Regulated Incident Management Ecosystem Versão portuguesa

Service sheet CSO-01

External or Supporting Cybersecurity Officer

External performance of the cybersecurity role, or support to the designated officer, with an annual plan, evidence and reporting to the management body.

The problem it solves

The appointment is made, but the role is left without a mandate, without time and without resources. The officer holds it alongside other duties, has no budget and is only heard after the incident.

Who it is for

  • Essential and important entities whose role is still unstructured;
  • International groups with a subsidiary or infrastructure in Portugal;
  • Suppliers to covered entities facing contractual requirements.

Deliverables

  • Annual cybersecurity plan and responsibility map;
  • Evidence file organised by area of measures;
  • Periodic reporting to the management body;
  • Interface with the CNCS and with the supply chain.

Method

  1. 01

    Assess

    Scope, measures and gaps.

  2. 02

    Structure

    Mandate, resources and plan.

  3. 03

    Operate

    Advise, monitor and evidence.

  4. 04

    Report

    To the management body and the authority.

Regulatory basis

  • Article 31 of Decree-Law 125/2025, on the appointment and duties of the cybersecurity officer;
  • Article 25 of the same act, on the responsibility of management bodies.

Expected results

  • A role performed with method and independence;
  • Evidence available before it is requested;
  • A management body informed in good time.
Note

The formal appointment before the authority is an act of the entity itself. Appointment duties and deadlines are covered at responsaveldeciberseguranca.pt.

An appointed role is not yet a role performed

Start by checking your organisation scope or ask for a proposal to structure the role.