For years, anyone writing about digital sovereignty in Portugal had to write in the conditional. People talked about what the State should do, what would be desirable, what other countries were already doing.
That changed in May 2026. Council of Ministers Resolution no. 102/2026, published on the 27th of that month, approved the National Sovereign Cloud Plan. For the first time, there is an official document that recognises the State's technological dependence as a risk and sets out a path to reduce it.
It is good news. But between the plan and reality on the ground there is a gap worth measuring honestly, especially if we look at the part of the public administration that is most exposed and least equipped: the municipalities.
What the plan says
The National Sovereign Cloud Plan rests on three dimensions: classifying the business processes, data and systems of the public administration; defining sovereignty, security and resilience requirements for each level; and adopting sovereign digital infrastructure in phases.
The logic is sound and deserves recognition, because it breaks with fifteen years of one-size-fits-all treatment. Not all State data requires the same degree of protection, and for the first time it is formally recognised that there is a level of criticality that requires infrastructure under enhanced State control.
The operational elements are equally concrete:
- Monitoring is the responsibility of the Agency for the Technological Reform of the State, in coordination with the National Cybersecurity Centre.
- Infrastructure is the responsibility of IP Telecom, with a sovereign data centre planned for 2027 and completion of the structure targeted for 2030.
- All public administration organisations must have their processes mapped and classified by 30 June 2027.
- There is an unusual financial incentive: half of the money saved through migration stays with the entity itself.
- Training in digital sovereignty is planned for at least 10% of the public administration's IT specialists by 2028, and for more than a thousand senior managers by 2030.
It is a serious plan. The problem is not what it says. It is how long it will take, and who is left exposed in the meantime.
On the ground: 308 councils, one attack surface
The latest picture of Portuguese municipalities is not reassuring.
In the National Cybersecurity Centre's cybersecurity report for 2024, municipal councils are identified as a preferred target, with a 9.4 percentage point increase in incidents since 2021. A quarter of municipalities reported detecting incidents that year. Across the country as a whole, CERT.PT recorded a 36% increase in incidents compared with the previous year.
An academic study that analysed the websites of all 308 municipalities concluded that, despite improvements, significant vulnerabilities remain, some of which, in the researchers' words, would not require a particularly sophisticated attacker to exploit. The national average score on the cybersecurity indicator was 0.660, on a scale of zero to one.
One more figure helps explain the nature of the problem: credential-stealing malware accounted for more than 80% of the malware activity recorded in the third quarter of 2025. And the most frequent type of incident is still phishing, with campaigns that increasingly imitate the public administration itself.
Put all this together and the picture becomes clear. The dominant entry point is not some exotic server flaw. It is an email that someone opens.
The asymmetry no plan can fix
Portugal's central administration has IT teams, its own budgets and the capacity to hire. The report's own data shows it: 63% of central administration uses at least two authentication factors, a higher percentage than Portuguese businesses.
A municipality of twenty thousand inhabitants is a different reality. It often has one or two people responsible for all IT, including user support, the municipal portal, document management systems, planning, water, fees and licences. Cybersecurity competes with all of this for the same time and the same budget.
It is not a lack of will. It is arithmetic. And that is why initiatives such as the national cybersecurity exercise for local authorities, which involved more than 270 councils and around a thousand participants in ransomware and phishing scenarios, matter: not because they train technology, but because they train decision-making in organisations where there is no permanent crisis team.
The National Sovereign Cloud Plan addresses the public administration as a whole. It does not, on its own, resolve the gap in capacity between a ministry and a small inland municipality.
The gap no one can ignore
It is worth reading the dates carefully. Classification of processes by mid-2027. Sovereign data centre planned for 2027. Completion of the structure targeted for 2030.
These are reasonable deadlines for a transformation of this scale. But they mean that, over the next few years, communications between the State and citizens will continue to run on the infrastructure that exists today. And that infrastructure, in many municipalities, relies on services contracted from providers subject to the laws of third countries.
The practical question, for anyone running a municipality or a public service today, is not "what will change in 2030". It is "what can I decide in the next contract I sign".
Three decisions that do not depend on waiting
First: treat jurisdiction as a requirement, not as a tie-breaker. No new legislation is needed. Tender specifications can require, right now, that the provider be subject exclusively to Portuguese and European law, and that there be no transfers to third countries. It is one line of text.
Second: start with email. It is where attacks come in, it is where the most sensitive information in the relationship with citizens lives, and it is the easiest system to change, because it is built on open protocols. That is where Germany and France started, and not by chance.
Third: demand proof instead of promises. A provider should be able to answer simple questions in writing and without hesitation: where the data is, which law the company operating it is subject to, how long logs are kept, and what happens when the contract ends.
None of these three decisions requires additional budget, legislative change or waiting for national infrastructure. They only require asking the right questions at the moment of contracting.
What is really at stake
For most people, a municipality is the closest face of the State. It is where you deal with a licence, report an incident, apply for social support, sort out a water problem. The information that passes through these communications is often more sensitive than what passes through a ministry.
Portugal took an important step by approving a national plan. But digital sovereignty is not decided only in the Council of Ministers. It is decided, above all, in the thousands of procurement procedures that public bodies launch every year, long before any national infrastructure is ready.
The plan sets the destination. Every contract signed until then sets the path.
