State of the Art in Critical Infrastructure Protection and Resilience in Portugal: Governance, Incidents, and Gaps
Abstract
Portugal is expanding its portfolio of recognized critical infrastructures from approximately 150 to more than 400 entities across twelve strategic sectors, reflecting increasing cross-sector interdependence and exposure to hybrid disruptions. Critical infrastructure governance is coordinated by the National Security Office and the National Cybersecurity Center and has been reinforced since 2024 through the establishment of the National Unit for the Protection of Critical Entities. Despite these advances, persistent challenges remain, including fragmented institutional mandates, uneven integration of cyber and physical resilience practices, skills shortages, and dependence on external technological providers. This paper examines how Portugal's critical infrastructure protection and resilience governance is evolving in response to the European Critical Entities Resilience (CER) and NIS2 frameworks. Its novelty lies in combining legal-institutional analysis, incident-based cross-case comparison, and a resilienceassurance framework tailored to CER/NIS2-aligned governance assessment. The study applies a structured review of legal instruments, national strategies, regulatory publications, and publicly documented incidents between 2011 and 2026 in order to synthesize sectoral scope, governance roles, disruption patterns, and assurance gaps across sectors. Findings highlight three recurring governance weaknesses: fragmented institutional coordination, incomplete cyber-physical integration in resilience practices, and the absence of comparable resilience metrics and assurance artifacts. The paper contributes a compact analytical synthesis of Portugal's critical infrastructure governance and proposes a minimal roadmap and assuranceoriented framework to support CER/NIS2-aligned resilience evaluation and continuous improvement.