MyCiber: entities have 60 business days to register under Portugal’s new cybersecurity regime
The MyCiber platform requires entities covered by Portugal’s new Legal Framework for Cybersecurity to register within 60 business days. Learn who must act, what to prepare and how to turn compliance into digital maturity.
Published on29 June 20262Views0 Ratings0 Comments
The launch of the MyCiber platform marks a new stage for cybersecurity in Portugal. Entities covered by the new Legal Framework for Cybersecurity now have a period of 60 business days to register, complete their self-identification and begin a formal qualification process before the competent authorities. More than an administrative requirement, this step represents a structural shift in the way public and private organisations must approach the protection of their systems, data, digital services and critical assets.
According to information shared by the National Cybersecurity Centre, the MyCiber platform, available at myciber.gov.pt, becomes the main communication channel between covered entities and the competent cybersecurity authorities. Through this platform, organisations must comply with registration duties, appoint responsible officers, submit mandatory information, report incidents and monitor their status under the regime. For many entities, this will be their first formal contact with cybersecurity obligations defined by law in a more prescriptive way.
The new framework appears in a context in which the digital dependence of companies, Public Administration and essential services continues to grow. E-commerce platforms, billing systems, communications infrastructures, financial services, healthcare units, logistics operators, food producers, research entities and digital service providers are just a few examples of activities that depend on reliable technological systems. When these systems fail, the impact can go beyond the technical dimension and affect business continuity, citizens’ trust and the stability of essential services. It is therefore also part of BYDAS’ mission to be involved in these matters, even though it is not a service provider in this specific area. It is imperative to keep our client base in compliance with this new reality, not only because of legal requirements, but also because of what matters most: ensuring that all systems are secure and that those who use them are not exposed to the risk of having their data stolen.
What is the MyCiber platform?
MyCiber is the electronic platform provided for in Decree-Law no. 125/2025, created to allow essential entities, important entities and relevant public entities to fulfil their registration duty under the Legal Framework for Cybersecurity. It is made available by the National Cybersecurity Centre, as the National Cybersecurity Authority, and is used to manage relevant information on legal obligations, incident notifications and communication with the competent authorities.
In practice, the platform centralises data on regulated entities, their responsible officers, permanent points of contact, annual reports, lists of publicly accessible assets and any incident notifications. This concentration of information provides a clearer view of the level of risk, compliance status and cybersecurity measures applicable to each organisation.
MyCiber should not be seen merely as a digital form. Its purpose is to create an operational basis for monitoring compliance with the obligations set out in the new regime. By bringing together information from entities across several sectors, the platform contributes to a more dynamic reading of the national cybersecurity ecosystem and to more effective coordination between organisations and authorities.
Who has to register?
Registration applies to essential entities, important entities and relevant public entities. Scope depends on the nature of the entity, its size, sector of activity and the level of risk associated with the services it provides. Among the sectors referred to within the regime are drinking water, wastewater, banking, energy, space, waste management, business-to-business information and communication technology services, manufacturing, digital infrastructures, financial market infrastructures, research, digital services, production and distribution of chemical products, food production and distribution, healthcare, postal and courier services and transport.
Public Administration is also covered whenever it falls within the categories provided for. This scope is particularly relevant because many public services depend on digital systems to ensure service delivery, document management, payments, communication with citizens and the provision of essential services.
According to the information disclosed, around six thousand entities are expected to be covered by the new regime, a very significant increase compared with the approximately 450 entities covered by the previous framework. This growth shows that cybersecurity is no longer a concern restricted to very specific operators and has become part of the reality of a much wider range of organisations.
The 60-business-day deadline and what it means
Entities already in operation must register within 60 days of the availability of the MyCiber platform. For entities that begin activity after the entry into force of Decree-Law no. 125/2025, the stated period is 30 days after the start of activity. The obligation does not end at the time of registration: entities must keep the information provided on the platform duly updated.
This 60-business-day period should be seen as a critical window for organising internal information, confirming powers of representation, identifying responsible officers and understanding whether the entity falls within the scope of the regime. Last-minute pressure may lead to errors, omissions or difficulties in submitting documents. Organisations should therefore start the process in advance and treat registration as a strategic step.
Before registering, entities may use the simulator available on the platform to test their possible classification. The result is indicative and depends on the accuracy of the information provided. It does not bind the National Cybersecurity Centre and does not exempt covered entities from mandatory registration, but it can help clarify initial doubts and prepare the necessary documentation.
Registration, self-identification and qualification: three essential concepts
The process provided for in MyCiber involves more than creating an account. First, the entity must register on the platform. It must then complete its self-identification, declaring information that allows the authorities to assess whether it is covered by the regime and which category it may fall into. Finally, the competent authorities analyse the information and issue a Draft Qualification Act.
This draft may conclude that the entity is not covered or that it is covered, indicating its respective qualification. If the entity disagrees or wishes to correct information, it has a hearing period for interested parties, referred to as 10 business days after the notification is sent. If the entity does not respond, the information is confirmed and the entity receives the Qualification Act. From that moment onwards, the obligations arising from the Legal Framework for Cybersecurity formally apply.
Qualification is decisive because it defines the applicable level of requirement. Essential entities, important entities and relevant public entities may be subject to different sets of minimum measures, adjusted to risk, size and sector of activity. This logic seeks to avoid a generic approach and to create more predictable criteria for organisations and authorities.
What information must be communicated through MyCiber?
After qualification, covered entities must use the platform to communicate several obligations. These include the appointment of the Cybersecurity Officer, the appointment of the Permanent Point of Contact, the submission of the annual report, the submission of the list of publicly accessible assets and the notification of incidents.
The Cybersecurity Officer plays a central role in the organisation’s internal and external coordination. This person must understand the risks, monitor the implementation of measures, promote good practices and ensure the connection with legal obligations. The Permanent Point of Contact, in turn, ensures that there is an operational communication channel with the competent authorities, which is essential in the event of an incident or the need for a rapid response.
The list of publicly accessible assets is another important element. Websites, applications, portals, online stores, APIs, servers and other systems exposed to the Internet represent potential entry points for attacks. An entity that does not know its digital assets can hardly protect them effectively. This mapping is therefore a fundamental step in reducing risk and establishing intervention priorities.
Minimum measures and the 24-month adaptation period
One of the main differences compared with the previous regime lies in the definition of minimum measures. Previously, the logic was mainly based on the risk analysis carried out by the entity, which then implemented the measures it considered appropriate. That approach could be flexible, but it also created uncertainty. Many organisations struggled to understand what was sufficient, acceptable or proportional.
The new model is more prescriptive. After qualification, entities receive a set of minimum measures that must be implemented within 24 months. This period should not be interpreted as a postponement of the problem, but as an opportunity to structure an internal transformation. In two years, an organisation can review policies, train teams, strengthen access controls, document processes, test incident response plans and improve the security of its systems.
Minimum measures should be seen as a basis for maturity. For some entities, they will represent a starting point. For others, they will allow existing practices to be formalised. In any case, the goal is to reduce risk to an acceptable level and ensure that essential and critical services maintain a high level of cybersecurity.
Why is this new regime so relevant?
The increase in cyberattacks, the sophistication of cybercrime, the activity of state actors, activism in cyberspace and the rapid evolution of technologies such as generative artificial intelligence make cybersecurity a national priority. Threats are no longer limited to viruses or suspicious messages. Today, they include credential theft, exploitation of vulnerabilities, data hijacking, attacks on suppliers, phishing campaigns, information manipulation and service disruption.
In an interconnected digital environment, a failure in one entity can affect customers, partners, suppliers and end users. A vulnerable technology provider can compromise several companies. An unavailable public portal can prevent citizens from accessing essential services. An insecure online store can expose customer data and damage a brand’s reputation. Cybersecurity has therefore become part of risk management, operational continuity and digital trust.
For companies with a significant digital presence, security is not only a legal requirement. It is also a competitive factor. Customers, partners and investors value organisations that are able to protect data, ensure availability and respond to incidents transparently. Trust has become a digital asset.
The role of the National Cybersecurity Reference Framework
The new regulation includes structuring instruments, among them the National Cybersecurity Reference Framework. This framework defines good cybersecurity practices in Portugal and gives entities a clearer reference for maturity, control and compliance.
One of the new features is the possibility for entities to obtain a certificate of compliance with the National Cybersecurity Reference Framework or with the digital maturity seal in the cybersecurity component. This type of certification can provide greater comfort to management and internal responsible officers by demonstrating that the organisation follows recognised practices and complies with relevant obligations.
Certification should not be seen as an end in itself. Its real value lies in the improvement process that supports it: risk identification, definition of responsibilities, access control, asset protection, incident response, monitoring, training and continuous review. Cybersecurity is a permanent cycle, not a project with a definitive closing date.
What entities should prepare before registration
To start registration on MyCiber, it is necessary to ensure the appropriate authentication means and documentation. The platform provides for the use of the Chave Móvel Digital or the Citizen Card with a card reader. In cases where the legal representative does not have the Professional Attribute Certification System, it may be necessary to present proof of powers of representation. When the registration is carried out by another person, internal or external, there must be a document proving the mandate or the attribution of specific powers.
In addition to these formal elements, it is advisable for the entity to gather in advance information on its structure, activity, sector, services provided, digital assets, internal contacts, technical officers and any critical suppliers. The more organised the information is, the simpler the registration and self-identification process will be.
This preparation can also reveal important gaps. Many organisations discover, during this type of exercise, that they do not have an updated inventory of systems, that access rights are not properly documented or that there is no formal process for reporting incidents. Although these shortcomings may seem administrative, they have a direct impact on the ability to respond to attacks.
How to create a cybersecurity culture
The final step indicated by the platform’s own logic is to implement a cybersecurity culture that ensures compliance with legal obligations. This expression is important because digital protection does not depend solely on technology. It also depends on people, processes, management decisions and daily habits.
A cybersecurity culture begins with management. Without leadership involvement, initiatives tend to remain limited to the technical department. It is necessary to define priorities, allocate resources, make teams accountable and integrate security into business decisions. The question is no longer simply «do we have antivirus?» but rather «can we maintain operations if a serious incident occurs?».
Employee training is equally decisive. A large proportion of incidents begins with human error, compromised credentials or fraudulent messages. Awareness should be practical, regular and adapted to the functions of each team. A finance team faces different risks from a customer service, marketing or technology development team.
It is also essential to review suppliers. Many companies depend on external platforms for hosting, payments, communication, management software, commercial automation or customer support. The organisation’s security depends, in part, on the security of these partners. Contracts, access rights, integrations and responsibilities should be reviewed carefully.
Impact on companies with online stores and digital services
Companies that operate online stores, booking platforms, customer portals, applications or digital services should pay special attention to this new context. Even when they are not directly covered as essential or important entities, they may be part of the supply chains of covered organisations. This means that cybersecurity requirements may also reach them through contractual, commercial or reputational routes.
In a Shopify project, for example, security should be considered from the store architecture to access management, installed applications, integrations with external systems, payment methods and the processing of personal data. An online store may offer an excellent shopping experience, but if it does not have secure processes, clear policies and proper maintenance, it is exposed to risks that affect sales and trust.
The same applies to institutional websites and lead generation projects. Technical SEO, performance and security often go hand in hand. A slow, outdated, vulnerable or poorly configured website damages the user experience and may affect organic visibility. Security is not a hidden detail on the server; it is part of the overall quality of the digital presence.
From legal obligation to improvement opportunity
Registration on MyCiber may, at first glance, seem like another legal obligation. However, organisations should use this moment to improve internal processes and gain maturity. The need to appoint responsible officers, list assets, notify incidents and implement minimum measures creates an opportunity to organise what is often scattered.
A good response involves turning the obligation into an action plan. First, confirm whether the entity is covered. Then prepare the registration and documentation. Next, identify internal responsibilities. Finally, map existing measures, understand gaps and define priorities for the 24-month adaptation period.
This approach avoids reactive decisions. In cybersecurity, acting only after an incident is almost always more expensive. The impact may include system unavailability, data loss, revenue disruption, reputational damage, legal costs and loss of trust. Prevention, on the other hand, reduces exposure, improves response and demonstrates diligence.
Sanctions and entity responsibility
Failure to comply with the obligations set out in the new Legal Framework for Cybersecurity, including the registration obligation, may result in sanctions. The value of fines depends on the entity’s qualification and the severity of the offence. This sanctioning dimension reinforces the need to treat the matter seriously, but it should not be the only reason to act.
The digital responsibility of organisations goes beyond a fine. When an entity provides critical services, manages sensitive data or maintains publicly accessible systems, it assumes a responsibility towards customers, citizens, partners and employees. Complying with the law is the minimum; building resilience is the more important goal.
For boards and management teams, cybersecurity should be present in strategic decisions. Investments in technology, supplier contracting, the launch of digital platforms, marketing campaigns, integrations with third parties and data collection should also be assessed from the perspective of digital risk.
What should be done now?
Potentially covered entities should begin by analysing their status under the regime and using the simulator available on MyCiber as indicative support. They should then gather documentation, confirm who can complete the registration, identify representatives and prepare information about their activity and digital assets. From there, registration must be completed within the applicable deadline.
After registration, the organisation should monitor notifications, analyse the Draft Qualification Act and prepare to comply with the obligations arising from the Qualification Act. The appointment of the Cybersecurity Officer and the Permanent Point of Contact should be made carefully, as these roles will be essential for the relationship with the authorities and for the internal management of the process.
In parallel, it is prudent to start a cybersecurity diagnosis. This diagnosis may include an inventory of assets, access review, supplier assessment, vulnerability analysis, password policies, backups, an incident response plan, employee training and a review of digital platforms. The sooner this assessment begins, the more controlled the adaptation path will be.
Cybersecurity as part of digital strategy
The launch of MyCiber confirms a clear trend: the digital presence of organisations requires governance, control and responsibility. It is no longer enough to have a website, an online store, a customer service platform or an internal system. It is necessary to ensure that these assets are known, protected, monitored and managed over time.
For companies, this means bringing management, technology, marketing, operations and legal teams closer together. Security should be integrated into the planning of digital projects from the outset, rather than added only at the end. This logic reduces costs, avoids rework and improves the quality of solutions.
Cybersecurity also has a communication dimension. In the event of an incident, the way an organisation communicates can influence market trust. Transparency, speed and clarity are essential. Therefore, response plans should include not only technical measures, but also internal and external communication procedures.
Conclusion
The MyCiber platform opens a more demanding phase for cybersecurity in Portugal. The 60-business-day deadline for registration and self-identification should be seen as the beginning of a journey towards compliance, maturity and resilience. For many entities, the coming months will be decisive for understanding obligations, structuring responsibilities and preparing the implementation of minimum measures within 24 months.
The new Legal Framework for Cybersecurity seeks to respond to an increasingly complex threat landscape. By requiring registration, qualification, responsible officers, incident reporting and minimum measures, it creates a more robust basis for protecting essential services, public organisations, private companies and citizens. Digitalisation has brought efficiency, scale and new opportunities, but it has also increased exposure to risk. The response must be proportional, organised and continuous.
BYDAS helps brands and companies build a digital presence with strategic vision, performance and security. In online store projects, web development and digital consultancy, technical preparation is essential to grow with confidence in an increasingly regulated market.
If you enjoyed the article, follow us on LinkedIn...
Add this source to your preferred sources
Rate this article
0 Comments