Command of the Portuguese regulatory framework — Centro Nacional de Cibersegurança, NIS2, GDPR — for companies and essential infrastructure operators.
Last updated — August 22, 2026
Portugal's cybersecurity framework is carried by the Centro Nacional de Cibersegurança (CNCS), the reference authority responsible for national coordination, support to public and private entities, and the publication of technical recommendations. The NIS2 directive, currently being transposed, broadens the scope of essential and important entities subject to risk management, governance and incident notification obligations. GDPR also governs any processing of personal data within Portuguese territory.
Engagement model
Direct engagement
Framework
CNCS recommendations and NIS2 requirements
Languages
Portuguese, English, French
The Centro Nacional de Cibersegurança (CNCS), which provides national coordination and technical recommendations.
Entities identified as essential or important based on the sector and size criteria set by the national transposition. This topic has its own dedicated page on this site.
GDPR, applicable to any processing of personal data within Portuguese territory.
Security audits, penetration testing and GRC compliance for entities subject to NIS2, complemented by continuous monitoring.
With an initial scoping phase to determine the entity's status under NIS2 and define the technical scope of the engagement.