NIS2 in Portugal: DL 125/2025, Regulamento 756/2026, and what to do now
Portugal's NIS2 regime is now complete: Decreto-Lei 125/2025 sets the law, Regulamento 756/2026 sets the mechanics — MyCiber registration, deadlines, and risk tiers.
NIS2 is a directive, which means it becomes real twenty-seven times — once per member state, each with its own authority, registration process, and reading of the details the directive left open. In Portugal that has now happened twice over: Decreto-Lei n.º 125/2025 created the legal regime, and on 23 June 2026 its implementing regulation — Regulamento n.º 756/2026 of the CNCS — made it operational. If your organisation operates in Portugal, these are the texts you actually comply with, and the deadlines are no longer abstract.
The stack, in three layers
The directive is the floor. Whether you are an essential or important entity still follows the directive’s sector lists (Annexes I and II) and size thresholds. The risk-management obligations of Art. 21 apply as written, and the incident clock is statutory across the EU: an early warning within 24 hours of becoming aware of a significant incident, a notification within 72 hours, and a final report within one month of the notification.
The decree-law names the institutions. DL 125/2025 makes the CNCS — Centro Nacional de Cibersegurança — the competent authority, routes incident notifications through the national channel to the CNCS and its CSIRT, and carries the directive’s Art. 20 duties through into Portuguese law: management approves the risk-management measures, oversees their implementation, and undergoes training. That clause is what moves NIS2 from the security team’s backlog to the board agenda.
The regulation sets the mechanics. Regulamento 756/2026 is where obligations become dates and forms:
- Registration runs on MyCiber, the CNCS platform live since 23 June 2026. Entities already operating have 60 business days from that date to self-identify and register — a window that closes in September 2026. Entities starting activity later have 30 days from the start.
- Your risk tier determines your obligations. The regulation classifies entities into three tiers — básico, substancial, elevado — and each tier maps to a minimum set of security measures drawn from the national cybersecurity reference framework (QNRCS). Classification is not a formality: it decides the size of your compliance surface.
- Notifications go through the platform. The statutory clock stays the directive’s; the regulation determines where and how the reports land.
- Registration also involves designating your point of contact — the exact designation windows have moved with the platform’s availability, so confirm the current deadline against the published text or with counsel when you register.
What to do, in order
- Classify — determine whether you’re essential or important, and which risk tier the regulation puts you in. Document the reasoning; you’ll need it for registration and any supervisory conversation.
- Register on MyCiber before the window closes — for entities already operating, that means September 2026. Keep a record of what you filed.
- Map your measures to your tier — the QNRCS minimum set for your tier is the checklist a supervisor will reach for first.
- Prepare the clock before you need it — an incident workflow with the 24-hour, 72-hour and one-month checkpoints built in, and reports in the shape the authority expects. The worst time to design a notification process is hour three of an incident.
- Put Art. 20 on the board agenda — measures approved, training done, both documented.
How Cautera encodes this
The Portuguese transposition is built into the platform, not left as a footnote: a CNCS registration checklist that produces a PDF summary of what you filed, CSIRT-ready incident reports at each statutory checkpoint, Art. 20 management-duty tracking, and deadline reminders that count from the moment of detection. The classification wizard runs on the directive’s criteria and produces the applicability report registration asks for.
See the NIS2 module, including the Portugal transposition, in a live workspace: Cautera’s NIS2 page.