Portugal completed its NIS2 transposition on 3 April 2026. The Regime Jurídico da Cibersegurança (RJC), approved by Decreto-Lei n.º 125/2025, de 4 de dezembro, transposes Directive (EU) 2022/2555 and, by its own Article 9(b), repeals the predecessor Regime Jurídico da Segurança do Ciberespaço (RJSC), approved by Lei n.º 46/2018, de 13 de agosto, which had transposed the original NIS Directive.
Decreto-Lei n.º 125/2025 was approved by the Council of Ministers on 5 November 2025, promulgated on 28 November 2025, published on 4 December 2025, and entered into force 120 days later, on 3 April 2026 (Article 11), so it now binds.
The RJC reaches 17 sectors plus a significant part of the Administração Pública, expanding well beyond the critical-infrastructure sectors the RJSC already covered to add IT service management, wastewater, space, manufacturing, postal and courier services, waste management, chemical production, food production and distribution, digital-service provision and research; it excludes national-security, public-security, defence and intelligence-service entities from its scope (Articles 2 and 6).
It classifies an entity as essential or important by sector type (Annexes I and II) and by whether it exceeds the EU medium-enterprise thresholds of Commission Recommendation 2003/361/EC, though a qualified trust service provider, a top-level-domain name registry and a DNS service provider are essential regardless of size (Article 6).
Annex II's digital-services sector names an online marketplace provider, an online search engine provider and a social-networking-services-platform provider expressly; Annex I's digital-infrastructure sector separately and expressly names a cloud-computing-service provider, a data-centre-service provider, a content-delivery-network provider, a trust-service provider and a top-level-domain registry, each reached at the medium-enterprise size threshold or above except the categories the Act designates as essential regardless of size.
The wider sector classes the RJC designates (energy, transport, banking, health, drinking water, public administration and the rest of the Annexes) are a designation and sector class no activity in this vocabulary expresses, so only the digital-provider slice is flagged here.
No Portuguese instrument reviewed here imposes a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here; the CNCS's own certification framework, the Quadro Nacional de Certificação da Cibersegurança, is a voluntary scheme under Regulation (EU) 2019/881 rather than a market-placement duty.
Portugal has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and Lei n.º 58/2019's breach-notification duties to the Comissão Nacional de Proteção de Dados (CNPD), both of which sit in the privacy topic rather than here.
The electronic qualification platform through which a covered entity registers (Article 8(7)) awaits its own CNCS regulation and was not yet available as of the CNCS's own 23 July 2026 update to its RJC guidance page, so the registration mechanics, though not the substantive Article 26 to 29 and Article 40 to 44 duties themselves, remain unsettled.