Framework assessment comes before the form

MyCiber self-identification should not begin with improvised answers. Before entering the platform, the organization needs to understand its nature, the activities it actually performs, the relevant sectors and subsectors, its size, and the territory in which it provides services.

Article 8 of the Portuguese Cybersecurity Legal Framework establishes the identification and qualification procedure. Regulation No. 756/2026 implements the platform's operation and clarifies that automated support tools are informational: they do not constitute an official decision or remove the need to submit the form when it is mandatory.

The question “Are we in scope?” should therefore rarely receive only an immediate yes or no. It should initiate a traceable analysis containing facts, assumptions, uncertainties, and elements that can be confirmed.

Who should pay attention

The framework covers entities of the types and sectors provided for in Decree-Law No. 125/2025, including entities that may be qualified as essential, important, or relevant public entities. The analysis should not be limited to the commercial name of an activity or its economic-activity code.

An organization may provide several services, operate in more than one sector, belong to a corporate group, or play a relevant role in a supply chain. Its declared primary activity may also differ from the digital, operational, or infrastructure services it actually provides.

  • Companies and private entities operating in sectors listed in Annex I or II of the RJCS.
  • Municipalities, intermunicipal entities, public-administration bodies, and public business entities.
  • Organizations with different activities in the same group or relevant services provided to third parties.
  • Entities whose size, territory, establishment, or legal nature requires confirmation.
  • Organizations that do not yet know whether a specific activity corresponds to a legal sector or subsector.

The data that should be organized

A reliable initial assessment depends on information quality. It is not necessary to know every answer in advance, but confirmed facts, estimates, and questions still requiring validation should be clearly distinguished.

The information should reflect the legal entity being identified, not a generic perception of the group, brand, or organization. Where several legal entities exist, the framework may need to be assessed individually.

  • Private, public, public business, or autonomous-administration status.
  • Activities, services, and functions actually performed.
  • Potentially applicable sector and subsector, including relevant secondary activities.
  • Number of employees and, where applicable, financial data used to determine size.
  • Place of establishment, operating territory, and cross-border service provision.
  • Group structure, control relationships, and entities sharing services or infrastructure.
  • Legal representative and any authority to act on the platform.

Sector and size should not be presumed

Annexes I and II of the Decree-Law identify entity types and sectors, but matching them requires a substantive reading of the activity. A similar designation does not guarantee the same framework, and an apparently secondary activity may be legally relevant.

Size is not always simply a headcount. Depending on the entity, the thresholds and rules in Annex III and group relationships may be relevant. For public entities, the framework establishes specific criteria for Groups A and B.

When information is missing, the responsible answer is to identify the uncertainty and the document or person who can clarify it. A clearly identified provisional answer is more useful than an unsupported definitive conclusion.

A checker provides guidance; it does not qualify

Cyberprotech provides a preliminary guidance pathway on its homepage. The tool organizes known answers, identifies relevant elements, and highlights what should be confirmed before a decision or submission.

The result is not an official qualification, an automatic legal declaration, or a replacement for the MyCiber platform. Qualification belongs to the legal procedure and the competent cybersecurity authority.

The tool's value lies in reducing initial noise: it helps identify what information exists, what is missing, which hypotheses merit validation, and the proportionate next step.

How the five-step pathway works

The pathway was designed so the organization answers only what it knows. Subsequent choices adapt to earlier information, avoiding long legal lists without context.

At the end, the organization can save the guidance or request validation. When a supported process is created, it receives a unique reference and private link for viewing messages, attaching documents, and proposing a meeting.

  • Identify the organization's nature.
  • Select the sector and approximate the activity type using plain language.
  • Record known size and structure elements.
  • Identify questions, exceptions, or unconfirmed data.
  • Review the summary and, where necessary, request human validation.

What happens when you request validation

The request creates a separate supported process identified by a unique reference. The team can analyze the answers, request clarification, and indicate which documents help confirm the framework.

The private link makes it possible to track status, exchange messages, submit described documents, and propose a meeting. The aim is to preserve context and prevent important decisions from being scattered across several emails or unrecorded conversations.

Validation may confirm an analytical direction, identify missing information, or recommend specialized legal review. It does not make Cyberprotech the competent authority or replace the decision issued through the official procedure.

Data protection and proportionality

The initial pathway should collect only the data required to organize guidance and, when requested, enable contact and support. Secrets, credentials, classified information, or documents unrelated to the analysis should not be submitted.

Before submission, users see the data that will be recorded and accept the applicable privacy policy. Subscription to alerts and news is optional and independent of the validation request.

The support link is private and should be stored like any other means of access. Documents should be limited to what is necessary, correctly identified, and reviewed before upload.

Documents that may help confirm the framework

Not every process requires the same documents. Selection should be proportionate to the specific question and may begin with simple elements rather than complete dossiers.

  • Permanent commercial certificate, bylaws, or equivalent document confirming the entity and its purpose.
  • Description of services actually provided and their recipients.
  • Organization chart or group diagram where several legal entities exist.
  • Human-resources and financial elements strictly necessary to confirm size.
  • Contracts, licenses, or authorizations that help characterize a regulated activity.
  • Internal record of the criteria, sources, and assumptions used in the analysis.

Mistakes to avoid

Urgency can turn self-identification into a merely administrative exercise. The objective should be to provide coherent, supported information prepared for updating.

  • Concluding that the entity is not in scope solely because it is small.
  • Using only the economic-activity code to determine the sector and ignoring services actually provided.
  • Answering for the entire group without distinguishing each legal entity.
  • Confusing preliminary guidance with official qualification.
  • Submitting data without retaining sources, assumptions, and internal approvals.
  • Postponing preparation because a question remains: uncertainties should also be recorded and directed appropriately.

From framework assessment to implementation

Qualification is not the end of the pathway. The RJCS and Regulation connect the framework to cybersecurity measures, governance, risk management, evidence, communications, the Cybersecurity Officer (RCS), Permanent Contact Point (PCP), reports, and incident notification.

A sound initial analysis should therefore leave a reusable trail: who decided, what data was used, which uncertainties remain, and what actions should follow. This record helps turn compliance into operational capability instead of creating just another completed form.

If your organization still does not know where to begin, use the checker on the homepage. Answer what you know, record questions, and request validation only when you need support.