< Back to all clusters
[TECHNOLOGY] · Portugal · 2 sources

EU NIS2 Directive Expands to 160,000 Entities, Portugal Launches New Cybersecurity Regulation

The EU NIS2 Directive (Directive (EU) 2022/2555) now covers roughly 160,000 organisations across 18 critical sectors, up from about 15,000 under the original NIS framework. It classifies entities as "essential" or "important" based on size and sector, assigns board‑level accountability under Article 21, and sets maximum fines of at least €10 million or 2 % of worldwide turnover for essential entities and up to €7 million or 1.4 % for important ones. Article 21 outlines ten minimum cyber‑risk‑management measures that must be implemented, ranging from risk analysis and incident handling to supply‑chain security and multi‑factor authentication.

Portugal has issued a national regulation to put NIS2 into practical effect. Approved by the National Cybersecurity Centre (CNCS), the rule creates a central electronic platform for self‑identification, qualification, reporting and incident notification. It introduces a graded compliance system—basic, substantial, and elevated—based on a risk matrix that considers the entity’s economic and social relevance. The regulation also formalises the roles of a Cybersecurity Responsible and a Permanent Point of Contact, and mandates use of secure authentication methods such as the Citizen Card and Mobile Key for platform access.