Regulated Incident Management Ecosystem Versão portuguesa

Cybersecurity Officer

Framework

A regime that sets the required outcome and standards that supply the method.

National regime

One regime, one role

Decree-Law 125/2025 enacted the Portuguese Cybersecurity Act, transposing Directive (EU) 2022/2555. Besides risk management measures and notification duties, it creates two distinct roles: the cybersecurity officer, under Article 31, and the permanent point of contact, under Article 32.

The appointment is communicated to the authority within the period set in that article, and the duties assigned to the officer include advising, monitoring the measures and acting as interlocutor with the National Cybersecurity Centre. This website deals with performing those duties; the duty to appoint, the deadlines and the consequences of failure are covered in detail on the dedicated website.

Where each matter lives

Appointment duties and deadlines at responsaveldeciberseguranca.pt; permanent point of contact at pontodecontacto.pt; incident notification at incidentesdeciberseguranca.pt.

Instruments

European layer

InstrumentSubjectRelevance to the role
Diretiva (UE) 2022/2555 (NIS 2)Common level of cybersecurity across the UnionSource of the Portuguese regime and an aid to interpretation
Regulamento (UE) 2024/2847Products with digital elementsVulnerability and incident reporting duties, applicable since 11 September 2026
Regulamento (UE) 2022/2554 (DORA)Digital operational resilience in the financial sectorA sectoral regime that adds to the general framework
GDPR and Law 58/2019Personal data protectionOne incident may create duties towards both the CNCS and the CNPD

Standards

Technical layer

The Act sets the required outcome, not the method. The method comes from technical standards, in particular ISO/IEC 27001 and the National Cybersecurity Reference Framework of the CNCS, which turn the areas of measures into verifiable controls and organised evidence.

An appointed role is not yet a role performed

Start by checking your organisation scope or ask for a proposal to structure the role.