
NIS2 / DORA / Cyber Resilience Act: what changes and how to prepare your organisation
Scope, governance, risk, incidents, third parties, digital products and evidence: a practical structure for preparing your organisation without confusing distinct regulatory frameworks.
⏱️ Estimated reading time: 7–8 minutes
NIS2, DORA and the Cyber Resilience Act are transforming how organisations manage risk, incidents, third parties, products with digital elements and evidence. Although they share some concerns, they apply to different contexts and require different responses.
In Portugal, Decree-Law No. 125/2025 established the new Cybersecurity Legal Framework, transposing NIS2, and entered into force on 3 April 2026. Regulation No. 756/2026, in force since 23 June, set out matters such as the operation of the electronic platform, the National Cybersecurity Reference Framework, the risk matrix, minimum measures and verification criteria.
DORA has applied directly since 17 January 2025. Under the Cyber Resilience Act, reporting obligations start to apply on 11 September 2026, while the Regulation applies generally from 11 December 2027.