# Decree-Law 125/2025 explained for SMEs

> What Portuguese Decree-Law 125/2025 requires from companies, in plain language: who is covered, which obligations it brings, and the deadlines and fines it sets.

By: Daniel Barreiros  
Published: 2026-10-01  
Online version: https://nis2pme.pt/en/guides/dl-125-2025-explained-smes/

## The essentials in 30 seconds

- Decree-Law 125/2025 has been in force since 3 April 2026 and transposes the NIS2 directive into Portuguese law.
- It applies, as a rule, to companies with 50 or more employees or more than €10 million in turnover, operating in the sectors listed in annexes I and II.
- There are seven core obligations: registration with the CNCS, cybersecurity measures, a designated officer, a permanent contact point, incident notification, an annual report and management involvement.
- Incident notification deadlines are tight: 24 hours for the initial report and 72 hours for the update.
- Fines reach €10 million or 2% of worldwide turnover, and management can be held personally liable in cases of intent or gross negligence.

---

Decree-Law 125/2025 approved Portugal's cybersecurity legal framework and transposed the European NIS2 directive. It has been in force since 3 April 2026 and brought cybersecurity obligations to thousands of companies that had never had to think about this in a structured way.

This guide explains the essentials: whether your company is covered, what it has to do, and what happens if it doesn't. No legalese, no alarmism.

## Is my company covered?

As a rule, the answer depends on two questions: **which sector you operate in** and **how large you are**.

**The sector.** The decree-law covers the sectors listed in its annexes I and II. Annex I covers the sectors of high criticality: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, business-to-business ICT service management, and space. Annex II covers other critical sectors: postal and courier services, waste management, chemicals, production and distribution of food, manufacturing (including medical devices, electronics, machinery and vehicles), digital service providers (online marketplaces, search engines, social networks) and research.

**The size.** Within those sectors, the framework applies to medium-sized and large companies. In practice, your company is in scope if it has **50 or more employees** or an annual turnover **above €10 million**. Micro and small companies are, as a rule, out of scope.

There are exceptions where size doesn't matter. Certain activities are covered regardless of company size: providers of electronic communications networks and services, trust service providers, DNS service providers and domain name registration providers, and companies that are the sole provider of a service essential to society or the economy, or whose failure could considerably affect public safety or public health.

If your company is in one of the listed sectors but is small and doesn't fall under any exception, it most likely isn't covered. Even so, it's worth confirming: the line is drawn case by case, and there are situations where the CNCS can qualify an entity based on its specific importance.

## Essential or important entity?

The decree-law divides covered entities into two groups:

- **Essential entities**: mainly the large companies in annex I sectors, plus specific cases such as qualified trust service providers or critical entities.
- **Important entities**: the remaining covered entities in annexes I and II. This is where most covered SMEs fall.

The distinction matters because it changes the intensity of supervision and the maximum fines. The substantive obligations are very similar.

The qualification is not the company's choice: entities identify themselves on an electronic platform made available by the CNCS (within 30 days of starting activity), and it is the CNCS that assigns the qualification and notifies the entity.

## The main obligations

### 1. Registration with the CNCS

Covered entities must register on the CNCS electronic platform with the company's identification details (name, tax number, contacts, sector). Any change to this information must be communicated within 30 working days.

### 2. Cybersecurity measures

This is the heart of the framework. Entities must adopt technical, operational and organisational measures to manage cybersecurity risks, covering areas such as: incident handling, business continuity (backups, disaster recovery), supply chain security, cyber hygiene and training, access control, cryptography and multi-factor authentication.

The decree-law defines the areas; the concrete detail comes from the **QNRCS**, Portugal's National Cybersecurity Reference Framework. Regulation 756/2026 from the CNCS, already in force, defines the minimum measures each entity must meet according to its **compliance level** (Basic, Substantial or High). We explain the three levels in detail in the guide [The three QNRCS compliance levels](/en/guides/qnrcs-compliance-levels/).

One point the decree-law itself makes clear: the minimum measures are a starting point, not a ceiling. Companies should adopt whatever additional measures result from their own risk analysis.

### 3. A cybersecurity officer

Each entity must designate a cybersecurity officer. It doesn't have to be a new role or a new hire: it does have to be someone who belongs to the company's management or reports to it directly. This person proposes the measures, reports to management and takes care of the day-to-day obligations, such as the annual report.

### 4. A permanent point of contact

The entity must provide a point of contact that the authorities can reach at any time, 24 hours a day, 7 days a week. In an SME, this role can be taken on by the cybersecurity officer.

### 5. Incident notification

When a significant incident occurs, there are concrete deadlines to meet with the competent authority:

- **Initial notification**: within 24 hours of the company concluding that a significant incident exists (or may come to exist);
- **Update**: within 72 hours of the incident being confirmed, with a first assessment of its severity and impact;
- **End-of-impact notification**: within 24 hours of the impact ending;
- **Final report**: within 30 working days of the end-of-impact notification.

These deadlines are tight. Meeting them without panic requires deciding in advance who notifies, how, and with what information. It's exactly the kind of procedure worth writing down before it's needed.

### 6. Annual report

Entities must prepare an annual report with the security activities carried out, incident statistics and the measures taken. Essential entities submit it to the competent authority by the last working day of January; important entities keep it and hand it over whenever the CNCS requests it.

### 7. Management involvement

The decree-law doesn't leave cybersecurity "to the IT person". It is the company's management (directors or board) that approves the risk management measures, supervises their application and ensures [regular cybersecurity training](/en/training/), for themselves and for employees.

These obligations cannot be delegated outside management. And members of management bodies can be held personally liable for infringements, by action or omission, in cases of intent or gross negligence. It is not automatic liability, but it is reason enough for management to follow the topic rather than ignore it.

## What if you don't comply? The fines

Failure to meet the obligations is an administrative offence. The maximum amounts are significant:

- **Essential entities**: fines up to €10 million or 2% of worldwide annual turnover, whichever is higher;
- **Important entities**: fines up to €7 million or 1.4% of worldwide annual turnover, whichever is higher;
- **Natural persons**: fines up to €200,000.

Two notes to keep a cool head. First, these are legal maximums, designed with large companies in mind too; actual fines are graduated by severity. Second, the framework's goal is not to fine, it's to raise the level of security: a company that has registered, adopted the measures for its level and can demonstrate it is in a solid position.

## How long do I have to adapt?

When an entity is qualified (or when the applicable minimum measures change), it has **six months** to adapt, extendable up to one year upon a reasoned request. Six months go by quickly when there are dozens of measures to implement, so the best time to start the assessment is before the notification, not after.

## In summary

- Decree-Law 125/2025 has been in force since 3 April 2026 and applies, as a rule, to medium-sized and large companies in critical sectors, with exceptions that catch smaller companies.
- The central obligations: registration with the CNCS, cybersecurity measures under the QNRCS, a cybersecurity officer, a permanent contact, incident notification with 24/72-hour deadlines, and an annual report.
- Company management has obligations of its own that it cannot delegate, and can be held personally liable in cases of intent or gross negligence.
- The fines are significant, but the way to avoid them is well known: know your compliance level, implement the minimum measures and be able to demonstrate it.

The natural next steps from here: understanding [the three QNRCS compliance levels](/en/guides/qnrcs-compliance-levels/) and then [where to start in practice](/en/guides/nis2-compliance-where-to-start/).

---

*This guide is informational and does not constitute legal advice. It reflects Decree-Law 125/2025 and Regulation 756/2026 as of September 2026; NIS2PME tracks regulatory developments and updates this content accordingly.*

## Frequently asked questions

### Is my company in scope of Decree-Law 125/2025?

It depends on sector and size. As a rule it applies to companies with 50 or more employees or annual turnover above €10 million, operating in the sectors listed in annexes I and II. There are exceptions where size does not matter, such as providers of electronic communications, trust service providers and DNS and domain name registration service providers.

### What is the difference between an essential and an important entity?

Essential entities are mostly large companies in annex I sectors; important entities are the remaining entities in scope, where most SMEs fall. The substantive obligations are very similar. What changes is the intensity of supervision and the maximum fines: up to €10 million or 2% of turnover for essential entities, and up to €7 million or 1.4% for important ones.

### How quickly must I notify a significant incident?

The initial notification is due within 24 hours of the company concluding that a significant incident exists or may come to exist. An update follows within 72 hours, notification of the end of impact within 24 hours of it ending, and a final report within 30 working days.

### How long do I have to adapt after being qualified?

Six months from qualification, extendable to one year on a reasoned request. Since the initial assessment takes time, it pays to start before being notified.

## Sources

- [Decree-Law 125/2025, of 4 December (Diário da República)](https://diariodarepublica.pt/dr/detalhe/decreto-lei/125-2025-962603401)
- [Regulation 756/2026, of 22 June (Diário da República)](https://diariodarepublica.pt/dr/detalhe/regulamento/756-2026-1134399056)

---

*Informational content. It does not constitute legal advice.*
