NIS2 in Portugal
What binds you in Portugal is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.
Reviewed . Verify against the national official journal before relying on this for a filing.
National transposition
Decreto-Lei n.º 125/2025 — Regime Jurídico da Cibersegurança
Published on 4 December 2025 and in force from 3 April 2026. It consolidates the Centro Nacional de Cibersegurança (CNCS) as the national cybersecurity authority.
Quadro Nacional de Referência para a Cibersegurança — QNRCS, with certification scheme EC QNRCS
referenced by Regulamento n.º 756/2026 of 22 June 2026, published by CNCS — Centro Nacional de Cibersegurança. Built on NIST Cybersecurity Framework — the five functions Identify, Protect, Detect, Respond, Recover.
Portugal is the second member state with a genuinely certifiable national framework, after Belgium: the QNRCS has an accredited certification scheme (EC QNRCS). Its structure is the five NIST CSF functions with three capability levels per measure, so an organisation already working to CSF will recognise the shape. Adoption is voluntary and a QNRCS certificate is not a NIS2 compliance certificate. Regulamento n.º 756/2026, published 22 June 2026, is what gave the QNRCS legal weight: it sets the conformity levels required of entities and the minimum security measures that become mandatory — read it alongside the decree-law.
A label is not compliance
Adoption of the QNRCS itself is voluntary and a QNRCS certificate is not a NIS2 compliance certificate. Your obligations come from Decreto-Lei n.º 125/2025 and the CNCS regulation; the QNRCS is the reference against which conformity levels are expressed.
QNRCS in full — levels, controls and what it does not cover →
Who supervises you
CNCS is the competent authority designated by Portugal. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.
Incident notifications under article 23 normally go to CERT.PT, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.
What differs from the directive
Because NIS2 is a directive, Portugal legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:
- Registration. The portal, the information required and the deadline are national.
- Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
- Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
- Reporting format. Deadlines are fixed by the directive; the form and the language are national.
If you operate in several member states
You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.