NIS2 Portugal: the RJC, MyCiber Registration & Coimas
Portugal transposed the NIS2 Directive through the Regime Jurídico da Cibersegurança (RJC), approved by Decreto-Lei n.º 125/2025 and in force since 3 April 2026. The implementing Regulamento n.º 756/2026 followed on 22 June 2026 and opened the MyCiber platform, which is where registration, qualification and incident reporting now happen.
Introduction: NIS2 Directive & the Portuguese context
Portugal previously had a fragmented cybersecurity framework, with obligations scattered across sectoral laws and soft-law guidance from the National Cybersecurity Centre (CNCS). The original NIS Directive (NIS1) was only partially reflected in national legislation, covering a limited set of operators of essential services.
The Regime Jurídico da Cibersegurança (RJC), approved by Decreto-Lei n.º 125/2025, replaced that framework outright. It transposes Directive (EU) 2022/2555 (NIS2) into Portuguese law, repeals the 2018 cyberspace security regime, and has applied since 3 April 2026.
Two things happened after the law took effect that most English-language summaries have not caught up with. The CNCS Regulamento n.º 756/2026 was published on 22 June 2026, and with it the MyCiber platform opened, starting the clock on the duty to register. That publication also started the 24-month period after which the substantive security measures take effect, which means the headline obligations are dated but not yet enforceable. Both points are set out below.
What you must do in Portugal
Five duties, in the order the RJC imposes them. Every one of them runs from a date, and the first two are live now.
- Register on MyCiber. Entities already trading when the RJC took effect have 60 dias úteis (working days) from the platform being made available. MyCiber opened alongside the Regulamento on 22 June 2026, which places the close of that window in mid-September 2026. Entities that started trading after 3 April 2026 have 30 dias úteis. This is a self-identification duty, not a wait-to-be-contacted one.
- Wait for your qualification. CNCS, ANACOM or GNS then notifies you of your qualification as an essential entity, important entity or relevant public entity, within 30 dias úteis. The rest of your deadlines run from that notification, not from registration.
- Appoint a Responsável de Cibersegurança and a Ponto de Contacto Permanente within 20 dias úteis of that qualification notice. The cybersecurity officer must sit on the management body or report directly to it, and the contact point has to be reachable at any hour.
- Submit your asset list (Lista de Ativos) by 31 January 2027, or within six months of your qualification notice — whichever falls first.
- Implement the minimum security measures and, for essential entities, file the annual report by 22 June 2028 — 24 months from the Regulamento's publication.
NIS2 implementation in Portugal
Portugal transposed NIS2 through Decreto-Lei n.º 125/2025, de 4 de dezembro, published in the Diário da República, 1.ª série, n.º 234. It approves the Regime Jurídico da Cibersegurança (RJC) as an annex and implements Directive (EU) 2022/2555 into national law.
Article 11 sets entry into force at 120 days after publication, which fell on 3 April 2026. Article 10(2) then defers a specific list of provisions — the core security measures, the essential-entity annual report, and the penalties attached to them — until 24 months after the implementing regulation is published. That regulation, Regulamento n.º 756/2026, was published on 22 June 2026, so those obligations bite on 22 June 2028. CNCS has confirmed this reading in writing.
The RJC rests on Lei n.º 59/2025, de 22 de outubro, which authorised the Government to transpose NIS2 by decree-law. Article 9 of the decree-law repeals the previous regime outright: Lei n.º 46/2018 (the cyberspace security regime), Decreto-Lei n.º 65/2021 (its implementing regulation), Article 2.º-A of Decreto-Lei n.º 3/2012, and Articles 59 to 65 of the Electronic Communications Law (Lei n.º 16/2022). If your compliance programme still cites Lei 46/2018, it is citing a repealed law.
Status
Transposed and in force. The RJC has applied since 3 April 2026 and the implementing Regulamento since 23 June 2026. Portugal reached this point under EU infringement pressure, having missed the October 2024 deadline.
What the Regulamento adds
Regulamento n.º 756/2026 sets the operating rules for MyCiber and carries four annexes: the Quadro Nacional de Referência for cybersecurity, the Matriz de Risco methodology, the minimum security measures for essential and important entities, and a separate set of measures for relevant public entities. It followed a public consultation that ran from 10 March to 22 April 2026.
Supervisory model
One national authority — CNCS — plus two sectoral authorities, ANACOM for electronic communications and postal services and GNS for electronic trust services. Three further bodies supervise digital operational resilience in finance only. The full designation is in the authorities table below.
Am I in scope in Portugal?
Portugal applies the Directive's sector and size tests, and then adds a third category that has no equivalent in the Directive at all.
| Category | Test |
|---|---|
| Essential entities | Medium and large organisations in the high-criticality sectors (Annex I) — energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, space. |
| Important entities | Medium and large organisations in the other critical sectors (Annex II) — postal and courier services, waste management, chemicals, food, manufacturing, digital providers, research. |
| Entidades públicas relevantes — Grupo A | Direct state administration and autonomous-region equivalents with 250 or more staff; indirect and autonomous administration above 250; public business entities above the Recommendation 2003/361/EC thresholds; independent administrative entities; and named bodies including the Provedoria da Justiça, the Conselho Económico e Social and the technical services of the Presidency, the Assembleia da República and the courts. |
| Entidades públicas relevantes — Grupo B | The same categories with 75 to 249 staff, plus public business entities qualifying as medium enterprises. |
| Regardless of size | DNS service providers, TLD name registries, domain-name registration service providers, trust service providers, and providers of public electronic communications networks or services. |
CNCS publishes a non-binding Simulador that lets an organisation test whether the RJC applies to it before registering. It is a guide, not a determination — the qualification that counts is the one the competent authority notifies to you.
NIS2 Portugal: what you need to know about compliance
The RJC mirrors the NIS2 architecture of essential entities and important entities and adds entidades públicas relevantes. Scope is set out in the section above; what follows is what being in scope actually obliges you to do.
Governance duties
- Appoint a Responsável de Cibersegurança who sits on the management body or reports directly to it, and notify the competent authority within 20 dias úteis of qualification.
- Nominate the team staffing the Ponto de Contacto Permanente, with primary and alternative contact details, on the same deadline.
- Notify any replacement of the cybersecurity officer without undue delay.
- Management bodies approve the cybersecurity measures, oversee implementation and receive training.
Core obligations
- Implement the minimum security measures in Annex III to the Regulamento, keyed to the Quadro Nacional de Referência and to the conformity level assigned to you. Relevant public entities follow Annex IV instead.
- Run the Matriz de Risco methodology in Annex II and manage the residual risk you accept.
- Maintain and submit the Lista de Ativos by 31 January 2027 or six months after qualification, whichever comes first.
- Notify significant incidents through MyCiber on the four-stage clock set out below.
- Manage supply-chain cybersecurity risk, including contractual security and incident-notification obligations for critical suppliers.
- Essential entities file an annual report to CNCS from 22 June 2028.
When the measures actually bite
Article 10(2) of the decree-law defers Articles 27(1) and (2), 28 to 30 and 33 — the substantive security-measure and annual-report duties — and the corresponding penalties in Article 61(1)(b), (c) and (f), until 24 months after the Regulamento was published. That is 22 June 2028. Registration, qualification, officer appointment and incident reporting are not deferred and apply now.
Registration: who, where and by when
MyCiber — myciber.gov.pt — is the electronic platform required by Article 8(1) of the RJC. It is where you identify yourself, receive your qualification, nominate your cybersecurity officer and contact point, and file every incident notification. Its operating rules are set by Regulamento n.º 756/2026.
| Who | Deadline | Counted from |
|---|---|---|
| Entities already trading on 3 April 2026 | 60 dias úteis | The platform being made available (22 June 2026) |
| Entities starting activity after 3 April 2026 | 30 dias úteis | The start of activity |
| Domain-name registration service providers | 30 days | The start of activity (Article 8(6)) |
| CNCS, ANACOM or GNS notifies your qualification | 30 dias úteis | The date of qualification (Article 8(5)) |
| Cybersecurity officer and permanent contact point | 20 dias úteis | The qualification notification |
Who may register
The entity's legal representative, or someone expressly given power to bind it. Authentication is by Chave Móvel Digital or Cartão de Cidadão, and the card route needs a reader. Unless the representative is listed in the Sistema de Certificação de Atributos Profissionais, have documentary proof of representation powers ready before you start.
What happens next
You self-declare whether you are an essential entity, an important entity or a relevant public entity. CNCS, ANACOM or GNS then qualifies you and notifies that decision within 30 dias úteis, after a prior hearing where the qualification rests on the discretionary criteria. Your remaining deadlines run from that notice.
| Portuguese | What it means |
|---|---|
| Regime Jurídico da Cibersegurança (RJC) | The cybersecurity legal regime — the NIS2 transposition itself |
| dias úteis | Working days, excluding weekends and public holidays |
| coima | Administrative fine |
| contraordenação | Administrative offence — graded muito grave, grave or leve |
| Responsável de Cibersegurança | The cybersecurity officer |
| Ponto de Contacto Permanente | The always-reachable contact point |
| entidades públicas relevantes | Relevant public entities, Groups A and B |
| Lista de Ativos | The asset list due by 31 January 2027 |
CNCS and MyCiber operate in Portuguese. There is no official English version of the RJC, so the Portuguese text is the one that governs.
Incident reporting in Portugal
Portugal does not use the Directive's familiar three-stage clock. Articles 40 to 44 of the RJC set out four stages, and add a carve-out for incidents you resolve quickly.
| Stage | Deadline | Provision |
|---|---|---|
| Initial notification | Without undue delay and within 24 hours of concluding that a significant incident exists or may come to exist | Article 42(1) |
| Update to the initial notification | Within 72 hours of verifying the incident, with an initial severity and impact assessment | Article 42(3) |
| Notification that the significant impact has ended | Without undue delay and within 24 hours of the impact ending | Article 43(1) |
| Final report | 30 dias úteis from the end-of-impact notification | Article 44(1) |
| Interim report | On request, while the incident is running | Article 44 |
All notifications go through MyCiber (Article 40(6)). Notifying does not by itself create additional liability for the notifying entity (Article 40(2)). Whether an incident is significant turns on the number of users affected, the total user base, duration, severity of the disruption and the scale of economic and social impact (Article 40(3)), read together with any CNCS technical instruction and the Commission's implementing acts.
NIS2 timeline & key dates (Portugal)
Sector-specific notes for Portugal
- Energy: electricity, gas and other critical energy operators are treated as essential entities with strict incident-reporting and resilience obligations.
- Digital infrastructure & telecom: electronic communications networks, data centres, cloud providers and key internet infrastructure are a central focus, with ANACOM playing a major supervisory role for communications and postal services.
- Public administration: central government bodies and other relevant public entities (Groups A and B) are explicitly covered to protect critical public services and state digital infrastructure.
- Finance & payments: banks and financial market infrastructures are in scope under both the RJC and DORA. Banco de Portugal, the CMVM and the ASF are named in Article 15 as special authorities for digital operational resilience only — for everything else in the RJC, the competent authority is CNCS.
- Health & critical services: hospitals and critical healthcare providers face substantial governance and technical uplift. There is no health-sector cybersecurity authority; they answer to CNCS.
- Electronic trust services: qualified and non-qualified trust service providers are supervised by the GNS, not CNCS — the one sectoral split that is easy to miss.
How Portugal differs from the NIS2 Directive
Five places where the RJC goes beyond, or simply departs from, the Directive text. If you are running a multi-country programme built on the Directive, these are the deltas that will catch you.
- A whole third category of entity. Entidades públicas relevantes have no equivalent in the Directive. Public bodies are pulled in on headcount alone — 250 or more staff for Group A, and as few as 75 for Group B — with no turnover test at all. That is well below the Directive's medium-enterprise threshold, and it captures a large part of the Portuguese public sector.
- A fourth reporting stage. The Directive runs early warning, notification, final report. Portugal inserts a notification that the significant impact has ended, due within 24 hours of the impact stopping, and runs the final report from that point rather than from the incident. It also expresses the final-report deadline in working days rather than as one month.
- Statutory minimum fines. The Directive sets ceilings only. Portugal sets a floor on every tier — from €2,000 for an essential entity's most serious breach down to €250 for a minor one by an individual. For a small in-scope entity the floor, not the ceiling, is the number that matters.
- A time-limited amnesty. Article 65 lets any in-scope entity apply to have its fines waived on the ground that it had no internal adaptation procedure — but only until 3 April 2027. Nothing in the Directive requires this and few member states offer it.
- The obligations are dated but deferred. Article 10(2) suspends the substantive security measures, the annual report and their penalties until 22 June 2028. Registration, qualification, officer appointment and incident reporting are live now. Portugal has separated the two in a way the Directive does not.
Penalties, coimas and how they are graded
The RJC does not simply restate the Directive's ceilings. Articles 61 to 63 grade every breach as muito grave, grave or leve, and set both a minimum and a maximum for each, separately for legal persons and for individuals. The tables below are the actual statutory ranges.
Contraordenações muito graves — Article 61
Covers failure to adopt the required cybersecurity measures, the annual report, the cybersecurity officer and contact point duties, measures set by CNCS, and the incident notification duties in Articles 40 to 44.
| Entity | Legal person | Individual |
|---|---|---|
| Essential entity | €2,000 – €10,000,000, or 2% of worldwide annual turnover in the previous financial year, whichever is higher | €350 – €200,000 |
| Important entity | €1,250 – €7,000,000, or a maximum not lower than 1.4% of worldwide annual turnover, whichever is higher | €350 – €200,000 |
| Relevant public entity, Group A | €16,000 – €4,000,000 | €500 – €16,000 |
| Relevant public entity, Group B | €8,000 – €350,000 | €500 – €16,000 |
Contraordenações graves — Article 62
Covers failure to identify yourself under Article 8, breaches of the binding orders, warnings and instructions of the competent authority, violation of a suspension, and failure to comply with an immediate execution measure.
| Entity | Legal person | Individual |
|---|---|---|
| Essential entity | €1,250 – €5,000,000, or 1% of worldwide annual turnover, whichever is higher | €250 – €125,000 |
| Important entity | €875 – €3,500,000, or a maximum not lower than 0.7% of worldwide annual turnover | €250 – €125,000 |
| Relevant public entity, Group A | €10,000 – €2,500,000 | €375 – €10,000 |
| Relevant public entity, Group B | €5,000 – €225,000 | €375 – €10,000 |
Contraordenações leves — Article 63
Confined to cybersecurity certification: using an invalid, expired or revoked certification mark, implying a certification that does not exist, withholding or falsifying information relevant to a certification process, or ignoring a request from the Comissão de Avaliação de Segurança do Ciberespaço.
- Legal person: €875 – €45,000
- Individual: €250 – €3,750
How to prepare for NIS2 in Portugal
- Register first, analyse second: the MyCiber deadline does not wait for your gap assessment, and registration is a self-declaration you can refine later. Sort out the Chave Móvel Digital or Cartão de Cidadão access and the proof of representation powers before you sit down to do it.
- Run a gap assessment against Annex III: the Quadro Nacional de Referência and the minimum measures in the Regulamento are the standard you will be held to, keyed to your conformity level. This is the work that needs the full run-up to June 2028.
- Build the asset list now: the Lista de Ativos is due by 31 January 2027 or six months after qualification, whichever comes first, and it is the input to everything else.
- Design one incident process, not five: the four-stage RJC clock has to coexist with GDPR notification to the CNPD and any criminal reporting. Article 40(7) allows simultaneous notification through MyCiber — use it.
- Manage supply-chain risk: review contracts with key ICT and service providers, adding explicit cybersecurity, audit and incident-notification clauses.
- Align with recognised frameworks: build or refine your ISMS using ISO/IEC 27001, NIST CSF or similar to structure your NIS2/RJC compliance programme.
- Engage leadership: brief the board and senior management on their new responsibilities and ensure cybersecurity is embedded in overall risk and business strategy.
Operating in more than one EU country?
If you are a DNS service provider, TLD name registry, cloud computing, data centre or content delivery network provider, a managed service or managed security service provider, or an online marketplace, search engine or social networking platform, you answer to the regulator where your main establishment sits — not to all 27. For most of those categories that means the member state where your cybersecurity risk-management decisions are predominantly taken. Registering with CNCS does not, by itself, settle the question.
For those same entity types, Implementing Regulation (EU) 2024/2690 sets the technical and methodological requirements directly. It is a regulation, not a directive, so it is not transposed and reads identically in Portugal, Spain and everywhere else. Where it applies, it — not the national annex — is the specification to build against.
Two national deltas worth checking if Portugal is one of several markets for you: the 75-employee public-sector floor has no counterpart elsewhere, and the 24-hour end-of-impact notification means a group-wide incident runbook written to the Directive's three-stage clock will be incomplete here. Compare with Spain, Italy, Germany and Belgium.
Official links & resources
FAQ: NIS2 in Portugal
Has Portugal fully transposed NIS2?
Who is the main NIS2 authority in Portugal?
By when must we register on MyCiber?
Do we need a specific certification like ISO 27001?
What are the actual fines?
Are the security measures enforceable yet?
Sources & verification
Every date, figure and fine range on this page was taken from the Portuguese gazette text or from CNCS directly. Law-firm summaries and NIS2 trackers were used to decide what to check, never as authority.
| Source | Used for | Checked |
|---|---|---|
| Decreto-Lei n.º 125/2025, DR 1.ª série n.º 234, 4 December 2025 — official gazette PDF | Entry into force (Article 11), repeals (Article 9), deferral (Article 10(2)), scope (Articles 6, 7, 9), qualification and registration (Article 8), authorities (Article 15), officer and contact point (Articles 31, 32), reporting (Articles 40–44), penalties (Articles 61–68) | 4 August 2026 |
| CNCS — Regulamento do Regime Jurídico da Cibersegurança | Regulamento n.º 756/2026, publication 22 June 2026, entry into force 23 June 2026, the four annexes, the consultation period, and the start of the 24-month clock | 4 August 2026 |
| CNCS — MyCiber, including the Calendário de obrigações | The 60 and 30 dias úteis registration deadlines, the 30 dias úteis qualification notice, the 20 dias úteis officer and contact-point deadline, the 31 January 2027 asset list, and the registration credentials | 4 August 2026 |
| European Commission — NIS2 implementation in Portugal | Infringement timeline: formal notice 28 November 2024, reasoned opinion 7 May 2025 | 4 August 2026 |
What this page deliberately does not state
- A single hard calendar date for the registration deadline. The rule is 60 dias úteis from the platform being made available. CNCS has published the rule but not the platform-availability date in writing, so the exact end date turns on a date the regulator has not fixed publicly. We say mid-September 2026 and explain why the August date circulating in English-language summaries — which reads "60 dias" as calendar days — is wrong. Your own MyCiber record is authoritative for your entity.
- An estimate of how many entities are in scope. A figure of around 9,000 circulates widely and previously appeared on this page. CNCS has not published a count, and we would rather print nothing than a number that gets quoted back to us.
- Any sectoral cybersecurity authority beyond ANACOM and the GNS. This page previously referred to "various regulators" for energy, finance, health and transport, and some third-party guides list ERSE, DGEG, IMT, ANAC, AMT and DGRM. Article 15 of the RJC names none of them. Banco de Portugal, the CMVM and the ASF appear only as special authorities for digital operational resilience in the financial sector. The claim has been removed rather than repeated.
- Any enforcement activity. No fines or supervisory actions under the RJC are documented as at the date above, which is unsurprising given the security measures do not take effect until 2028.
