Overview

The diploma and the attached scheme are not the same layer.

The 11 articles of the Decree-Law approve the RJCS, amend other diplomas, establish transition, repeals, take effect and enter into force. The material regime is in the annex.

Publication
4 December 2025
Entry into force
3 April 2026
Diploma
11 articles
RJCS Annex
87 Articles
Structure
9 chapters and 3 annexes

Operational Reading

The articles that change the organization.

A selection for initial guidance — does not replace reading the other articles.

Article 8

Autoidentification

Entities already active are identified within 60 days of the availability of the platform; new entities within 30 days of the start of the activity.

The count depends on the availability of the platform and the applicable framework. View operational tutorial
Article 25

Management responsibility

Management bodies shall adopt and supervise measures, ensure supervision and enforcement measures and promote regular training.

The necessary responsibility and powers are not freely delegable. View operational tutorial
Articles 26 to 29

Risk and measures

The scheme requires a systemic risk-proportional approach complemented by residual risk analysis and management.

Compliance with minimum measures does not eliminate the obligation to treat residual risks. View operational tutorial
Article 30

Annual report

Key and important entities draw up and maintain annual reports; communication varies according to qualification.

There are specific rules for the first report and subsequent reports. View operational tutorial
Articles 31 and 32

Responsible and contact point

Key and important entities designate cybersecurity officer and ensure permanent contact point.

The diploma provides for communications within 20 working days in the relevant cases. View operational tutorial
Articles 40 to 44

Notification of incidents

Significant incidents follow an initial notification sequence, significant impact end and final report.

The deadlines depend on the verification, evolution and end of the significant impact. View operational tutorial

Significant incidents

A sequence, not a single notification.

The deadlines count from different events. The organization needs detection, decision, time record and coordination.

  1. Up to 24 hours
    Article 42

    Initial notification after the entity has concluded that there is or may be a significant incident, except incompatibility with mitigation or resolution.

  2. Up to 72 hours
    Article 42

    Updating of the initial notification, where necessary, with initial assessment, severity, impact and indicators available.

  3. Up to 24 hours after the end of impact
    Article 43

    Notification of the end of significant impact.

  4. 30 business days
    Article 44

    Final report of the notification of the end of significant impact.

First layer

The 11 articles of the Decree-Law.

  1. Article 1 — Subject matter
  2. Article 2 — Legal regime for cybersecurity
  3. Article 3 — Amendment to Law No 53/2008 of 29 August
  4. Article 4 — Amendment to Law No 109/2009 of 15 September 2009
  5. Article 5 — Amendment to Law No 16/2022 of 16 August
  6. Article 6 — Addition to Law 53/2008 of 29 August
  7. Article 7 — Addition to Law No 109/2009 of 15 September
  8. Article 8 — Transitional rules
  9. Article 9 — Repealing rules
  10. Article 10 — Taking effect
  11. Article 11 — Entry into force

Scheme approved in Annex

87 articles, organized into nine chapters.

Open each chapter to consult all the official titles of the articles. This structure will be the basis of the explanations article by article.

Chapter I General provisions Articles 1 to 10
  1. Article 1 — Subject matter
  2. Article 2 — Definitions
  3. Article 3 — Subjective scope
  4. Article 4 — Territorial delimitation of the subjective scope
  5. Article 5 — Extraterritorial scope
  6. Article 6 — Key entities and important entities
  7. Article 7. — Relevant public entities
  8. Article 8 — Procedure for the qualification of entities
  9. Article 9 — Competition for qualifications and cybersecurity measures
  10. Article 10 — Processing of personal data
Chapter II Structured instruments Articles 11 to 14
  1. Article 11. — Structured Cyberspace Security Instruments
  2. Article 12th — National Cyberspace Security Strategy
  3. Article 13th — National plan to respond to large-scale cybersecurity crises and incidents
  4. Article 14th — National Cybersecurity Reference Framework
Chapter III Organization of cyberspace security Articles 15 to 24
  1. Article 15 — Organization
  2. Article 16. Superior Cyberspace Security Council
  3. Article 17 — Competences of the Superior Cyberspace Security Council
  4. Article 18th — Cyberspace Security Assessment Commission
  5. Article 19th — National Cybersecurity Centre
  6. Article 20 — Powers of the National Cybersecurity Centre
  7. Article 21. — Cybersecurity crisis management authority
  8. Article 22nd — Cybersecurity Incident Response Team
  9. Article 23 — Cooperation between national authorities
  10. Article 24 — Cooperation with the private sector
Chapter IV Risk management and other duties Articles 25 to 37
  1. Article 25 — Obligations of management, management and administration bodies
  2. Article 26 — Cybersecurity risk management system
  3. Article 27 — Cybersecurity measures
  4. Article 28th — Supply chain
  5. Article 29 — Residual risk management
  6. Article 30 — Annual report
  7. Article 31 — Cybersecurity Officer (RCS)
  8. Article 32 — Permanent contact point
  9. Article 33 — Measures applicable to relevant public entities
  10. Article 34 — Certification of cybersecurity
  11. Article 35 — Registration obligation
  12. Article 36 — Domain name registration database
  13. Article 37 — Access to domain name registration
Chapter V Vulnerability and incidents Articles 38 to 52
  1. Article 38 — Vulnerability in information systems
  2. Article 39 — Communication of vulnerabilities
  3. Article 40 — Compulsory notification
  4. Article 41 — Types of notifications
  5. Article 42 — Initial notification
  6. Article 43 — Notification of significant impact end
  7. Article 44 — Final and interim reports
  8. Article 45 — Voluntary notifications of relevant information
  9. Article 46 — Requests for information
  10. Artigo Article 47
  11. Article 48 — Communication to the addressees of the services
  12. Article 49 — Communication between authorities
  13. Article 50 — Communication to entities within the European Union or its Member States
  14. Article 51 — Information to the public
  15. Article 52 — Response to notifications
Chapter VI Supervision and enforcement Articles 53 to 60
  1. Article 53 — Principles
  2. Article 54 — Supervisory measures concerning essential entities
  3. Article 55 — Supervisory measures for relevant important and public entities
  4. Article 56 — Implementing measures
  5. Article 57 — Blocking and redirecting measures
  6. Article 58 — Procedural guarantees
  7. Article 59 — Reporting of incidents and implementing measures
  8. Article 60 — Cooperation in the field of critical infrastructure security
Chapter VII Penalty regime Articles 61 to 81
  1. Article 61 — Very serious counter-ordinations
  2. Article 62 — Serious counter-ordinations
  3. Article 63 — Mild counter-ordinations
  4. Article 64 — Negligence
  5. Article 65 — Exemption from fines
  6. Article 66 — Determination of the fine
  7. Article 67 — ancillary penalties and other determinations
  8. Article 68 — Compulsory sanctions
  9. Article 69 — Prescription of the procedure
  10. Article 70 — Prescription of the fine and ancillary penalties
  11. Article 71 — Rule of jurisdiction of the competent authorities
  12. Article 72 — Notifications
  13. Article 73 — Product of fines
  14. Article 74 — Costs
  15. Article 75 — Compliance with omitted duty
  16. Article 76 — Suspension of the fine
  17. Article 77 — Repeal of suspension of the fine
  18. Article 78 — Extinction of the fine
  19. Article 79 — Violation of personal data
  20. Article 80 — Impugnation of decisions of the competent cybersecurity authority
  21. Article 81 — Subsidiary law
Chapter VIII Additional provisions Articles 82 to 84
  1. Article 82 — Supervisory fee
  2. Article 83 — Communications
  3. Article 84 — Information security and integrity
Chapter IX Final provisions Articles 85 to 87
  1. Article 85 — Approval of the national large-scale cybersecurity crisis and incident response plan
  2. Article 86 — Provision of means and operational independence of the CNCS
  3. Article 87 — Interoperability and access to information

Scope and dimension

Three essential annexes to the framework.

Frequently Asked Questions

Read without oversimplifying.

Does the diploma have only 11 articles?

The legislative act has 11 articles, but it approves in an annex the Legal System for Cybersecurity, which contains 87 articles, nine chapters and three annexes.

Does entry into force mean that all obligations took effect on the same date?

Not necessarily. Article 10 contains specific rules for the production of effects for certain provisions linked to the publication of the rules laid down in the scheme.

Are the minimum measures sufficient in itself?

No. Articles 26 and 29 require risk analysis and management, including residual risks, and appropriate and proportionate measures to the entity’s context.

Do all entities concerned have the same obligations?

No. The qualification, type of entity, group, risk matrix and level of compliance influence the specifically applicable obligations.

Primary source

Always confirm in the official act.

Informational content published on .

Practical implementation

What's the next step in your organization?

The right article depends first on the framework, qualification and real state of the organization.

Identify priorities