The TMT department at SRS Legal, in conjunction with SRS Advisory, has published an informative leaflet on the new Legal Framework for Cybersecurity (RJCS), approved by Decree-Law No. 125/2025, which transposes the NIS2 Directive into national law.
This new framework strengthens the cybersecurity obligations applicable to essential and important entities, introducing more stringent requirements regarding risk management, governance, incident reporting and supply chain security.
Key impacts include the accountability of management bodies, the implementation of technical, operational and organisational measures appropriate to the organisations’ risk profile, and the strengthening of the penalty regime applicable in the event of non-compliance.
This new regime aims to ensure a high common level of cybersecurity across the European Union, promoting greater operational resilience and the protection of critical infrastructure and essential services.
Read the full text here.