NIS2 Country Guide

NIS2 Portugal: the RJC, MyCiber Registration & Coimas

Portugal transposed the NIS2 Directive through the Regime Jurídico da Cibersegurança (RJC), approved by Decreto-Lei n.º 125/2025 and in force since 3 April 2026. The implementing Regulamento n.º 756/2026 followed on 22 June 2026 and opened the MyCiber platform, which is where registration, qualification and incident reporting now happen.

In force: 3 April 2026 Register on MyCiber: 60 dias úteis Law: Decreto-Lei n.º 125/2025 (RJC) Authorities: CNCS · ANACOM · GNS Last updated: 4 August 2026

Introduction: NIS2 Directive & the Portuguese context

Portugal previously had a fragmented cybersecurity framework, with obligations scattered across sectoral laws and soft-law guidance from the National Cybersecurity Centre (CNCS). The original NIS Directive (NIS1) was only partially reflected in national legislation, covering a limited set of operators of essential services.

The Regime Jurídico da Cibersegurança (RJC), approved by Decreto-Lei n.º 125/2025, replaced that framework outright. It transposes Directive (EU) 2022/2555 (NIS2) into Portuguese law, repeals the 2018 cyberspace security regime, and has applied since 3 April 2026.

Two things happened after the law took effect that most English-language summaries have not caught up with. The CNCS Regulamento n.º 756/2026 was published on 22 June 2026, and with it the MyCiber platform opened, starting the clock on the duty to register. That publication also started the 24-month period after which the substantive security measures take effect, which means the headline obligations are dated but not yet enforceable. Both points are set out below.

Quick link: New to NIS2? Start with our general guides “What is NIS2?” and “NIS vs NIS2”.

What you must do in Portugal

Five duties, in the order the RJC imposes them. Every one of them runs from a date, and the first two are live now.

  1. Register on MyCiber. Entities already trading when the RJC took effect have 60 dias úteis (working days) from the platform being made available. MyCiber opened alongside the Regulamento on 22 June 2026, which places the close of that window in mid-September 2026. Entities that started trading after 3 April 2026 have 30 dias úteis. This is a self-identification duty, not a wait-to-be-contacted one.
  2. Wait for your qualification. CNCS, ANACOM or GNS then notifies you of your qualification as an essential entity, important entity or relevant public entity, within 30 dias úteis. The rest of your deadlines run from that notification, not from registration.
  3. Appoint a Responsável de Cibersegurança and a Ponto de Contacto Permanente within 20 dias úteis of that qualification notice. The cybersecurity officer must sit on the management body or report directly to it, and the contact point has to be reachable at any hour.
  4. Submit your asset list (Lista de Ativos) by 31 January 2027, or within six months of your qualification notice — whichever falls first.
  5. Implement the minimum security measures and, for essential entities, file the annual report by 22 June 2028 — 24 months from the Regulamento's publication.
The fine waiver is the deadline nobody mentions. Under Article 65 of the RJC, any essential, important or relevant public entity may apply, with reasons, to have the Article 61 and Article 62 fines waived on the ground that it had no internal procedure for adapting to the new regime. That option is open for 12 months from entry into force — until 3 April 2027, and then it is gone.

NIS2 implementation in Portugal

Portugal transposed NIS2 through Decreto-Lei n.º 125/2025, de 4 de dezembro, published in the Diário da República, 1.ª série, n.º 234. It approves the Regime Jurídico da Cibersegurança (RJC) as an annex and implements Directive (EU) 2022/2555 into national law.

Article 11 sets entry into force at 120 days after publication, which fell on 3 April 2026. Article 10(2) then defers a specific list of provisions — the core security measures, the essential-entity annual report, and the penalties attached to them — until 24 months after the implementing regulation is published. That regulation, Regulamento n.º 756/2026, was published on 22 June 2026, so those obligations bite on 22 June 2028. CNCS has confirmed this reading in writing.

The RJC rests on Lei n.º 59/2025, de 22 de outubro, which authorised the Government to transpose NIS2 by decree-law. Article 9 of the decree-law repeals the previous regime outright: Lei n.º 46/2018 (the cyberspace security regime), Decreto-Lei n.º 65/2021 (its implementing regulation), Article 2.º-A of Decreto-Lei n.º 3/2012, and Articles 59 to 65 of the Electronic Communications Law (Lei n.º 16/2022). If your compliance programme still cites Lei 46/2018, it is citing a repealed law.

Status

Transposed and in force. The RJC has applied since 3 April 2026 and the implementing Regulamento since 23 June 2026. Portugal reached this point under EU infringement pressure, having missed the October 2024 deadline.

What the Regulamento adds

Regulamento n.º 756/2026 sets the operating rules for MyCiber and carries four annexes: the Quadro Nacional de Referência for cybersecurity, the Matriz de Risco methodology, the minimum security measures for essential and important entities, and a separate set of measures for relevant public entities. It followed a public consultation that ran from 10 March to 22 April 2026.

Supervisory model

One national authority — CNCS — plus two sectoral authorities, ANACOM for electronic communications and postal services and GNS for electronic trust services. Three further bodies supervise digital operational resilience in finance only. The full designation is in the authorities table below.

Am I in scope in Portugal?

Portugal applies the Directive's sector and size tests, and then adds a third category that has no equivalent in the Directive at all.

Category Test
Essential entities Medium and large organisations in the high-criticality sectors (Annex I) — energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, space.
Important entities Medium and large organisations in the other critical sectors (Annex II) — postal and courier services, waste management, chemicals, food, manufacturing, digital providers, research.
Entidades públicas relevantes — Grupo A Direct state administration and autonomous-region equivalents with 250 or more staff; indirect and autonomous administration above 250; public business entities above the Recommendation 2003/361/EC thresholds; independent administrative entities; and named bodies including the Provedoria da Justiça, the Conselho Económico e Social and the technical services of the Presidency, the Assembleia da República and the courts.
Entidades públicas relevantes — Grupo B The same categories with 75 to 249 staff, plus public business entities qualifying as medium enterprises.
Regardless of size DNS service providers, TLD name registries, domain-name registration service providers, trust service providers, and providers of public electronic communications networks or services.
If more than one qualification fits, the most demanding one applies. Article 9 of the RJC sets an explicit order of precedence, headed by essential entities. You do not get to pick the lighter regime.

CNCS publishes a non-binding Simulador that lets an organisation test whether the RJC applies to it before registering. It is a guide, not a determination — the qualification that counts is the one the competent authority notifies to you.

NIS2 Portugal: what you need to know about compliance

The RJC mirrors the NIS2 architecture of essential entities and important entities and adds entidades públicas relevantes. Scope is set out in the section above; what follows is what being in scope actually obliges you to do.

Governance duties

  • Appoint a Responsável de Cibersegurança who sits on the management body or reports directly to it, and notify the competent authority within 20 dias úteis of qualification.
  • Nominate the team staffing the Ponto de Contacto Permanente, with primary and alternative contact details, on the same deadline.
  • Notify any replacement of the cybersecurity officer without undue delay.
  • Management bodies approve the cybersecurity measures, oversee implementation and receive training.

Core obligations

  • Implement the minimum security measures in Annex III to the Regulamento, keyed to the Quadro Nacional de Referência and to the conformity level assigned to you. Relevant public entities follow Annex IV instead.
  • Run the Matriz de Risco methodology in Annex II and manage the residual risk you accept.
  • Maintain and submit the Lista de Ativos by 31 January 2027 or six months after qualification, whichever comes first.
  • Notify significant incidents through MyCiber on the four-stage clock set out below.
  • Manage supply-chain cybersecurity risk, including contractual security and incident-notification obligations for critical suppliers.
  • Essential entities file an annual report to CNCS from 22 June 2028.

When the measures actually bite

Article 10(2) of the decree-law defers Articles 27(1) and (2), 28 to 30 and 33 — the substantive security-measure and annual-report duties — and the corresponding penalties in Article 61(1)(b), (c) and (f), until 24 months after the Regulamento was published. That is 22 June 2028. Registration, qualification, officer appointment and incident reporting are not deferred and apply now.

Do not read the 2028 date as a reprieve. The measures in Annex III are the ones that take real programme time, and the conformity level you are held to depends on the qualification you receive this year. CNCS runs a national NIS2 roadmap, awareness programme and training sessions across the mainland and the autonomous regions.

Competent authorities & CSIRT

Article 15 of the RJC sets out the institutional framework precisely, and it is narrower than most summaries suggest. There are three competent cybersecurity authorities — CNCS, ANACOM and GNS — and three further bodies whose remit is confined to digital operational resilience in the financial sector.

Role Authority Notes
National cybersecurity authority, EU single point of contact, national cybersecurity certification authority Centro Nacional de Cibersegurança (CNCS) Leads the RJC, qualifies entities, operates MyCiber, sets technical instructions and represents Portugal in EU NIS2 cooperation. Also part of the national incident response team.
National CSIRT CERT.PT, within CNCS Receives incident notifications, issues alerts and guidance, coordinates technical response and runs coordinated vulnerability disclosure.
Sectoral cybersecurity authority — electronic communications and postal services ANACOM Qualifies and supervises entities in its sector, and receives their incident notifications.
Sectoral cybersecurity authority — electronic trust services Gabinete Nacional de Segurança (GNS) Competent authority for qualified and non-qualified trust service providers in the internal market.
Special authorities — financial sector digital operational resilience only Banco de Portugal · CMVM · ASF Their competence under the RJC is limited to digital operational resilience in the financial sector. They are not general sectoral cybersecurity authorities.
Advisory and crisis bodies Conselho Superior de Segurança do Ciberespaço · Secretário-Geral do Sistema de Segurança Interna The CSSC advises the Prime Minister on cybersecurity policy. The Secretary-General is the national authority for managing large-scale cyber crises and incidents.

Registration: who, where and by when

MyCibermyciber.gov.pt — is the electronic platform required by Article 8(1) of the RJC. It is where you identify yourself, receive your qualification, nominate your cybersecurity officer and contact point, and file every incident notification. Its operating rules are set by Regulamento n.º 756/2026.

Who Deadline Counted from
Entities already trading on 3 April 2026 60 dias úteis The platform being made available (22 June 2026)
Entities starting activity after 3 April 2026 30 dias úteis The start of activity
Domain-name registration service providers 30 days The start of activity (Article 8(6))
CNCS, ANACOM or GNS notifies your qualification 30 dias úteis The date of qualification (Article 8(5))
Cybersecurity officer and permanent contact point 20 dias úteis The qualification notification
These are working days, and that changes the date by about a month. The statute writes "60 dias" at Article 8(1), which several English-language summaries have read as calendar days — giving a deadline around 21 August 2026. The CNCS Calendário de obrigações states 60 dias úteis, consistent with the Portuguese Código do Procedimento Administrativo, which counts procedural deadlines in working days. On the regulator's own reading the window closes in mid-September 2026. We do not print a single hard date here, because CNCS has published the rule but not the platform-availability date in writing — see Sources.

Who may register

The entity's legal representative, or someone expressly given power to bind it. Authentication is by Chave Móvel Digital or Cartão de Cidadão, and the card route needs a reader. Unless the representative is listed in the Sistema de Certificação de Atributos Profissionais, have documentary proof of representation powers ready before you start.

What happens next

You self-declare whether you are an essential entity, an important entity or a relevant public entity. CNCS, ANACOM or GNS then qualifies you and notifies that decision within 30 dias úteis, after a prior hearing where the qualification rests on the discretionary criteria. Your remaining deadlines run from that notice.

Portuguese What it means
Regime Jurídico da Cibersegurança (RJC)The cybersecurity legal regime — the NIS2 transposition itself
dias úteisWorking days, excluding weekends and public holidays
coimaAdministrative fine
contraordenaçãoAdministrative offence — graded muito grave, grave or leve
Responsável de CibersegurançaThe cybersecurity officer
Ponto de Contacto PermanenteThe always-reachable contact point
entidades públicas relevantesRelevant public entities, Groups A and B
Lista de AtivosThe asset list due by 31 January 2027

CNCS and MyCiber operate in Portuguese. There is no official English version of the RJC, so the Portuguese text is the one that governs.

Incident reporting in Portugal

Portugal does not use the Directive's familiar three-stage clock. Articles 40 to 44 of the RJC set out four stages, and add a carve-out for incidents you resolve quickly.

Stage Deadline Provision
Initial notification Without undue delay and within 24 hours of concluding that a significant incident exists or may come to exist Article 42(1)
Update to the initial notification Within 72 hours of verifying the incident, with an initial severity and impact assessment Article 42(3)
Notification that the significant impact has ended Without undue delay and within 24 hours of the impact ending Article 43(1)
Final report 30 dias úteis from the end-of-impact notification Article 44(1)
Interim report On request, while the incident is running Article 44
The two-hour carve-out. Article 41(2): if the incident is resolved within two hours of detection, you owe only the end-of-impact notification — no initial notification, no final report. This is a genuine simplification and it appears in no other member state's transposition we have reviewed.

All notifications go through MyCiber (Article 40(6)). Notifying does not by itself create additional liability for the notifying entity (Article 40(2)). Whether an incident is significant turns on the number of users affected, the total user base, duration, severity of the disruption and the scale of economic and social impact (Article 40(3)), read together with any CNCS technical instruction and the Commission's implementing acts.

An RJC notification does not discharge your other duties. Article 40(5) preserves separate obligations to the Ministério Público, the Polícia Judiciária, the CNPD (data protection), the Entidade Fiscalizadora do Segredo de Estado and the GNS. Article 40(7) allows those notifications to be made simultaneously through MyCiber under a protocol between the authorities — so plan one process, not five.

NIS2 timeline & key dates (Portugal)

17 October 2024 — EU deadline for NIS2 transposition passes; Portugal does not yet have implementing legislation in place.
28 November 2024 — European Commission launches infringement proceedings and sends letter of formal notice for failure to transpose NIS2.
7 May 2025 — Commission issues reasoned opinion to Portugal for continued failure to notify full transposition.
22 October 2025 — Law 59/2025 published, authorising the Government to transpose NIS2 and approve the RJC by decree-law.
4 December 2025 — Decree-Law 125/2025 (RJC) published in the Official Journal, formally transposing Directive (EU) 2022/2555 (NIS2).
3 April 2026 — RJC enters into force, 120 days after publication. Lei 46/2018 and Decreto-Lei 65/2021 are repealed.
22 June 2026 — Regulamento n.º 756/2026 published; the MyCiber platform opens and the 24-month clock for the security measures starts running.
23 June 2026 — Regulamento enters into force, the day after publication.
Mid-September 2026 — the 60 dias úteis window for entities already trading on 3 April 2026 to register on MyCiber closes.
31 January 2027 — deadline for the Lista de Ativos, or six months after your qualification notice if that falls first.
3 April 2027 — the Article 65 window to apply for a waiver of Article 61 and 62 fines closes, 12 months after entry into force.
22 June 2028 — the minimum security measures and the essential-entity annual report take effect, 24 months after the Regulamento was published, along with the penalties attached to them.

Sector-specific notes for Portugal

  • Energy: electricity, gas and other critical energy operators are treated as essential entities with strict incident-reporting and resilience obligations.
  • Digital infrastructure & telecom: electronic communications networks, data centres, cloud providers and key internet infrastructure are a central focus, with ANACOM playing a major supervisory role for communications and postal services.
  • Public administration: central government bodies and other relevant public entities (Groups A and B) are explicitly covered to protect critical public services and state digital infrastructure.
  • Finance & payments: banks and financial market infrastructures are in scope under both the RJC and DORA. Banco de Portugal, the CMVM and the ASF are named in Article 15 as special authorities for digital operational resilience only — for everything else in the RJC, the competent authority is CNCS.
  • Health & critical services: hospitals and critical healthcare providers face substantial governance and technical uplift. There is no health-sector cybersecurity authority; they answer to CNCS.
  • Electronic trust services: qualified and non-qualified trust service providers are supervised by the GNS, not CNCS — the one sectoral split that is easy to miss.

How Portugal differs from the NIS2 Directive

Five places where the RJC goes beyond, or simply departs from, the Directive text. If you are running a multi-country programme built on the Directive, these are the deltas that will catch you.

  1. A whole third category of entity. Entidades públicas relevantes have no equivalent in the Directive. Public bodies are pulled in on headcount alone — 250 or more staff for Group A, and as few as 75 for Group B — with no turnover test at all. That is well below the Directive's medium-enterprise threshold, and it captures a large part of the Portuguese public sector.
  2. A fourth reporting stage. The Directive runs early warning, notification, final report. Portugal inserts a notification that the significant impact has ended, due within 24 hours of the impact stopping, and runs the final report from that point rather than from the incident. It also expresses the final-report deadline in working days rather than as one month.
  3. Statutory minimum fines. The Directive sets ceilings only. Portugal sets a floor on every tier — from €2,000 for an essential entity's most serious breach down to €250 for a minor one by an individual. For a small in-scope entity the floor, not the ceiling, is the number that matters.
  4. A time-limited amnesty. Article 65 lets any in-scope entity apply to have its fines waived on the ground that it had no internal adaptation procedure — but only until 3 April 2027. Nothing in the Directive requires this and few member states offer it.
  5. The obligations are dated but deferred. Article 10(2) suspends the substantive security measures, the annual report and their penalties until 22 June 2028. Registration, qualification, officer appointment and incident reporting are live now. Portugal has separated the two in a way the Directive does not.
Where Portugal does not deviate: the sector lists, the size thresholds for private entities, the risk-management measures in Article 21 of the Directive and the main-establishment rule are transposed without national embellishment. If your programme already meets the Directive on those points, it meets the RJC on them too.

Penalties, coimas and how they are graded

The RJC does not simply restate the Directive's ceilings. Articles 61 to 63 grade every breach as muito grave, grave or leve, and set both a minimum and a maximum for each, separately for legal persons and for individuals. The tables below are the actual statutory ranges.

Contraordenações muito graves — Article 61

Covers failure to adopt the required cybersecurity measures, the annual report, the cybersecurity officer and contact point duties, measures set by CNCS, and the incident notification duties in Articles 40 to 44.

EntityLegal personIndividual
Essential entity €2,000 – €10,000,000, or 2% of worldwide annual turnover in the previous financial year, whichever is higher €350 – €200,000
Important entity €1,250 – €7,000,000, or a maximum not lower than 1.4% of worldwide annual turnover, whichever is higher €350 – €200,000
Relevant public entity, Group A €16,000 – €4,000,000 €500 – €16,000
Relevant public entity, Group B €8,000 – €350,000 €500 – €16,000

Contraordenações graves — Article 62

Covers failure to identify yourself under Article 8, breaches of the binding orders, warnings and instructions of the competent authority, violation of a suspension, and failure to comply with an immediate execution measure.

EntityLegal personIndividual
Essential entity €1,250 – €5,000,000, or 1% of worldwide annual turnover, whichever is higher €250 – €125,000
Important entity €875 – €3,500,000, or a maximum not lower than 0.7% of worldwide annual turnover €250 – €125,000
Relevant public entity, Group A €10,000 – €2,500,000 €375 – €10,000
Relevant public entity, Group B €5,000 – €225,000 €375 – €10,000

Contraordenações leves — Article 63

Confined to cybersecurity certification: using an invalid, expired or revoked certification mark, implying a certification that does not exist, withholding or falsifying information relevant to a certification process, or ignoring a request from the Comissão de Avaliação de Segurança do Ciberespaço.

  • Legal person: €875 – €45,000
  • Individual: €250 – €3,750
Three things that change the number. Under Article 64, a negligent breach is punishable with both the minimum and the maximum halved. Under Article 66 the authority sets the actual amount within the range. Article 68 adds sanções compulsórias — periodic penalties to compel compliance — on top of the fine.
The waiver, while it lasts. Article 65 allows any essential, important or relevant public entity to apply, with reasons, for the Article 61 and 62 fines to be waived on the ground that it had no internal procedure for adapting to the new regime. The window runs 12 months from entry into force and closes on 3 April 2027.

How to prepare for NIS2 in Portugal

  1. Register first, analyse second: the MyCiber deadline does not wait for your gap assessment, and registration is a self-declaration you can refine later. Sort out the Chave Móvel Digital or Cartão de Cidadão access and the proof of representation powers before you sit down to do it.
  2. Run a gap assessment against Annex III: the Quadro Nacional de Referência and the minimum measures in the Regulamento are the standard you will be held to, keyed to your conformity level. This is the work that needs the full run-up to June 2028.
  3. Build the asset list now: the Lista de Ativos is due by 31 January 2027 or six months after qualification, whichever comes first, and it is the input to everything else.
  4. Design one incident process, not five: the four-stage RJC clock has to coexist with GDPR notification to the CNPD and any criminal reporting. Article 40(7) allows simultaneous notification through MyCiber — use it.
  5. Manage supply-chain risk: review contracts with key ICT and service providers, adding explicit cybersecurity, audit and incident-notification clauses.
  6. Align with recognised frameworks: build or refine your ISMS using ISO/IEC 27001, NIST CSF or similar to structure your NIS2/RJC compliance programme.
  7. Engage leadership: brief the board and senior management on their new responsibilities and ensure cybersecurity is embedded in overall risk and business strategy.

Operating in more than one EU country?

If you are a DNS service provider, TLD name registry, cloud computing, data centre or content delivery network provider, a managed service or managed security service provider, or an online marketplace, search engine or social networking platform, you answer to the regulator where your main establishment sits — not to all 27. For most of those categories that means the member state where your cybersecurity risk-management decisions are predominantly taken. Registering with CNCS does not, by itself, settle the question.

For those same entity types, Implementing Regulation (EU) 2024/2690 sets the technical and methodological requirements directly. It is a regulation, not a directive, so it is not transposed and reads identically in Portugal, Spain and everywhere else. Where it applies, it — not the national annex — is the specification to build against.

Two national deltas worth checking if Portugal is one of several markets for you: the 75-employee public-sector floor has no counterpart elsewhere, and the 24-hour end-of-impact notification means a group-wide incident runbook written to the Directive's three-stage clock will be incomplete here. Compare with Spain, Italy, Germany and Belgium.

Official links & resources

FAQ: NIS2 in Portugal

Has Portugal fully transposed NIS2?
Yes. Decreto-Lei n.º 125/2025 approved the Regime Jurídico da Cibersegurança and has been in force since 3 April 2026. The implementing Regulamento n.º 756/2026 followed on 22 June 2026. Portugal reached this point after missing the October 2024 deadline and facing EU infringement proceedings.
Who is the main NIS2 authority in Portugal?
The Centro Nacional de Cibersegurança (CNCS) is the national cybersecurity authority, the EU single point of contact and the national certification authority, with CERT.PT as the national CSIRT. Article 15 of the RJC names only two sectoral authorities alongside it — ANACOM for electronic communications and postal services, and the GNS for electronic trust services.
By when must we register on MyCiber?
If you were already trading on 3 April 2026, within 60 dias úteis — working days — of the platform being made available, which puts the close of the window in mid-September 2026. If you started activity after that date, within 30 dias úteis. Note that several English-language sources read the statute's "60 dias" as calendar days and give a date in August; CNCS's own published calendar says working days.
Do we need a specific certification like ISO 27001?
The RJC does not mandate a single certification, but alignment with standards like ISO/IEC 27001 is strongly recommended as an efficient way to structure and evidence compliance with NIS2 obligations in Portugal.
What are the actual fines?
For a very serious breach by an essential entity, €2,000 to €10 million or 2% of worldwide turnover, whichever is higher; for an important entity, €1,250 to €7 million or 1.4%. Individuals face €350 to €200,000. Relevant public entities have their own scales. Unlike the Directive, which sets ceilings only, every Portuguese tier has a statutory minimum, and a negligent breach halves both ends of the range.
Are the security measures enforceable yet?
Not until 22 June 2028. Article 10(2) of the decree-law defers the core security measures, the essential-entity annual report and the penalties attached to them until 24 months after the Regulamento was published. Registration, qualification, appointing your cybersecurity officer and incident reporting all apply now.

Sources & verification

Every date, figure and fine range on this page was taken from the Portuguese gazette text or from CNCS directly. Law-firm summaries and NIS2 trackers were used to decide what to check, never as authority.

SourceUsed forChecked
Decreto-Lei n.º 125/2025, DR 1.ª série n.º 234, 4 December 2025 — official gazette PDF Entry into force (Article 11), repeals (Article 9), deferral (Article 10(2)), scope (Articles 6, 7, 9), qualification and registration (Article 8), authorities (Article 15), officer and contact point (Articles 31, 32), reporting (Articles 40–44), penalties (Articles 61–68) 4 August 2026
CNCS — Regulamento do Regime Jurídico da Cibersegurança Regulamento n.º 756/2026, publication 22 June 2026, entry into force 23 June 2026, the four annexes, the consultation period, and the start of the 24-month clock 4 August 2026
CNCS — MyCiber, including the Calendário de obrigações The 60 and 30 dias úteis registration deadlines, the 30 dias úteis qualification notice, the 20 dias úteis officer and contact-point deadline, the 31 January 2027 asset list, and the registration credentials 4 August 2026
European Commission — NIS2 implementation in Portugal Infringement timeline: formal notice 28 November 2024, reasoned opinion 7 May 2025 4 August 2026

What this page deliberately does not state

  • A single hard calendar date for the registration deadline. The rule is 60 dias úteis from the platform being made available. CNCS has published the rule but not the platform-availability date in writing, so the exact end date turns on a date the regulator has not fixed publicly. We say mid-September 2026 and explain why the August date circulating in English-language summaries — which reads "60 dias" as calendar days — is wrong. Your own MyCiber record is authoritative for your entity.
  • An estimate of how many entities are in scope. A figure of around 9,000 circulates widely and previously appeared on this page. CNCS has not published a count, and we would rather print nothing than a number that gets quoted back to us.
  • Any sectoral cybersecurity authority beyond ANACOM and the GNS. This page previously referred to "various regulators" for energy, finance, health and transport, and some third-party guides list ERSE, DGEG, IMT, ANAC, AMT and DGRM. Article 15 of the RJC names none of them. Banco de Portugal, the CMVM and the ASF appear only as special authorities for digital operational resilience in the financial sector. The claim has been removed rather than repeated.
  • Any enforcement activity. No fines or supervisory actions under the RJC are documented as at the date above, which is unsurprising given the security measures do not take effect until 2028.
Information provided for general guidance; always consult Decreto-Lei n.º 125/2025 and Regulamento n.º 756/2026 as published in the Diário da República, the CNCS guidance, and Portuguese legal counsel, for definitive NIS2 compliance requirements in Portugal.