Decree-Law No. 125/2025
The new Cybersecurity Legal System, structured to be applied.
A verifiable map of the diploma: 11 articles of the act, 87 articles of the system approved in the annex, nine chapters and three annexes.
Overview
The diploma and the attached scheme are not the same layer.
The 11 articles of the Decree-Law approve the RJCS, amend other diplomas, establish transition, repeals, take effect and enter into force. The material regime is in the annex.
- Publication
- 4 December 2025
- Entry into force
- 3 April 2026
- Diploma
- 11 articles
- RJCS Annex
- 87 Articles
- Structure
- 9 chapters and 3 annexes
Operational Reading
The articles that change the organization.
A selection for initial guidance — does not replace reading the other articles.
Autoidentification
Entities already active are identified within 60 days of the availability of the platform; new entities within 30 days of the start of the activity.
The count depends on the availability of the platform and the applicable framework. View operational tutorialManagement responsibility
Management bodies shall adopt and supervise measures, ensure supervision and enforcement measures and promote regular training.
The necessary responsibility and powers are not freely delegable. View operational tutorialRisk and measures
The scheme requires a systemic risk-proportional approach complemented by residual risk analysis and management.
Compliance with minimum measures does not eliminate the obligation to treat residual risks. View operational tutorialAnnual report
Key and important entities draw up and maintain annual reports; communication varies according to qualification.
There are specific rules for the first report and subsequent reports. View operational tutorialResponsible and contact point
Key and important entities designate cybersecurity officer and ensure permanent contact point.
The diploma provides for communications within 20 working days in the relevant cases. View operational tutorialNotification of incidents
Significant incidents follow an initial notification sequence, significant impact end and final report.
The deadlines depend on the verification, evolution and end of the significant impact. View operational tutorialSignificant incidents
A sequence, not a single notification.
The deadlines count from different events. The organization needs detection, decision, time record and coordination.
- Up to 24 hoursArticle 42
Initial notification after the entity has concluded that there is or may be a significant incident, except incompatibility with mitigation or resolution.
- Up to 72 hoursArticle 42
Updating of the initial notification, where necessary, with initial assessment, severity, impact and indicators available.
- Up to 24 hours after the end of impactArticle 43
Notification of the end of significant impact.
- 30 business daysArticle 44
Final report of the notification of the end of significant impact.
First layer
The 11 articles of the Decree-Law.
- Article 1 — Subject matter
- Article 2 — Legal regime for cybersecurity
- Article 3 — Amendment to Law No 53/2008 of 29 August
- Article 4 — Amendment to Law No 109/2009 of 15 September 2009
- Article 5 — Amendment to Law No 16/2022 of 16 August
- Article 6 — Addition to Law 53/2008 of 29 August
- Article 7 — Addition to Law No 109/2009 of 15 September
- Article 8 — Transitional rules
- Article 9 — Repealing rules
- Article 10 — Taking effect
- Article 11 — Entry into force
Scheme approved in Annex
87 articles, organized into nine chapters.
Open each chapter to consult all the official titles of the articles. This structure will be the basis of the explanations article by article.
Chapter I General provisions Articles 1 to 10
- Article 1 — Subject matter
- Article 2 — Definitions
- Article 3 — Subjective scope
- Article 4 — Territorial delimitation of the subjective scope
- Article 5 — Extraterritorial scope
- Article 6 — Key entities and important entities
- Article 7. — Relevant public entities
- Article 8 — Procedure for the qualification of entities
- Article 9 — Competition for qualifications and cybersecurity measures
- Article 10 — Processing of personal data
Chapter II Structured instruments Articles 11 to 14
- Article 11. — Structured Cyberspace Security Instruments
- Article 12th — National Cyberspace Security Strategy
- Article 13th — National plan to respond to large-scale cybersecurity crises and incidents
- Article 14th — National Cybersecurity Reference Framework
Chapter III Organization of cyberspace security Articles 15 to 24
- Article 15 — Organization
- Article 16. Superior Cyberspace Security Council
- Article 17 — Competences of the Superior Cyberspace Security Council
- Article 18th — Cyberspace Security Assessment Commission
- Article 19th — National Cybersecurity Centre
- Article 20 — Powers of the National Cybersecurity Centre
- Article 21. — Cybersecurity crisis management authority
- Article 22nd — Cybersecurity Incident Response Team
- Article 23 — Cooperation between national authorities
- Article 24 — Cooperation with the private sector
Chapter IV Risk management and other duties Articles 25 to 37
- Article 25 — Obligations of management, management and administration bodies
- Article 26 — Cybersecurity risk management system
- Article 27 — Cybersecurity measures
- Article 28th — Supply chain
- Article 29 — Residual risk management
- Article 30 — Annual report
- Article 31 — Cybersecurity Officer (RCS)
- Article 32 — Permanent contact point
- Article 33 — Measures applicable to relevant public entities
- Article 34 — Certification of cybersecurity
- Article 35 — Registration obligation
- Article 36 — Domain name registration database
- Article 37 — Access to domain name registration
Chapter V Vulnerability and incidents Articles 38 to 52
- Article 38 — Vulnerability in information systems
- Article 39 — Communication of vulnerabilities
- Article 40 — Compulsory notification
- Article 41 — Types of notifications
- Article 42 — Initial notification
- Article 43 — Notification of significant impact end
- Article 44 — Final and interim reports
- Article 45 — Voluntary notifications of relevant information
- Article 46 — Requests for information
- Artigo Article 47
- Article 48 — Communication to the addressees of the services
- Article 49 — Communication between authorities
- Article 50 — Communication to entities within the European Union or its Member States
- Article 51 — Information to the public
- Article 52 — Response to notifications
Chapter VI Supervision and enforcement Articles 53 to 60
- Article 53 — Principles
- Article 54 — Supervisory measures concerning essential entities
- Article 55 — Supervisory measures for relevant important and public entities
- Article 56 — Implementing measures
- Article 57 — Blocking and redirecting measures
- Article 58 — Procedural guarantees
- Article 59 — Reporting of incidents and implementing measures
- Article 60 — Cooperation in the field of critical infrastructure security
Chapter VII Penalty regime Articles 61 to 81
- Article 61 — Very serious counter-ordinations
- Article 62 — Serious counter-ordinations
- Article 63 — Mild counter-ordinations
- Article 64 — Negligence
- Article 65 — Exemption from fines
- Article 66 — Determination of the fine
- Article 67 — ancillary penalties and other determinations
- Article 68 — Compulsory sanctions
- Article 69 — Prescription of the procedure
- Article 70 — Prescription of the fine and ancillary penalties
- Article 71 — Rule of jurisdiction of the competent authorities
- Article 72 — Notifications
- Article 73 — Product of fines
- Article 74 — Costs
- Article 75 — Compliance with omitted duty
- Article 76 — Suspension of the fine
- Article 77 — Repeal of suspension of the fine
- Article 78 — Extinction of the fine
- Article 79 — Violation of personal data
- Article 80 — Impugnation of decisions of the competent cybersecurity authority
- Article 81 — Subsidiary law
Chapter VIII Additional provisions Articles 82 to 84
- Article 82 — Supervisory fee
- Article 83 — Communications
- Article 84 — Information security and integrity
Chapter IX Final provisions Articles 85 to 87
- Article 85 — Approval of the national large-scale cybersecurity crisis and incident response plan
- Article 86 — Provision of means and operational independence of the CNCS
- Article 87 — Interoperability and access to information
Scope and dimension
Three essential annexes to the framework.
Annex I
Sectors of critical importance.
Explore AnnexAnnex II
Other critical sectors.
Explore AnnexAnnex III
Definition of enterprise and size categories.
Explore AnnexFrequently Asked Questions
Read without oversimplifying.
Does the diploma have only 11 articles?
The legislative act has 11 articles, but it approves in an annex the Legal System for Cybersecurity, which contains 87 articles, nine chapters and three annexes.
Does entry into force mean that all obligations took effect on the same date?
Not necessarily. Article 10 contains specific rules for the production of effects for certain provisions linked to the publication of the rules laid down in the scheme.
Are the minimum measures sufficient in itself?
No. Articles 26 and 29 require risk analysis and management, including residual risks, and appropriate and proportionate measures to the entity’s context.
Do all entities concerned have the same obligations?
No. The qualification, type of entity, group, risk matrix and level of compliance influence the specifically applicable obligations.
Primary source
Always confirm in the official act.
Information and structural guide. The summaries shall not replace the official text, the applicable regulation or a legal and technical analysis adjusted to the entity.