info@goldenblatt.co.uk
49 Russell Square, London, UK

Flash AlertNews & MediaPortugal Passes NIS2 Transposition

25 de September, 2025

 

The Portuguese Parliament has approved the transposition of the European NIS2 Directive, marking a turning point in national digital security.

The bill still awaits presidential promulgation and publication in the Official Gazette, after which the new cybersecurity rules will become mandatory.

What changes in practice:

Broader scope
The bill now covers sectors such as energy, transport, banking, financial infrastructures, healthcare, water supply, public administration, the space sector, and digital infrastructures.

Digital service providers
Also included are providers of cloud services, data centers, content delivery networks (CDNs), DNS services, online marketplaces, search engines, and social media platforms.

Personal liability – Executives and directors may now be held personally liable for non-compliance — a clear sign that cybersecurity has moved up to the C-level agenda.

Mandatory CISO role – Appointment of a Chief Information Security Officer (or equivalent) as the compliance guarantor and responsible for implementing security measures.

Strict incident reporting deadlines

  • 24h: initial alert

  • 72h: detailed report

  • 30 days: final assessment

Sanctions for non-compliance
Fines up to €10M or 2% of global turnover.

Coordinated oversight
The National Cybersecurity Center (CNCS) leads, with specialized support from the Bank of Portugal, CMVM, ASF, and ANACOM.

The message is clear:
Cybersecurity is no longer a “nice to have” — it is now a strategic and legal obligation.

For companies in the covered sectors — including many tech firms and digital providers — this is the moment to assess the maturity of your cybersecurity programs.

by Joana Pinto e Ana Bastos, Practice Area – TMT – Technology, Media & Telecommunications

https://adcecija.pt/wp-content/uploads/2020/06/logo_horizontal_b-768x75.png
LISBOA
Edifício Amoreiras Square
Rua Carlos Alberto da Mota Pinto, 17 - 2.º piso
1070-313 Lisboa
PORTO
Rua Eugénio de Castro, n.º 352, 2.º andar, sala 26
4100-225 Porto
BRAGA
Rua de Janes, n.º 20, 1.º andar, sala 101
4700-318 Braga

* Chamadas sem custos adicionais, sujeito apenas à tarifa de base.

SOCIAL