DataRoad · IT Services and Consultancy![]()
NIS2 in Portugal
Who is covered?
There is a deadline for registration on MyCiber, which ends in mid-September 2026.
Decree-Law 125/2025 is now in force; fines can reach 10 million euros and the legislation holds management personally liable. Find out who is covered, what you need to do and by when.
Request a NIS2 assessment
NIS2 in Portugal: is your company covered?
Decree-Law No. 125/2025 has been in force since 4 May 2026, and the CNCS MyCiber platform was launched on 23 June. Entities already trading have 60 working days to identify and register themselves — the deadline is in mid-September 2026. Failure to register is an offence in its own right.
What you need to do, and by when
- Already in forceCybersecurity Legal FrameworkDecree-Law No. 125/2025 of 4 December came into force on 4 May 2026. Regulation No. 756/2026 of 22 June sets out how it works in practice.
- ~15 September 2026Self-identification and registration on MyCiber60 working days from 23 June, the date on which the CNCS platform became available. Entities that commenced trading at a later date have 30 working days. Failure to meet this deadline is, in itself, an offence.
- 20 days after classificationCybersecurity officer and point of contactOnce the CNCS has confirmed your organisation’s classification, you must specify who is responsible for cybersecurity and appoint a permanent point of contact.
- 31 January 2027Asset inventoryOr six months after the final classification notice, whichever comes first.
- June 2028Minimum measures and annual reportYou have two years to implement the security measures for your assigned level and to submit the first report.
Fines reach 10 million euros or 2% of global turnover for essential entities, and 7 million or 1.4% for important entities. The framework also holds management bodies directly accountable.
What DataRoad does — and what it does not do
We are not lawyers and we do not carry out registration on your behalf: the self-assessment and the MyCiber submission are carried out by the organisation itself. What we do is everything that comes afterwards, which is where the real work lies.
- Asset inventoryA comprehensive survey of servers, workstations, network equipment, cloud services and access rights — the document required by the framework by January 2027, which almost nobody has prepared.
- Minimum requirements for your levelImplementation and documented evidence: access control, encryption, network segmentation, firewalls, endpoint protection, tested backups and patch management.
- Detection and logging24/7 monitoring with retained logs. Without it, there is no way to meet the 24-hour notification requirement, because you would not even know that an incident had occurred.
- Incident responseA written procedure, named individuals and a rehearsal. When this happens, the 24-hour clock is already ticking.
- Continuity and recoveryBackups that have been tested and defined recovery times — not a promise that copies exist somewhere.
- Training for staff and managementThe framework holds management bodies accountable. Short sessions and phishing simulations, with a record of who took part.
Frequently asked questions about NIS2
Is my company covered by NIS2?
As a rule, medium-sized and large organisations in the sectors listed in the framework fall within the scope — energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration, postal services, waste, chemicals, food, manufacturing and research, amongst others. There are cases where size is irrelevant and the organisation falls within the scope regardless. The official determination is made through self-assessment on the MyCiber platform, and the responsibility for that assessment lies with the organisation itself — not with the CNCS.
What if my company is not covered?
You are still affected, via the supply chain. Entities within the scope of the regulation are required to manage the risk posed by their suppliers, which involves security questionnaires, contractual requirements and, increasingly, documented evidence. If you sell to hospitals, banks, the energy sector, public administration or industry, NIS2 will affect you through your customers.
What are the fines?
For essential entities, up to 10 million euros or 2% of global annual turnover, whichever is higher. For important entities, up to 7 million euros or 1.4%. In addition, the framework holds management bodies directly accountable.
How long do I have to report an incident?
An early warning within 24 hours, a notification with an assessment within 72 hours and a final report within 30 days. In practice, this means you need detection and logging — without monitoring, there is no way to meet the 24-hour deadline, because you would never notice the incident in the first place.
What technical measures are required?
The framework defines three levels — basic, substantial and high — with 39, 75 and 91 measures, assigned according to the organisation’s risk profile. The methodology is based on the Portuguese National Cybersecurity Reference Framework, which is aligned with NIST CSF 2.0.
Does DataRoad handle the registration for us?
Registration and self-assessment are carried out by the organisation itself, and nobody can do them on your behalf — we guide you and prepare the information, but it is up to you to submit it. What we do manage from start to finish is the technical side: asset inventory, security measures, monitoring, logging and the ability to respond to an incident within the specified timeframes.
This page is for information purposes only and does not constitute legal advice. How your entity is classified is determined by the self-assessment on the CNCS MyCiber platform.
Latest news
DataRoad's latest news and articles.

Office Relocation: An IT Checklist to Ensure Everything Runs Smoothly
IT checklist for relocating premises: the long lead times that affect everything, what needs to be decided before the work begins, the phased plan and the mistakes that are always repeated.

IT for Businesses: Lisbon, Setúbal, Porto, Beja, Cascais and Oeiras
IT support for businesses on the Setúbal Peninsula: what sets the region’s needs apart, when face-to-face contact is essential, and the four questions to ask before engaging a local partner.

Enterprise Wireless Networks: Why Home Wi-Fi Isn’t Up to the Job
Wireless networks for businesses: the four issues that cause Wi-Fi failures, why more access points can worsen the network, the role of a coverage survey, and the most demanding environments.