The problem it solves
The appointment is made, but the role is left without a mandate, without time and without resources. The officer holds it alongside other duties, has no budget and is only heard after the incident.
Who it is for
- Essential and important entities whose role is still unstructured;
- International groups with a subsidiary or infrastructure in Portugal;
- Suppliers to covered entities facing contractual requirements.
Deliverables
- Annual cybersecurity plan and responsibility map;
- Evidence file organised by area of measures;
- Periodic reporting to the management body;
- Interface with the CNCS and with the supply chain.
Method
- 01
Assess
Scope, measures and gaps.
- 02
Structure
Mandate, resources and plan.
- 03
Operate
Advise, monitor and evidence.
- 04
Report
To the management body and the authority.
Regulatory basis
- Article 31 of Decree-Law 125/2025, on the appointment and duties of the cybersecurity officer;
- Article 25 of the same act, on the responsibility of management bodies.
Expected results
- A role performed with method and independence;
- Evidence available before it is requested;
- A management body informed in good time.
Note
The formal appointment before the authority is an act of the entity itself. Appointment duties and deadlines are covered at responsaveldeciberseguranca.pt.