EU Regulatory Domain
Directive (EU) 2022/2555: a high common level of cybersecurity, with accountable management bodies and strict incident reporting.
Key facts
NIS2 applies, as a rule, to medium-sized and large entities operating in the sectors listed in Annexes I and II.
Management bodies approve and oversee risk-management measures, can be held liable for infringements and must follow training.
Significant incidents need an early warning within 24 hours, a notification within 72 hours and a final report within one month.
Maximum fines are at least EUR 10 million or 2% of turnover for essential entities, and EUR 7 million or 1.4% for important ones.
The NIS2 Directive replaced the original NIS Directive and raised the level of cybersecurity required across the Union. Member States had to transpose it by 17 October 2024, so obligations arise from each national transposing law. The Directive broadens the range of covered sectors, makes management bodies directly accountable and harmonises incident reporting.
NIS2 applies, as a rule, to medium-sized and large entities operating in the sectors listed in its annexes:
Annex I, sectors of high criticality: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space;
Annex II, other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing of certain products, digital providers and research.
Certain entities are covered regardless of size, such as qualified trust service providers, top-level domain registries, DNS service providers and specified public administration entities. Entities are classified as essential or important, which determines the intensity of supervision.
governance: management bodies approve the cybersecurity risk-management measures, oversee their implementation, can be held liable for infringements and must follow training (Article 20);
risk-management measures (Article 21): risk analysis and information-system security policies, incident handling, business continuity and crisis management, supply-chain security, secure acquisition, development and maintenance, effectiveness assessment, cyber hygiene and training, cryptography, human-resources security and access control, and multi-factor authentication with secured communications;
incident reporting (Article 23): an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report within one month;
registration: entities must register with the competent national authority and keep their information up to date.
For digital-infrastructure and digital-provider entities, Implementing Regulation (EU) 2024/2690 specifies the technical and methodological requirements.
Maximum fines are at least EUR 10 million or 2% of worldwide annual turnover for essential entities, and EUR 7 million or 1.4% for important entities. Supervisors may also impose binding instructions, audits and, for essential entities, temporary bans on persons in management positions.
Portugal transposed NIS2 through Decree-Law 125/2025 of 4 December, which establishes the new Cybersecurity Legal Regime and has been in force since 3 April 2026. The National Cybersecurity Centre (CNCS) is the national authority. Its implementing Regulation 756/2026 took effect in June 2026, together with the MyCiber platform for registering entities. Some obligations are phased and run from CNCS notifications, so each entity should confirm its own deadlines.
Compliance Assessment: scoping, classification and gap analysis against Article 21;
Implementation Kits: the NIS2 kit of policies, incident-response and supplier-security templates;
Training & Capacity: the training required for management bodies and staff;
Fractional Compliance Officer: ongoing support to the cybersecurity officer and contact point.
Related domains: Digital Operational Resilience · Data Protection · Third-Party & Supply Chain · Corporate Governance
Official text: Directive (EU) 2022/2555 on EUR-Lex
General information as of October 2026; it does not constitute legal advice. Confirm the applicable requirements with the competent authorities.
Related domains
Get a free scoping, classification and gap analysis against the Article 21 measures.