Portugal's new cybersecurity framework, Decree-Law 125/2025 transposing the EU's NIS2 Directive, came into force on 3 April 2026. The outsourcing market in Lisbon and Porto has not changed much in the last year, but the rules around buying from it have.
Since April 2026, Portugal's transposition of NIS2 means a CTO hiring a Portuguese outsourcing provider is expected, under their own country's version of the same directive, to assess that provider's security practices. The provider's certification scope, sub-processors and incident process are now part of the buyer's compliance file, not optional diligence.
What follows is what actually matters now, grouped by where each point comes up in a real evaluation.
WHAT YOU’LL FIND IN THIS ARTICLE:
→ The cybersecurity rules that changed in April 2026, and whose law actually applies to you
→ Why your provider's security posture is now partly your problem
→ What you are actually buying when you buy "outsourcing"
→ Where speed genuinely comes from, and where it does not
→ The integration questions most evaluations skip
Portugal transposed the EU's NIS2 Directive through Decree-Law No. 125/2025 of 4 December, which entered into force on 3 April 2026, according to the published analysis by Vieira de Almeida. It replaced the previous national regime and consolidated the Centro Nacional de Cibersegurança as the national authority.
The practical consequence for a CTO is that any conversation about security with a Lisbon provider now has a specific legal frame behind it, rather than resting on general assurances. If your last vendor security review predates April 2026, it predates the rules.
Of everything in NIS2, this is the requirement most directly relevant to outsourcing, and the easiest to miss.
Under Portugal's Decree-Law 125/2025, essential and important entities must adopt cybersecurity measures across defined areas, and supply chain security is named as one of them. The measures required in that area include considering the vulnerabilities of each direct supplier and service provider, and the cybersecurity practices of those suppliers and providers.
Read plainly: for a company inside scope, assessing an outsourcing provider's security practices is not optional diligence. It is part of what the regime expects.
In practice that turns three questions into standing requirements: which of your systems and data the provider's engineers will touch, which sub-processors sit behind them and where those operate, and what the provider does when something goes wrong. None are difficult. They are simply ones a lot of engagements signed before April 2026 never recorded an answer to.
The same supply chain obligation exists in every EU member state's transposition of NIS2, not only Portugal's. Which national version applies to a given company depends on where that company is established.
Under the NIS2 Directive, entities generally fall under the jurisdiction of the member state in which they are established, with exceptions for certain digital providers such as cloud, data centre and managed service providers, assessed on their main establishment in the Union. A German company therefore answers to Germany's transposition, not Portugal's. A UK company sits outside NIS2 altogether, since the directive is an EU instrument, and has its own separate regime.
So hiring a Lisbon provider does not pull you into Portuguese cybersecurity law. It places a Portuguese supplier inside the supply chain your own national rules ask you to assess.
The obligation is real either way. The question is not whether Portugal's law reaches you, but whether your provider can satisfy whichever version does. The Portuguese framework still tells you something useful: what regulatory environment your supplier now operates in, drawn from the same directive as your own.
Under Portugal's Decree-Law 125/2025, non-compliance with NIS2 obligations can carry fines of up to €10 million or 2% of annual global turnover, whichever is higher, and members of management bodies may be held liable for action or omission where there is intent or gross negligence. Other transpositions of the same directive carry comparable provisions, so this shape is not specific to Portugal.
That changes the tone of vendor security reviews. A question that used to sit with procurement now has a named person at board level attached to it.
For a CTO, the useful consequence is leverage. Security requirements previously hard to justify against delivery pressure now carry a compliance argument, which makes them easier to fund and easier to insist on.
5. Ask what a certification actually covers, not whether one exists
ISO 27001 covers information security management and ISO 27701 covers privacy information management. Both are externally audited, which makes them meaningful. Neither tells you anything on its own about your engagement.
The detail that matters is the scope statement: which activities the certification was audited against. A certification scoped to a provider's own office IT is a different thing from one scoped to how consultants are contracted, managed and given access to client systems.
For reference, KWAN holds both standards with a scope covering contracts, talent management and the IT outsourcing of consultants, with teams and data based in Portugal. That level of specificity is what to ask any provider for, because it is the part a client's own risk assessment can actually use.
Ask for the scope statement rather than the logo, and ask when the last audit took place. It is a short conversation that separates providers with a real posture from providers with a badge.
The first decision is not which provider, but what kind of capacity.
IT Staffing and team augmentation extends a team you already run. Engineers work inside your processes and sprint structure, and you manage delivery directly.
Dedicated teams and integrated squads is a different shape: a stable group assembled around a product or a longer-term objective, where continuity at team level is the point rather than individual placements.
Comparing a staffing proposal against a dedicated team proposal on price alone is comparing two different things. Decide which one the work actually calls for before asking anyone for numbers.
Once the capacity question is settled, the delivery model is an independent decision. Nearshore delivery from Portugal puts the team in a close time zone with substantial overlap with UK and Northern European working hours. Remote and hybrid or on-site models exist alongside it, and either capacity type can be delivered through any of them.
The confusion worth avoiding is treating "nearshore" as the product. It describes geography and working-hours overlap, not what you are buying.
Portugal shares the UK's time zone year-round and sits one hour behind Germany, Austria and Switzerland, since Portugal and the UK shift their clocks on the same dates.
That is a checkable number rather than a claim about being "closely aligned with Europe." Ask any provider to state the actual overlap with your team's working day, and treat vague geography as a non-answer. Our comparison of nearshore and offshore delivery sets out what the difference costs in practice.
When a provider quotes days rather than months to present candidates, the honest explanation is sequencing rather than effort. Sourcing, technical vetting and employment have already happened before your brief arrives, so you enter the process partway through it.
That is also why a list of available profiles ready to start is a more useful thing to ask for than a capability deck. It tells you what exists now rather than what could be found later.
The corollary matters just as much: a provider without that groundwork is starting the same search you would run yourself, and will take about as long.
Even after the right person accepts, they usually cannot start immediately. In Portugal, a permanent employee resigning owes 30 or 60 days' notice depending on how long they have been with the employer they are leaving.
No provider shortens a statutory notice period. What varies is whether the person you want is currently employed elsewhere or is a consultant already with the provider and moving between engagements, in which case no notice applies.
If a timeline sounds impossible for a senior profile, this is usually why. Ask which situation applies to the specific person before assuming a date.
A start date is not the same as a contribution date. New engineers spend early weeks building context: which systems matter, which conventions are enforced, why a particular decision was made two years ago.
Providers vary in whether they treat that period as their responsibility or yours, and the difference shows up in the first month rather than in the contract.
Three questions surface it quickly:
Who from the provider speaks to the engineer during the first weeks, and about what
What happens operationally if the technical fit turns out to be wrong, including who initiates that conversation
And what the provider's actual continuity figure is, expressed as a number rather than as a promise of long-term partnership
Our account of a nearshore engineer's first 30 days describes what that month looks like from the inside.
At KWAN, continuity runs at around 70%, excluding internalisations, with a dedicated People Experience Partner assigned to each engagement. Numbers like that are worth requesting from any provider, because a placement that leaves in month four costs more than a slower search that stays.
Assessing an outsourcing provider under NIS2 reduces to two lists: one you work through internally, one you put to every provider on the shortlist.
| What to establish | |
| Before contacting anyone | Which national transposition of the cybersecurity rules applies to your company, if any |
| Whether the work calls for IT staffing or a dedicated team | |
| Which delivery model fits: nearshore, remote, or hybrid and on-site | |
| The last date someone could start and still contribute this quarter | |
| Ask every provider | What the ISO certification scope covers, and when it was last audited |
| Which of your systems and data the engineers will actually access | |
| Which sub-processors sit behind them, and where those operate | |
| What happens when there is an incident, and how quickly you would be told | |
| The actual overlap in hours with your team's working day | |
| Who is available now, rather than who could be found later | |
| Whether a specific candidate is employed elsewhere or already with the provider | |
| Who from the provider speaks to the engineer in the first month, and what happens if the fit is wrong | |
| The real continuity figure, expressed as a number |
Generally no. Under the NIS2 Directive, entities fall under the jurisdiction of the member state where they are established, with specific exceptions for certain digital service providers. A German or Dutch company answers to its own national transposition; a UK company sits outside NIS2 entirely. Hiring in Lisbon does not change that, though it does place a Portuguese supplier inside the supply chain your own rules ask you to assess.
Not automatically. The obligation sits with the covered entity, which must consider its suppliers' cybersecurity practices and vulnerabilities as part of its own risk management. Certification is one form of evidence a provider can offer, not a blanket legal requirement on them. The practical test is whether the provider can give you a scoped, audited answer about how consultants are contracted, managed and given access, since that is what your own assessment needs to record.
IT staffing extends an existing team with engineers who work inside your processes. A dedicated team is assembled as a stable unit around a product or longer-term objective. Both can be delivered nearshore, remotely or on-site.
A full working day. Portugal and the UK share the same time zone throughout the year because both change their clocks on the same dates. For Germany, Austria and Switzerland, Portugal is one hour behind.
Because the sourcing and vetting happened before the brief arrived. It reflects work already completed rather than a faster search, which is why the same speed is not available from a provider building a pipeline from scratch.
The scope of the certification, when it was last audited, which of your systems the engineers will access, where data is processed and stored, and which sub-processors are involved. Those specifics are what a vendor review actually needs.
Most of the questions above take one conversation to answer properly. If you are working through a Lisbon shortlist, send us the requirement and we will go through them with you, including the ones about our own setup.