Regulated Incident Management Ecosystem Versão portuguesa

Designated roles layer · Cybersecurity

The cybersecurity role, performed with a mandate and a method

Support for the person performing the cybersecurity role in organisations operating in Portugal, under the Portuguese Cybersecurity Act, including coordination with group functions based abroad.

DL 125/2025 NIS 2 Article 31 24 hours CNCS
CNCSNIS 2CRADORARGPDISO24 h72 h

The Act in figures

Three deadlines, a single clock

24 hearly warning after becoming aware of a significant incident
72 hincident notification, with an initial assessment
30 working daysfinal report on the incident
20 working dayscommunication of the officer appointment

Source: Decree-Law 125/2025, Articles 31 and 41 to 44. The actual counting depends on how the incident qualifies.

Scope

Obligations by category of entity

The substantive obligations are equivalent; what differs is supervision and the penalty framework.

CategoryWho it covers, as a ruleCore obligations
Essential entityHighly critical sectors, above the relevant sizeArticle 27 measures, notification under Articles 41 to 44, a designated officer and a permanent point of contact
Important entityOther critical sectors and smaller entities in the listed sectorsThe same substantive obligations, with different supervision and fines
Relevant public entityPublic administration entities under Articles 6 and 7Equivalent obligations, with regime-specific features

Summary of Articles 6, 7, 27, 31, 32 and 41 to 44 of Decree-Law 125/2025. It does not replace reading the act itself.

Open the scope checker

What we do

Services

CSO-01

External or Supporting Cybersecurity Officer

External performance of the cybersecurity role, or support to the designated officer, with an annual plan, evidence and reporting to the management body.

Open service sheet
CSO-02

Assessment of Scope under the Act

A reasoned determination of how the entity qualifies and of the resulting obligations, considering sector, size and services provided.

Open service sheet
CSO-03

Risk Management Measures Programme

Design and follow-up of the technical, operational and organisational measures required from covered entities, with evidence for each area.

Open service sheet
CSO-04

Notification Readiness and Coordination

Preparation of the incident communication sequence, from the early warning to the final report, with the legal deadlines and the parallel recipients.

Open service sheet
CSO-05

Governance and Management Bodies

Definition of the cybersecurity governance model and training of the management body on its own responsibilities.

Open service sheet
CSO-06

Product and Digital Supply Chain Security

Analysis of the duties applicable to products with digital elements and of the security requirements to impose on, and meet within, the supply chain.

Open service sheet
CSO-07

Exercises, Simulations and Team Capability

Design and delivery of exercises that test decision-making, communication and deadlines, with a lessons-learnt report.

Open service sheet
CSO-08

Career Path and Mentoring

Individual support for the person holding the role, with a competence plan, review of real cases and preparation for dealing with the authority.

Open service sheet

International groups

Local role, international decision

When the group cybersecurity function sits outside Portugal, the obligation is still owed here. The split of responsibilities has to be written down.

Who is appointed in Portugal

The appointment and the communication to the authority are acts of the Portuguese entity.

Who decides what

A decision matrix between headquarters and the local entity, including incident activation.

Who meets the deadlines

Portuguese deadlines run regardless of the time zone of headquarters.

An appointed role is not yet a role performed

Start by checking your organisation scope or ask for a proposal to structure the role.