Introduction
Portugal transposed NIS2 into national law through Decreto-Lei 125/2025, giving the Centro Nacional de Cibersegurança its supervisory mandate over essential and important entities. Transposition was the easy part. The harder, more consequential phase is the one now underway across the EU's more mature enforcement jurisdictions: supervisors actually opening audits against organizations that assumed a signed policy document was sufficient. Portuguese organizations should expect CNCS's audit programme to follow the same pattern already visible in Germany and elsewhere - not a search for missing paperwork, but a search for evidence that documented controls are actually operating.
What Portuguese Organizations Can Learn From Earlier Movers
Germany and France are further along in NIS2 supervisory activity, and the pattern from both jurisdictions is consistent: audits are not primarily flagging organizations with no security policy at all. They are flagging organizations whose policy exists but cannot be evidenced - an incident response plan that has never been tested, a risk assessment that was completed once and never updated, a supply-chain review that lives as a static document rather than a continuously maintained record. For Portuguese essential and important entities, the practical lesson from these earlier jurisdictions is to close that specific gap now, before CNCS reaches them, rather than discover it during an active audit.
The Ten Article 21 Measures CNCS Will Test Against
- Risk analysis and information system security policies
- Incident handling procedures
- Business continuity and crisis management, including backup and disaster recovery
- Supply chain security, including relationships with direct suppliers and service providers
- Security in network and information systems acquisition, development, and maintenance





