Portugal Has Its Own NIS2 Law Now. Are You Ready?
Portugal transposed the EU NIS2 Directive into national law through Decreto-Lei 125/2025, published in late 2025. Like the NIS2 Directive itself, the Portuguese transposition establishes cybersecurity obligations for essential and important entities operating in Portugal.
The Portuguese implementation follows the NIS2 framework closely but includes national-level specifics: the designated national authority (CNCS - Centro Nacional de Cibersegurança), sector-specific supervisory arrangements, and national registration requirements that go beyond what the Directive itself mandates.
For Portuguese organisations that were already working toward NIS2 compliance based on the EU Directive text, the national transposition changes some timelines and adds administrative requirements. For organisations that had not yet started, the national law removes any ambiguity about whether and when obligations apply.
This post covers what the Portuguese transposition requires, how it differs from the base Directive, and what practical steps Portuguese organisations must take now.
Who Is Covered Under the Portuguese Transposition
The Portuguese NIS2 transposition covers the same sectors as the EU Directive, with the essential/important entity classification:
Essential entities (stricter obligations, proactive supervision):
- Energy (electricity, oil, gas, district heating and cooling, hydrogen)
- Transport (air, rail, water, road)
- Banking and financial market infrastructure
- Healthcare (hospitals, laboratories, pharmaceutical manufacturers, medical device manufacturers)





