← Back to blog

NIS2 in Portugal: what changes for your company

Illuminated electronic circuit representing cybersecurity and digital infrastructure

If you think cybersecurity is a topic that only concerns large companies with IT departments the size of a football pitch, I have bad news. From 3 April 2026, things change. And they change for real.

Portugal has finally transposed the European Union's NIS2 Directive into national law through Decree-Law no. 125/2025. Translated into plain language: there's now a cybersecurity legal regime that forces a huge number of companies to take digital security seriously. Not as a nice-to-have. As a legal obligation, with fines that can reach 10 million euros.

Yes, you read that right. Ten million.

So what exactly is NIS2?

NIS2 (Directive (EU) 2022/2555) is the second version of the European directive on the security of network and information systems. The first version, from 2016, was limited. It covered few sectors, had weak enforcement and each country implemented it however it pleased. The result? A Europe full of cybersecurity gaps, with attacks on critical infrastructure multiplying year after year.

NIS2 was brought in to fix that. More sectors covered, more obligations, more enforcement and, of course, fines that hurt. The idea is simple: if your company is relevant to the economy or to society, you have to protect your systems. Full stop.

Is your company in scope?

This is the question everyone asks. The answer depends on two things: the sector you operate in and the size of your organisation.

The law splits entities into two categories. Essential entities are companies with 250 or more employees, or with turnover above 50 million euros, that operate in high-criticality sectors. Important entities are companies with at least 50 employees or turnover above 10 million euros, in sectors considered critical.

There are 18 sectors covered in total. The high-criticality ones include energy, transport, banking, healthcare, water, digital infrastructure, public administration and even space. The sectors considered important include postal services, waste management, the chemical industry, food, manufacturing, digital service providers and research.

If you run a software company with more than 50 people that provides services to clients in healthcare or energy, for example, this is for you. If you run a food production company with 60 employees, this is for you. If you manage cloud infrastructure or a data centre, this is definitely for you.

Watch out for the exceptions

Even if your company has fewer than 50 employees, you may still be in scope if you are a qualified trust service provider, a domain name registry, an electronic communications network provider, or if your activity has a significant systemic impact. When in doubt, check.

What you actually have to do

Let's get to the point. The law requires ten minimum cybersecurity risk-management measures. These aren't suggestions, they are requirements:

Security policies. You must have a documented and implemented information systems risk analysis and security policy. A forgotten PDF in a SharePoint folder won't cut it.

Incident management. You need clear procedures to detect, report and respond to security incidents. And when I say report, I mean it: you have 24 hours to send an initial alert to the CNCS, 72 hours for a detailed notification, and 30 working days for the final report.

Business continuity. Backups, disaster recovery, crisis management. If your main server goes down tomorrow, what's the plan? If you don't have an answer, you have a problem.

Supply chain security. This is new and important. You have to assess the security risks of your suppliers and service providers. That IT partner who sets up your servers? You need to know how they handle security.

Secure acquisition and development. If you develop software or buy systems, security must be built into the process from the start. Vulnerability management included.

Training and digital hygiene. Your team needs cybersecurity training. Yes, including the CEO. Especially the CEO, in fact, because management bodies are personally liable.

Cryptography and authentication. Policies on the use of cryptography and encryption. Multi-factor authentication. Secure communications. The basics that many companies still don't get right.

The deadlines you can't ignore

The law comes into force on 3 April 2026. Not in five years. Now.

You have 20 working days after it comes into force to appoint a cybersecurity officer and designate a permanent point of contact available 24/7. In other words, by 4 May 2026, you must have someone appointed.

After that, once the CNCS (National Cybersecurity Centre) launches the registration platform, you have 60 days to self-identify and register. New entities created after that point have 30 days.

The CNCS is your point of contact

The National Cybersecurity Centre (Centro Nacional de Cibersegurança) is the competent authority in Portugal for everything NIS2-related. They're who you report incidents to, who you register with, and they're the ones who carry out inspections and apply sanctions. Keep an eye on the official site at cncs.gov.pt.

The fines that hurt

Let's be blunt. If you're an essential entity and you don't comply, the fine can reach 10 million euros or 2% of annual global turnover, whichever is higher. If you're an important entity, the maximum is 7 million euros or 1.4% of turnover.

But it's not just fines. The CNCS can issue warnings, order compliance audits, suspend certifications or licences, and even order the temporary suspension of activities. And here comes the point that makes many boards lose sleep: management bodies are personally liable. They can be temporarily barred from holding leadership positions.

This isn't meant to scare you. It's to make clear that cybersecurity is no longer a technical issue. It's a management, governance and personal-responsibility issue.

Why Portugal arrived late

Let's put this in context. The EU set 17 October 2024 as the deadline for member states to transpose the directive. Portugal missed it. The European Commission opened infringement proceedings and issued a reasoned opinion in May 2025. The decree-law was eventually published in December 2025 and only comes into force in April 2026.

This means we spent more than a year in limbo. Many companies put the matter on the back burner because they figured "since Portugal hasn't transposed it yet, it's not urgent." The problem is that now it is urgent, and the time to get ready is short.

What you should do now

If you've read this far and reckon your company might be in scope, here's what I recommend:

First, do an applicability assessment. Confirm whether your sector and size put you within the scope of NIS2. Don't guess, analyse.

Second, do a risk assessment. Identify where the vulnerabilities are in your systems, processes and supply chain. This isn't done in-house by the IT intern. You need specialists.

Third, implement the measures. Security policies, incident management, business continuity, training. Everything the law requires. Document everything.

Fourth, set up the governance. Appoint the cybersecurity officer, train the management bodies, establish the 24/7 point of contact.

Fifth, don't do this alone. Cybersecurity is a specialist area. Work with partners who know the subject, who have experience with compliance frameworks and who can support you through the operational side. At Sparksoft, we work with partners specialised in security and compliance who help us make sure that both we and our clients are ready for these requirements.

Training is mandatory, not optional

NIS2 explicitly requires management bodies to undergo regular cybersecurity training. It's not enough to delegate to the IT department. If you're CEO, CFO or a board member, you have to understand the risks and approve the measures. It's the law.

This isn't just another European law

It's easy to look at NIS2 as just another layer of bureaucracy. Another regulation to comply with, another cost, another headache. But think about this: in 2024, the CNCS recorded a significant increase in cyberattacks in Portugal, with incidents affecting hospitals, municipalities and companies of all sizes. Ransomware doesn't distinguish between big and small companies. Supply chain attacks hit those who least expect it.

NIS2 isn't perfect. No legislation is. But it forces organisations to do the minimum. And the minimum, in this case, is to have policies, processes, training and response capability. Things any serious company should have regardless of the legal obligation.

The real risk isn't the fine. The real risk is the attack that shuts your business down for two weeks, that exposes your customers' data, that destroys the trust you took years to build.

So what now?

If you need help understanding how NIS2 applies to your case, or if you want to prepare your company before the deadlines close in, get in touch. We have partners specialised in cybersecurity, compliance and training who can make the difference between being prepared and being caught off guard.

Need help with NIS2?

We have partners specialised in cybersecurity and compliance who can help you get your company ready. No complications, no jargon. Let's have a conversation.

Talk to Sparksoft

Need help with your project?

Sparksoft helps companies turn ideas into digital products. Let's talk about your next step.

Get in Touch