Portugal’s 2022 Cybersecurity Regulation Made Asset Inventories Reportable
Portugal’s Regulation 183/2022 turned familiar security practices—named contacts, a security officer, an asset inventory, an annual report and incident notices—into structured communications with the national cybersecurity authority.
Current-status note: Regulation No. 183/2022 governed Portugal’s previous regime through 2 April 2026. Decree-Law No. 125/2025’s NIS2 framework took effect on 3 April 2026 and replaced that legal regime. Organisations should use the current framework and its applicable implementing measures for present-day compliance; this retrospective article explains the 2022 milestone.
Regulation No. 183/2022 was published on 21 February 2022 by the National Cybersecurity Centre, CNCS. It provided the technical instruction supporting Portugal’s earlier cyberspace-security regime and Decree-Law No. 65/2021.
The instruction applied to communications from covered public-administration bodies, critical-infrastructure operators, essential-service operators and digital-service providers. It also supported voluntary incident notification by other entities using networks and information systems.
Permanent contact is a resilience control
Covered entities must provide a permanent contact point to CNCS. A permanent contact is not useful if it is an individual employee’s mailbox checked only during office hours.
The function needs monitored communications, authorised deputies, current telephone and email details, and a process for validating unusual requests. Contact information should be updated when responsibilities change. Exercises should confirm that a CNCS message reaches someone able to assess and escalate it.
The entity must also identify a security responsible person. Contact and responsibility can interact but should not be confused: one route receives and coordinates communications, while the accountable security role oversees the programme described by the law.
The inventory is external evidence
The regulation specifies information to be maintained for assets and communicated as required. That elevates the asset inventory from an internal spreadsheet to part of the regulatory relationship.
An asset should be connected to the service it supports, its owner, location, dependencies, exposure and criticality. Cloud resources, software-as-a-service, operational technology and outsourced platforms belong in the view when they support the covered service. A hardware list alone cannot support incident scope or risk analysis.
Inventory change should be linked to procurement, deployment and decommissioning. Temporary cloud resources and forgotten test systems are particularly likely to escape a yearly manual census. Automated discovery can help, but ownership and service context still require human governance.
Annual reporting should describe the operating year
The technical instruction defines the information required in the annual cybersecurity report and how it is sent. A useful report should be generated from the organisation’s normal evidence, not reconstructed under deadline pressure.
Risk assessments, control changes, exercises, incidents, significant vulnerabilities and improvement actions should use consistent identifiers throughout the year. That makes the annual submission a summary of a maintained programme rather than a separate compliance narrative.
Management should review the report against known gaps. A polished document that omits an unresolved unsupported system can create more risk than an honest statement with a funded remediation plan.
Incident notification needs classification and follow-through
The regulation prescribes the communication of incident notifications and additional information to CNCS. Teams need to know which entity, service and asset are affected; the incident category; known impact; actions taken; and how updates will be provided.
The first report may precede full forensic certainty. Playbooks should distinguish confirmed facts, current assessment and open questions. They should also preserve the time of detection and the time the organisation became aware that a covered service was affected.
Suppliers need an escalation route that leaves the entity enough time to meet its duty. The contract should require prompt technical facts, continued cooperation and preservation of evidence. A service desk severity based only on the supplier’s own financial impact may not match the customer’s public or essential-service risk.
Use the regulatory fields as a control model
The required communications can be connected into one evidence chain:
- the contact point receives national warnings and coordinates notices;
- the security responsible person owns risk and improvement;
- the inventory identifies affected assets and services;
- incident records show what happened and how the entity responded; and
- the annual report summarises the maintained programme.
If the fields disagree—an incident mentions a system absent from the inventory, or the annual report omits a known event—the inconsistency reveals a governance gap.
Portugal’s 2022 regulation remains instructive because it made basic cybersecurity information operationally reusable. An accurate inventory is not produced for the regulator and forgotten. It is the same map an organisation needs to assess a warning, scope an incident, recover a service and explain the year to management.
Official sources
- Portuguese National Cybersecurity Centre: Regulation No. 183/2022
- CNCS: publication notice for Regulation No. 183/2022
- CNCS: NIS2 and Decree-Law No. 125/2025
Continue the series
- Also in Portugal: Portugal’s Whistleblower Law Requires More Than an Anonymous Inbox
- European National Cyber & Digital Law Series index
This article provides general information and is not legal advice.



