The deadline is more than a date on the calendar
Article 8 of the Portuguese Cybersecurity Legal Framework requires entities within scope to identify themselves on the electronic platform provided by CNCS. For entities already operating when the framework entered into force, the legal deadline is 60 days after the platform becomes available. For new entities, the deadline is 30 days after operations begin.
Cyberprotech's operational reference considers MyCiber to have become available on June 23, 2026, and, for informational purposes, uses a count in business days. Each entity should confirm its framework, applicable date, and any guidance from the competent authority.
Waiting until the final days creates avoidable risk
Self-identification is not merely a matter of opening a form and entering administrative data. It requires decisions about sector and subsector, activities and services, size, establishments, representation, and contacts. Some of this information may be distributed among management, finance, human resources, legal, and technology teams.
Leaving this work until the end increases the likelihood of contradictory data, missing representation documents, an unavailable legal representative, or submissions without internal validation. The problem is rarely the time needed to complete the form; it is the time required to gather, confirm, and approve the correct information.
Who should act now
Organizations that may fall within Article 3 of the RJCS should act, particularly based on their sector, activity, size, or public relevance. The analysis should include the annexes to Decree-Law No. 125/2025 and the criteria that may determine application regardless of size.
The checker provided by CNCS is indicative support. It does not replace an assessment of the applicable framework or self-identification where required. Final qualification results from the procedure conducted by the competent authority; the entity should not confuse an internal estimate with the formal decision.
What should be ready before submission
Create a controlled working folder and a framework assessment record. Record the sources used, assumptions, who validated each item, and the confirmation date. This record reduces rework and makes it possible to explain later how the entity arrived at the submitted information.
- Current legal name, tax identification number, registered office, establishments, and contacts.
- Activities, services, sectors, and subsectors relevant to the framework assessment.
- Validated size data, including headcount and applicable financial information.
- Legal representative or authorized person, with appropriate authority and supporting documents.
- Internal process owner and deputy to ensure continuity.
- Evidence and internal sources supporting each relevant answer.
- Final review by at least two organizational functions.
A practical seven-day plan
If preparation has not yet begun, do not try to resolve everything in one meeting. Organize a short cycle: on day one, appoint the owner and confirm the perimeter; over the next two days, collect data and evidence; on day four, validate sector, size, and representation; on day five, conduct a cross-review; on day six, prepare the submission; on day seven, submit and preserve the receipt.
If material questions arise, record them and seek clarification instead of inventing answers. A timely, supported submission is more valuable than a rushed form that no one can explain.
Submission is the beginning, not the end
Regulation No. 756/2026 provides for a receipt containing the submission date and time. The authority may request additional information, and the procedure may include a draft decision, hearing, and qualification notice. The entity should monitor the platform and the contacts it provided.
Qualification leads to concrete responsibilities, including communication of the Cybersecurity Officer (RCS) and Permanent Contact Point under the applicable terms, as well as continuous organization of measures, documents, and evidence.
Time is short, but control is the objective
Urgency should mobilize the organization, not create panic. Confirming the framework, distributing responsibilities, gathering evidence, and submitting with adequate time is a governance decision.
If your entity has not yet begun the process, the best time to bring it under control is now. Cyberprotech can support assessment, information preparation, and the connection between self-identification, obligations, and required evidence.
