Introduction
Portugal transposed NIS2 into national law through Decreto-Lei 125/2025, giving the Centro Nacional de Cibersegurança its supervisory mandate over essential and important entities. Transposition was the easy part. The harder, more consequential phase is the one now underway across the EU's more mature enforcement jurisdictions: supervisors actually opening audits against organizations that assumed a signed policy document was sufficient. Portuguese organizations should expect CNCS's audit programme to follow the same pattern already visible in Germany and elsewhere - not a search for missing paperwork, but a search for evidence that documented controls are actually operating.
What Portuguese Organizations Can Learn From Earlier Movers
Germany and France are further along in NIS2 supervisory activity, and the pattern from both jurisdictions is consistent: audits are not primarily flagging organizations with no security policy at all. They are flagging organizations whose policy exists but cannot be evidenced - an incident response plan that has never been tested, a risk assessment that was completed once and never updated, a supply-chain review that lives as a static document rather than a continuously maintained record. For Portuguese essential and important entities, the practical lesson from these earlier jurisdictions is to close that specific gap now, before CNCS reaches them, rather than discover it during an active audit.
The Ten Article 21 Measures CNCS Will Test Against
- Risk analysis and information system security policies
- Incident handling procedures
- Business continuity and crisis management, including backup and disaster recovery
- Supply chain security, including relationships with direct suppliers and service providers
- Security in network and information systems acquisition, development, and maintenance
- Policies and procedures to assess the effectiveness of risk management measures
- Basic cyber hygiene practices and security training
- Cryptography and encryption policies where appropriate
- Human resources security, access control policies, and asset management
- Use of multi-factor authentication, secured communications, and secured emergency communication systems where appropriate
Why 'we have a policy for that' won't be sufficient
Every one of the ten measures above can be satisfied on paper with a written policy. CNCS's audit, like its counterparts elsewhere in the EU, will be testing for operational evidence behind each one: proof that backups are tested, not merely scheduled; proof that supply-chain risk assessments were updated when vendor relationships changed, not written once at onboarding; proof that access control policies reflect who currently has access, not who had access when the policy was drafted. Organizations that can produce this evidence on demand, continuously, are in a fundamentally different position during an audit than those reconstructing it under time pressure once CNCS makes contact.
As CNCS's supervisory programme matures, the organizations best positioned are the ones that can already prove their controls are working, not just describe them. See how ROOTKey gives Portuguese organizations continuous, audit-ready NIS2 evidence.
在邮箱中获取网络韧性洞见
关于数据完整性、合规与连续性的实用、可审计指南--发布即送达。





