NIS2 enters into force in the EU
Directive (EU) 2022/2555, establishing the new European cybersecurity framework, enters into force.
Suppliers · Dependencies · Supply chain
From obligation to implementation. From implementation to evidence. From evidence to continuity.
Understand critical dependencies and treat third-party risk as an integral part of your organization's security and continuity.
NIS2 · Portugal · MyCiber
NIS2 has been transposed into Portuguese law and the MyCiber platform is operational. Organizations already operating are within the self-identification window. Starting early allows the framework, representation, data and evidence to be checked before submission.
Progress is updated automatically according to the device date.
—% elapsed
Swipe horizontally on smaller screens.
Directive (EU) 2022/2555, establishing the new European cybersecurity framework, enters into force.
The deadline for Member States to transpose NIS2 into national law expires.
Portugal publishes the law transposing NIS2 and approving the Cybersecurity Legal Framework.
The new Portuguese cybersecurity legal framework becomes applicable.
The implementing regulation establishes rules on qualification, risk, measures, evidence and MyCiber.
The platform begins supporting self-identification and the qualification procedure.
End of the announced window for organizations already operating when the framework entered into force.
Informative reference; it does not replace confirmation applicable to the organization. Sources: Decree-Law no. 125/2025 (PT), Regulation no. 756/2026 (PT), official MyCiber FAQ (PT) and Article 87 of the Portuguese Administrative Procedure Code (PT).
Initial RJCS guidance
Answer only what you know. The tool organizes relevant elements, highlights uncertainty and provides preliminary guidance — never an official qualification.
First understand the process, its stages and data safeguards →
Preliminary guidance
Further analysisThis result organizes the information provided. It is not an official qualification, legal opinion or substitute for self-identification and the competent authority's decision.
Validation request
Identify yourself to request a Cyberprotech review. Before submission, we show exactly which answers and data will be associated with the process.
After self-identification
Submission through MyCiber begins a qualification and implementation pathway. The useful work is to turn the framework into responsibilities, measures, documents and evidence the organization can maintain.
Validate the organization, sector, size, services and representation.
Define owners, sources, assumptions and internal approvals.
Connect every obligation to measures, documents, implementation and proof.

Before choosing a solution
Are cybersecurity responsibilities and decision-making authority clearly assigned?
Can you identify the systems, services and third parties your operations depend on?
Can you locate the evidence supporting each implemented measure?
Local Public Sector
The framework, dependencies and priorities are not the same for every organization. We organize the starting point around its institutional and operational reality, without anticipating qualification by the competent authority.
Governance, citizen services, digital dependencies, suppliers and municipal continuity.
Explore pathway →02Proportionate measures, shared systems, access, backups, capability building and continuity of public service.
Explore pathway →03Sector activity, independent governance, operational systems, third parties and organization-specific evidence.
Explore pathway →04Essential services, IT and OT environments, remote access, supply chain and recovery.
Explore pathway →Knowledge Center
Structured content for people, search engines and AI systems, supported by context, primary sources and editorial review.
Practical guidance on scope, responsibilities, obligations and implementation in Portugal.
Learn more ImplementationConnect obligations, risks, measures, owners, documents and verifiable evidence.
Learn more PathwayRegistration, self-identification, qualification, designated roles, evidence and practical guidance.
Learn moreResource Library
Guides, templates and tools with proportionate access, metadata, versions and documented sources.
Open the LibraryPractical explanations and implementation pathways
Verification lists by obligation and context
Document structures and working templates
Matrices, flowcharts and operational resources
How we work
A continuous pathway connecting governance, technical implementation, operations and evidence, with professional responsibility at every decision point.
Confirm the organization, sector, size, services, assumptions and priorities without anticipating official decisions.
Define who decides, delivers, oversees, reports and maintains availability, with clear authority and boundaries.
Turn requirements into measures, owners, deadlines, configurations, documents and acceptance criteria.
Integrate monitoring, support, triage, incident response and continuity into real operations.
Connect obligations, risks, measures, delivery and evidence; measure, test, correct and evolve.
Implementation
Cyberprotech steps in when obligations and priorities need to become verifiable operations.
A platform supporting continuous compliance, evidence, documentation and roadmaps.
Learn more in Portuguese →Understand the starting point, priorities and an actionable plan.
Learn more in Portuguese →Cybersecurity governance and ongoing organizational capability.
Learn more in Portuguese →Reception, triage, contact activation and escalation of alerts, notifications and incidents.
Learn more in Portuguese →Monitoring, incident response and coordinated operational decisions.
Learn more in Portuguese →Capability building aligned with roles, risks and obligations.
Learn more in Portuguese →Digital learning paths, content, sessions and capability follow-up.
Visit platform ↗See how governance, implementation, operations and response connect in a modular architecture.
Incident notification and response
A clear entry point for triage and rapid professional support, remotely or on site, according to impact, urgency and organizational context.
This support request does not replace official notification. Where applicable, we help prepare information for MyCiber or the channel designated by the competent authority.
We gather essential information, assess impact and help establish the first priorities.
Technical support and remote coordination to accelerate containment, evidence gathering and decisions.
On-site intervention when severity, affected systems or local coordination require it.
Clients
Organizations of different sizes and sectors that have trusted Cyberprotech to address concrete needs.
Meet our clients →Each relationship has its own scope. Inclusion here does not necessarily indicate a currently active contractual relationship.
Next step
An initial conversation helps identify your organization's context, risks and first priorities.