RJCS / NIS2 framework
From the NIS2 Directive to the Portuguese Cybersecurity Legal Framework.
NIS2 establishes the European framework. Decree-Law no. 125/2025 transposes it into Portuguese law. Regulation no. 756/2026 specifies a significant part of its implementation.
The essential distinction
Three parts of the same framework, with different functions.
Practical application requires the European framework, national law and its implementing regulation to be read together.
European Union
Directive (EU) 2022/2555
Defines measures intended to achieve a high common level of cybersecurity across the European Union.
Portugal
Decree-Law no. 125/2025
Approves the Portuguese Cybersecurity Legal Framework and transposes the NIS2 Directive into national law.
Implementation
Regulation no. 756/2026
Specifies matters including the platform, qualification, communications, risk, compliance, minimum measures and evidence.
Timeline
From the European framework to national implementation.
- NIS2 Directive
Directive (EU) 2022/2555 is adopted by the European Parliament and the Council.
- National publication
Decree-Law no. 125/2025 is published.
- Entry into force
The new Portuguese Cybersecurity Legal Framework enters into force.
- Implementing regulation
Regulation no. 756/2026 implementing the RJCS is published.
Scope
Who should assess whether they are in scope?
Classification does not depend on sector alone. It may depend on size, services provided, establishment, special criteria and a qualification decision.
Essential entities
Organizations qualified as essential according to the scope, size, sector and criteria established by the RJCS.
Important entities
Organizations qualified as important under the applicable legal criteria.
Relevant public entities
Public bodies falling within scope and qualified in accordance with the framework and its regulation.
The CNCS tool supports the assessment, but it is non-binding and does not replace self-identification where mandatory. Some criteria require specific analysis.
Operational view
What changes for an organization in scope?
The framework cannot be treated as an isolated documentation project. It requires governance, risk management, operations, communication and evidence.
Governance
Involvement of management, executive or administrative bodies and a clear allocation of responsibilities.
Risk management
Technical, operational and organizational measures appropriate and proportionate to risk.
Incidents
The ability to manage incidents and meet the legally applicable communication and notification duties.
Continuity
Backups, recovery, crisis management and business continuity.
Supply chain
Management of risks associated with direct suppliers and service providers.
Evidence
Factual, documentary or technical criteria demonstrating that measures have been applied.
Officers and contacts
Appointment and communication of the Cybersecurity Officer and Permanent Point of Contact, where applicable.
Continuous improvement
Assessment of measure effectiveness, training, monitoring and continuous development of the system.
First steps
A practical sequence for getting started.
Before selecting tools or producing policies, confirm the scope, responsibilities and required information.
- 01
Assess the scope
Confirm sector, size, services, establishment and special criteria. The CNCS simulator is a non-binding support tool.
- 02
Prepare self-identification
Gather the legal, organizational and operational information required for the process on the electronic platform.
- 03
Define governance
Clarify the responsible governing bodies, Cybersecurity Officer, point of contact and decision model.
- 04
Connect risk to measures
Inventory services and assets, assess risks and associate measures, owners, deadlines and verification criteria.
- 05
Organize evidence
Create a documentary and technical structure that makes compliance easy to locate, review and demonstrate.
Frequently asked questions
Direct answers.
Are NIS2 and the RJCS the same thing?
No. NIS2 is Directive (EU) 2022/2555. The RJCS is the national framework approved by Decree-Law no. 125/2025, which transposes that directive into Portuguese law.
Is Decree-Law no. 125/2025 already in force?
Yes. It entered into force on 3 April 2026. Some provisions have specific rules on when they take effect and must be assessed in the applicable context.
Does the CNCS simulator definitively confirm whether an organization is in scope?
No. CNCS presents it as a non-binding support tool. It does not replace mandatory self-identification or assessment of legal criteria that may not be covered by the tool.
Do all organizations have exactly the same measures?
No. The framework provides for qualification, a risk matrix, compliance levels and proportionality. Applicable measures depend on the entity's specific circumstances.
Primary sources
Consult the official acts.
General informational content. It does not replace consultation of official acts or legal or technical analysis tailored to the organization.