DataRoad · IT Services and Consultancy![]()
NIS2 in Portugal
Who is covered?
There is a deadline for registration on MyCiber, which ends in mid-September 2026.
Decree-Law 125/2025 is now in force; fines can reach 10 million euros and the legislation holds management personally liable. Find out who is covered, what you need to do and by when.
Request a NIS2 assessment
NIS2 in Portugal: is your company covered?
Decree-Law No. 125/2025 has been in force since 4 May 2026, and the CNCS MyCiber platform was launched on 23 June. Entities already trading have 60 working days to identify and register themselves — the deadline is in mid-September 2026. Failure to register is an offence in its own right.
What you need to do, and by when
- Already in forceCybersecurity Legal FrameworkDecree-Law No. 125/2025 of 4 December came into force on 4 May 2026. Regulation No. 756/2026 of 22 June sets out how it works in practice.
- ~15 September 2026Self-identification and registration on MyCiber60 working days from 23 June, the date on which the CNCS platform became available. Entities that commenced trading at a later date have 30 working days. Failure to meet this deadline is, in itself, an offence.
- 20 days after classificationCybersecurity officer and point of contactOnce the CNCS has confirmed your organisation’s classification, you must specify who is responsible for cybersecurity and appoint a permanent point of contact.
- 31 January 2027Asset inventoryOr six months after the final classification notice, whichever comes first.
- June 2028Minimum measures and annual reportYou have two years to implement the security measures for your assigned level and to submit the first report.
Fines reach 10 million euros or 2% of global turnover for essential entities, and 7 million or 1.4% for important entities. The framework also holds management bodies directly accountable.
What DataRoad does — and what it does not do
We are not lawyers and we do not carry out registration on your behalf: the self-assessment and the MyCiber submission are carried out by the organisation itself. What we do is everything that comes afterwards, which is where the real work lies.
- Asset inventoryA comprehensive survey of servers, workstations, network equipment, cloud services and access rights — the document required by the framework by January 2027, which almost nobody has prepared.
- Minimum requirements for your levelImplementation and documented evidence: access control, encryption, network segmentation, firewalls, endpoint protection, tested backups and patch management.
- Detection and logging24/7 monitoring with retained logs. Without it, there is no way to meet the 24-hour notification requirement, because you would not even know that an incident had occurred.
- Incident responseA written procedure, named individuals and a rehearsal. When this happens, the 24-hour clock is already ticking.
- Continuity and recoveryBackups that have been tested and defined recovery times — not a promise that copies exist somewhere.
- Training for staff and managementThe framework holds management bodies accountable. Short sessions and phishing simulations, with a record of who took part.
Frequently asked questions about NIS2
Is my company covered by NIS2?
As a rule, medium-sized and large organisations in the sectors listed in the framework fall within the scope — energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration, postal services, waste, chemicals, food, manufacturing and research, amongst others. There are cases where size is irrelevant and the organisation falls within the scope regardless. The official determination is made through self-assessment on the MyCiber platform, and the responsibility for that assessment lies with the organisation itself — not with the CNCS.
What if my company is not covered?
You are still affected, via the supply chain. Entities within the scope of the regulation are required to manage the risk posed by their suppliers, which involves security questionnaires, contractual requirements and, increasingly, documented evidence. If you sell to hospitals, banks, the energy sector, public administration or industry, NIS2 will affect you through your customers.
What are the fines?
For essential entities, up to 10 million euros or 2% of global annual turnover, whichever is higher. For important entities, up to 7 million euros or 1.4%. In addition, the framework holds management bodies directly accountable.
How long do I have to report an incident?
An early warning within 24 hours, a notification with an assessment within 72 hours and a final report within 30 days. In practice, this means you need detection and logging — without monitoring, there is no way to meet the 24-hour deadline, because you would never notice the incident in the first place.
What technical measures are required?
The framework defines three levels — basic, substantial and high — with 39, 75 and 91 measures, assigned according to the organisation’s risk profile. The methodology is based on the Portuguese National Cybersecurity Reference Framework, which is aligned with NIST CSF 2.0.
Does DataRoad handle the registration for us?
Registration and self-assessment are carried out by the organisation itself, and nobody can do them on your behalf — we guide you and prepare the information, but it is up to you to submit it. What we do manage from start to finish is the technical side: asset inventory, security measures, monitoring, logging and the ability to respond to an incident within the specified timeframes.
This page is for information purposes only and does not constitute legal advice. How your entity is classified is determined by the self-assessment on the CNCS MyCiber platform.
Latest News
Our projects
How we help companies comply with NIS2 on time.
Hassle-Free NIS2 Compliance Diagnosis, plan and monitoring to comply with Decree-Law 125/2025 on time — without surprises.
Ouro Rossio Hotel: 30 Wi-Fi access points, 55 rooms and a firewall
DataRoad has installed 30 Wi-Fi hotspots, 55 CCTV cameras and a firewall at the Ouro Rossio Hotel in Lisbon. Take a look at the project and request a quote.
IT Unlimited: unlimited IT support for businesses
Unlimited, proactive IT support for businesses that can’t afford to stop. Find out more about DataRoad’s IT Unlimited and request a quote.
Lambert Clinic: IT Unlimited at the new Corroios branch
The Lambert Clinic has opened its Corroios branch and has once again chosen DataRoad to provide its full IT support. Read the case study.
Harlan & Poston Group: IT Unlimited in Portugal and the UK
The Harlan & Poston Group has chosen DataRoad for its IT Unlimited support contract. Find out what’s included.
Clínica Mulher: 192 network access points, Wi-Fi 7 and a firewall
A complete network comprising 192 access points, Wi-Fi 7, a firewall and IT Unlimited at the new Clínica Mulher in Sete Rios. View the project.
IT Unlimited IT support for businesses
Comprehensive maintenance, certified support and round-the-clock assistance for your company’s IT infrastructure. Find out what’s included in IT Unlimited.
Some of the companies that entrust their infrastructure to DataRoad, sectors where downtime costs much more than IT support























































































































































































