Este portal utiliza "cookies". Se quiser saber mais sobre cookies, quais as suas finalidades e como geri‑los, consulte a nossa Política de privacidade
Skip to main content

Cybersecurity: New compliance requirements now in Effect

Update   06.08.2026

4 Minute(s)

What’s changing for businesses and public sector organisations?

Cybersecurity

Public Administration

Digital Transformation

Business

In Detail

Cybersecurity is no longer just an IT concern; it has also become a key business and governance priority.

Following the introduction of Regulation No. 756/2026, Portugal's comprehensive Cybersecurity Legal Framework is now in full effect, introducing practical compliance obligations for businesses and public sector organisations within its remit. 

The regulation, published by the National Cybersecurity Centre (CNCS), implements the provisions of Decree-Law No. 125/2025, which transposed the European Union NIS2 Directive into Portuguese law. Key changes include mandatory registration, identification of entities within scope, incident reporting obligations and implementation of minimum cybersecurity measures. 

Mandatory registration on the MyCiber platform 

For organisations that may be covered by the new framework, one of the first steps is to register on the MyCiber platform. 

According to the CNCS Coordinator, organisations have 60 working days to complete their registration and self-identification. This process will determine whether they fall within the scope of the new legal framework. 

To support organisations during this process, the CNCS has made guidance tools available to help them assess whether the new rules apply to them. However, please note that these resources are purely informational and do not exempt organisations from the obligation to complete the self-identification process where required. 

Which organisations are affected? 

The new framework applies to essential and important entities, as well as relevant public sector organisations. It covers a wide range of sectors that are considered critical to the economy and the functioning of the state. 

Whether an organisation falls within the scope depends on factors such as its sector of activity, size and the services it provides, as well as other criteria established by law. Once the required information has been submitted through the platform, the CNCS will review the data and notify the organisation of its classification and, where applicable, its required compliance level. 

It's more than just a compliance exercise. 

The new framework goes well beyond administrative requirements. Organisations covered by the legislation must strengthen their cybersecurity governance by implementing risk-based security measures and maintaining internal risk management processes. They must also be able to respond effectively to cybersecurity incidents. 

They must also keep the information submitted to the CNCS up to date via the electronic platform to ensure that it accurately reflects their operational reality. 

Risk management becomes an ongoing process. 

The regulation reinforces a continuous risk management approach. Organisations must regularly assess the risks affecting their networks and information systems, and evaluate the residual risk remaining after implementing security measures. 

This assessment should take into account factors such as previous cybersecurity incidents, the number of potentially affected users, incident duration, dependencies on other critical sectors and technical guidance issued by the CNCS. 

So, what should organisations do now? 

For many businesses and public sector organisations, this marks the start of a major compliance initiative. As well as establishing whether they fall within the scope of the new framework, organisations must ensure they have the necessary internal processes to comply with the new legal requirements. 

Key actions include: 

  • Determine whether the organisation is subject to Portugal’s Cybersecurity Legal Framework; 
  • Register and complete the self-identification process on the MyCiber platform by the required deadline. 
  • Review internal information security and risk management policies. 
  • Ensure procedures are in place for incident response and reporting. 
  • Keep all information submitted to the CNCS accurate and up to date. 

Significant step forward 

The implementation of this regulation is a significant milestone in Portugal’s national cybersecurity strategy. The aim is to bolster the resilience of Portuguese organisations against cyber threats, while fostering a culture of prevention, risk management and swift incident response. 

For organisations within its scope, complying with these new obligations is not just a legal requirement; it is also an essential component of good corporate governance and business continuity planning.

Outros pontos de interesse

Digital Transformation

The European Commission has published an overview of digital public administration in Portugal

Update   07.09.2026

3 Minute(s)

Digital Transformation

This webinar explores the current state of cloud adoption in Public Administration and the Sovereign Cloud

Update   30.07.2026

4 Minute(s)

Digital Transformation

The Public Administration has seen growth in cloud adoption and increased investment

Update   22.07.2026

4 Minute(s)