A broader, operational framework

Decree-Law No. 125/2025 transposes the NIS2 Directive and approves, in an annex, Portugal's new Cybersecurity Legal Framework. Its scope is significantly broader, and requirements are graduated according to the entity's type, size, and importance.

The first task is not to buy technology. It is to determine the applicable framework, document the criteria used, and prepare the information required for self-identification.

Management now has a verifiable role

Management bodies approve and oversee cybersecurity risk-management measures, ensure their implementation, and promote regular training. Governance can no longer be reduced to an informal decision by the IT department.

Minutes, decisions, responsibilities, resources, reviews, and monitoring become part of the evidence that the organization is effectively directing risk.

Minimum measures do not replace risk assessment

The framework combines applicable standards and measures with residual-risk assessment. Even when an entity applies the minimum measures associated with its level, it still needs to assess whether additional risks require treatment.

Inventory, criticality, dependencies, scenarios, treatment decisions, and reasoned acceptance should form a continuous process.

People and permanent channels

Where applicable, the framework provides for the appointment of a Cybersecurity Officer and a permanent contact point. These are not merely names on a form: they need authority, availability, replacement arrangements, and integration into decision-making and response processes.

Incidents with deadlines and sequence

Significant incidents follow a communication sequence that tracks verification, impact, and closure. To comply, the organization needs detection, classification, escalation, decisions, and fact collection before a crisis occurs.

The legal clock does not wait for the team to improvise a procedure.

The decisive question

Maturity is no longer simply, “Do we have a policy?” It becomes, “Can we demonstrate that the policy is applied, reviewed, and effective?” The difference lies in evidence connected to owners, dates, decisions, and outcomes.

This article is explanatory and does not replace reading the legislation or assessing the specific applicable framework.