration, the severity of the service disruption and its economic and social impact.
  • Submit an initial notification without undue delay and within 24 hours of concluding that a significant incident exists or may exist, and, where necessary, update it within 72 hours with an initial assessment of the incident's severity and impact; if the incident resolves within two hours of detection, submit only the end-of-impact notification below.
  • Submit a notification that the incident's significant impact has ended, without undue delay and within 24 hours of that impact ending.
  • Submit a final report within 30 working days of your end-of-impact notification, describing the incident, its impact, the mitigating measures you took and any residual impact still present, and submit an interim report if the competent authority asks for one.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 61 makes non-compliance with the Article 40 to 44 notification duties a contraordenação muito grave (very serious administrative offence) punished by an administrative fine; no provision reviewed here makes the infringement itself a criminal offence.

Penalty structure

Article 61(2)(a) sets the fine for an essential entity's infringement of, among other provisions, Articles 40 to 44, at EUR 2,000 to EUR 10,000,000 or 2 percent of the entity's total worldwide annual turnover in the preceding financial year, whichever is higher, for a legal person (EUR 350 to EUR 200,000 for a natural person). Article 61(2)(b), the mirror provision for an important entity, sets the equivalent range at EUR 1,250 to EUR 7,000,000 or a minimum of 1.4 percent of that turnover, whichever is higher, for a legal person. Both mirror NIS2 Article 34(4) and (5).

Rule
Higher of
As of
15 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The Centro Nacional de Cibersegurança (CNCS), Portugal's national cybersecurity authority, receiving notifications through the electronic platform referenced in Article 8(7), or the sectoral national cybersecurity authority the Decree-Law designates for your sector under Article 15.

Settledness

As of
15 September 2026
Guidance link
https://www.cncs.gov.pt/pt/regime-juridico/
Guidance body
Centro Nacional de Cibersegurança (CNCS)
Open questions
Will the CNCS technical instruction on notification format, procedure and incident taxonomy that Article 41(4) contemplates, together with the European Commission's own implementing acts under NIS2 Article 23(11), narrow or restate the impact thresholds Article 40(3) currently leaves to the entity's own judgement?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 40 requires an essential, important or relevant public entity to notify the competent cybersecurity authority of any significant incident, weighed against the number of users affected, the incident's duration, the severity of the service disruption and its economic and social impact.

Article 41 sets three notification types per incident: an initial notification, a notification that the significant impact has ended, and a final report, with an entity whose incident resolves within two hours of detection required only to submit the end-of-impact notification. Article 42 requires the initial notification without undue delay and within 24 hours of concluding a significant incident exists or may exist.

Where necessary, Article 42 also requires an update within 72 hours of that determination, providing an initial assessment of the incident's severity and impact. Article 43 requires the end-of-significant-impact notification without undue delay and within 24 hours of the impact ending.

Article 44 requires the final report within 30 working days of the end-of-impact notification, describing the incident, its impact, the mitigating measures taken and the residual impact still present; an entity may also be asked for an interim report.

This clock differs from the calendar-day early-warning and one-calendar-month pattern used elsewhere in the corpus: Portugal's 30-day final-report deadline runs in working days from the end-of-impact notification rather than in calendar days from the initial notification. This Decree-Law transposes NIS2 Directive Article 23 and, by its own Article 9(b), repeals the Regime Jurídico da Segurança do Ciberespaço approved by Lei n.º 46/2018, de 13 de agosto, the predecessor NIS1 transposition.

When LexLint raises it

  • operates_social_platform

Read the law

Consolidated text
data.dre.pt, Decreto-Lei n.º 125/2025, de 4 de dezembro, ELI record, as published in Diário da República n.º 234/2025, Série I

Back to the example  ·  Lint your app