{"id":21735,"date":"2026-07-27T05:00:04","date_gmt":"2026-07-27T04:00:04","guid":{"rendered":"https:\/\/belzuz.com\/?post_type=publicacion&#038;p=21735"},"modified":"2026-07-24T12:31:55","modified_gmt":"2026-07-24T11:31:55","slug":"cybersecurity-legal-framework-_myciber","status":"publish","type":"publicacion","link":"https:\/\/belzuz.com\/en\/publicacion\/cybersecurity-legal-framework-_myciber\/","title":{"rendered":"Portugal\u2019s Cybersecurity Legal Framework._MyCiber: Before Registering, Confirm Whether Your Company Falls Within Its Scope"},"content":{"rendered":"<p>Why should the entity\u2019s position be assessed before registration?<\/p>\n<p>Portugal\u2019s Cybersecurity Legal Framework, approved by Decree-Law No. 125\/2025 of 4 December, transposed the NIS 2 Directive into Portuguese law and broadened the range of entities subject to cybersecurity obligations.<\/p>\n<p>The obligation to identify and register on MyCiber applies to entities falling within Article 3 of that framework, which may be classified as:<\/p>\n<ul>\n<li>essential entities;<\/li>\n<li>important entities; or<\/li>\n<li>relevant public entities.<\/li>\n<\/ul>\n<p>Whether the framework applies should not be determined solely by reference to the entity\u2019s principal activity or economic activity code. It requires an analysis of the activities actually carried out, the size of the organisation and the general and specific criteria laid down by law.<\/p>\n<p>This assessment should precede registration, as the information submitted will be examined by the Portuguese National Cybersecurity Centre or, where applicable, the competent national sectoral authority, in order to determine whether the entity falls within the scope of the framework and how it should be classified.<\/p>\n<p>In the procedures we are currently advising on, it has been necessary to go beyond the entity\u2019s corporate purpose and economic activity code, identify the different activities carried out and, where applicable, examine the group\u2019s corporate structure in order to determine the relevant size of the entity.<\/p>\n<h2>Is the simulator provided by the Portuguese National Cybersecurity Centre sufficient?<\/h2>\n<p>No. The simulator may assist with a preliminary assessment of the scope of the framework, but its result is merely indicative, depends on the information entered and is not subject to formal assessment by the Portuguese National Cybersecurity Centre.<\/p>\n<p>Furthermore, the simulator does not cover the criteria laid down in Article 3(2)(b), (c), (d) and (e), or Article 3(5), of Decree-Law No. 125\/2025. Nor does use of the simulator release entities falling within the scope of the framework from the registration obligation.<\/p>\n<p>In our work with clients, the simulator\u2019s result is used as a supporting element and assessed against the activities carried out, the size of the organisation and the legal criteria not taken into account by the tool.<\/p>\n<p>The simulator may therefore provide a useful starting point, but it is no substitute for a legal assessment of the entity\u2019s position.<\/p>\n<h2>What information should be validated before submission?<\/h2>\n<p>Before completing the registration, the information concerning the activities carried out, the size of the entity and the sector or sectors in which it operates should be checked for consistency.<\/p>\n<p>This assessment is particularly important where the entity:<\/p>\n<ul>\n<li>carries out more than one activity;<\/li>\n<li>operates across different sectors;<\/li>\n<li>forms part of a corporate group;<\/li>\n<li>has relationships with partner or associated companies that are relevant to determining its size; or<\/li>\n<li>carries out an activity whose classification is not immediately apparent from the categories established under the framework.<\/li>\n<\/ul>\n<p>These are the situations most frequently encountered by the Cybersecurity Department at <strong><a href=\"https:\/\/belzuz.com\/en\/\">Belzuz Abogados, S.L.P.<\/a> <\/strong>in the legal advice it provides to clients. Depending on the circumstances, preparing the registration has required information concerning the activities carried out, the corporate structure, the number of employees and the relevant financial data to be brought together, so that the information submitted accurately reflects the organisation\u2019s circumstances.<\/p>\n<p>It is also necessary to verify who has authority to represent the entity on MyCiber and which documents are required to evidence that authority.<\/p>\n<p>Preparing the registration should therefore not be limited to completing the fields on the platform. The information submitted must be consistent and properly substantiated and must enable the competent authority to assess the entity\u2019s position correctly.<\/p>\n<h2>What is the deadline for registration?<\/h2>\n<p>Entities that were already operating before the Cybersecurity Legal Framework entered into force must register within 60 working days of the platform being made available.<\/p>\n<p>Entities that began operating after the framework entered into force have 30 working days in which to comply with this obligation.<\/p>\n<p>The applicable deadline should be confirmed considering the entity\u2019s specific circumstances. The need to register within the relevant period does not remove the requirement to assess the entity\u2019s position beforehand.<\/p>\n<h2>Can a lawyer complete the registration on behalf of the entity?<\/h2>\n<p>Yes. The registration may be completed by the entity\u2019s legal representative or by an individual, whether internal or external to the organisation, who has been granted the necessary authority for that purpose.<\/p>\n<p>A lawyer may therefore complete the MyCiber registration in the name and on behalf of the entity, provided that the lawyer has the necessary authority to represent it.<\/p>\n<p><strong><a href=\"https:\/\/belzuz.com\/en\/\">Belzuz Abogados, S.L.P.<\/a><\/strong> has been providing clients with comprehensive support throughout this process: we assess the entity\u2019s position, validate the required information with the client, prepare the necessary powers of representation and, where instructed to do so, complete the registration on the entity\u2019s behalf.<\/p>\n<h2>Does registration automatically determine the entity\u2019s classification?<\/h2>\n<p>No. Registration initiates the classification procedure.<\/p>\n<p>Based on the information submitted, the Portuguese National Cybersecurity Centre or, where applicable, the competent national sectoral authority will assess whether the entity falls within the scope of the Cybersecurity Legal Framework and which category applies.<\/p>\n<p>The entity will be notified of a draft classification decision stating:<\/p>\n<ul>\n<li>that the entity does not fall within the scope of the framework; or<\/li>\n<li>that the entity falls within its scope and specifying the applicable classification.<\/li>\n<\/ul>\n<p>The entity may submit representations as part of the interested-party hearing procedure within 10 working days of the notification being sent. Once the procedure has been completed, a final classification decision will be issued.<\/p>\n<h2>Why should the draft classification decision be reviewed?<\/h2>\n<p>The draft decision should be reviewed considering the factual and legal grounds on which it is based.<\/p>\n<p>It is important to verify whether the competent authority has correctly considered:<\/p>\n<ul>\n<li>the activities actually carried out by the entity;<\/li>\n<li>the relevant sector;<\/li>\n<li>the size of the organisation;<\/li>\n<li>any specific criteria that may apply; and<\/li>\n<li>the information submitted as part of the registration.<\/li>\n<\/ul>\n<p>If the proposed classification does not reflect the entity\u2019s circumstances, or if the information considered requires correction or clarification, the entity should consider exercising its right to be heard within the period granted.<\/p>\n<p>In the procedures we advise on, the information supporting the registration is validated and documented from the outset, so that it can be properly substantiated during the classification procedure.<\/p>\n<p>Legal advice does not therefore end once the registration has been submitted. It should extend to reviewing the draft decision and, where appropriate, preparing the entity\u2019s representations.<\/p>\n<h2>Which obligations should be prepared for while the classification procedure is under way?<\/h2>\n<p>The entity should not wait until the procedure has been completed before beginning to prepare for the obligations that may arise from its classification.<\/p>\n<p>Within 20 working days of notification of the final classification, the entity must communicate through MyCiber:<\/p>\n<ul>\n<li>the person responsible for cybersecurity; and<\/li>\n<li>the individual or individuals performing the role of permanent point of contact.<\/li>\n<\/ul>\n<p>These roles should be defined before the deadline expires, with the designated individuals clearly identified and their coordination with the organisation\u2019s internal risk management and incident response procedures properly established.<\/p>\n<p>For our clients, these decisions are prepared during the classification procedure by defining the relevant roles, the authority required and their interaction with each organisation\u2019s internal structures.<\/p>\n<h2>When must the list of assets be submitted?<\/h2>\n<p>Essential entities, important entities and relevant public entities must submit their list of assets by 31 January 2027 or within six months of notification of the final classification, whichever deadline falls first.<\/p>\n<p>Compliance with this obligation requires the identification of the assets relevant to the entity\u2019s networks and information systems. This work should not be postponed until the final classification is issued: it requires the prior involvement of the relevant teams and the identification and validation of the information to be reported.<\/p>\n<h2>Are the incident notification procedures ready?<\/h2>\n<p>Entities that fall within the scope of the framework and have been registered and classified must use the restricted area of MyCiber to notify incidents having a significant impact.<\/p>\n<p>The initial notification must be submitted within 24 hours of the entity becoming aware of the incident. Any subsequent notifications and reports relating to the same incident must also be submitted through the platform.<\/p>\n<p>Meeting this deadline requires the entity to have determined in advance:<\/p>\n<ul>\n<li>who receives information concerning the incident internally;<\/li>\n<li>who assesses its significance;<\/li>\n<li>who decides whether notification is required;<\/li>\n<li>who is responsible for submitting the notification through the platform; and<\/li>\n<li>how the information required for subsequent communications will be collected and validated.<\/li>\n<\/ul>\n<p>When reviewing these procedures with our clients, the <strong><a href=\"https:\/\/belzuz.com\/en\/\">Belzuz Abogados, S.L.P.<\/a> <\/strong>team providing specialist legal advice on cyber risk, cybersecurity and digital compliance has found that the principal challenge is not access to the platform, but the speed at which information circulates internally and reaches the designated individuals with authority to assess the incident and decide whether it should be notified.<\/p>\n<p>It is therefore not sufficient merely to identify who will have access to MyCiber. The organisation must ensure that an internal process is in place to detect, assess and report an incident within the applicable deadline.<\/p>\n<h2>When will the cybersecurity measures become enforceable?<\/h2>\n<p>The Regulation implementing the Cybersecurity Legal Framework was published on 22 June 2026 and entered into force the following day.<\/p>\n<p>Its publication triggered the statutory 24-month period after which the cybersecurity measures will take effect and the submission of the annual report by essential entities will become mandatory.<\/p>\n<p>This period does not suspend or postpone obligations that are already under way, including registration, the classification procedure and the communications required following the final classification decision.<\/p>\n<h2>What should entities do now?<\/h2>\n<p>Entities that may potentially fall within the scope of the framework should begin by confirming their position under the Cybersecurity Legal Framework.<\/p>\n<p>They should now:<\/p>\n<ul>\n<li>identify the activities actually carried out and the applicable legal criteria;<\/li>\n<li>verify the size of the entity and, where relevant, the corporate relationships that must be taken into account;<\/li>\n<li>collect and validate the necessary information and formalise the authority to represent the entity;<\/li>\n<li>prepare and complete the registration within the applicable deadline;<\/li>\n<li>follow the classification procedure; and<\/li>\n<li>anticipate the appointment of those performing the roles prescribed by law, the identification of assets and the review of incident notification procedures.<\/li>\n<\/ul>\n<p>The priority is not merely to complete the registration within the applicable deadline.<\/p>\n<p>It is to ensure that the entity\u2019s position has been correctly determined that the information submitted accurately reflects its circumstances and that the organisation is prepared for the obligations that may arise from its classification.<\/p>\n<p>The <strong><a href=\"https:\/\/belzuz.com\/en\/\">Belzuz Abogados, S.L.P.<\/a><\/strong> <strong>Cybersecurity and Digital Compliance<\/strong> team provides comprehensive legal advice in the following areas:<\/p>\n<ul>\n<li><strong>Incident response:<\/strong> legal support in cases involving personal data breaches, ransomware attacks or computer-related fraud.<\/li>\n<li><strong>Regulatory compliance:<\/strong> legal assessment and registration on the MyCiber platform, audits, GDPR compliance and cybersecurity procedures in Portugal and the European Union.<\/li>\n<li><strong>Litigation and criminal matters:<\/strong> representation in cybercrime proceedings, including matters involving hacking and phishing, and related investigations.<\/li>\n<\/ul>\n","protected":false},"featured_media":18971,"template":"","categories":[514],"area-de-practica":[511,220,512,513],"publicaciones":[123],"idioma-publicacion":[71],"areas-practica-publicacciones":[],"class_list":["post-21735","publicacion","type-publicacion","status-publish","has-post-thumbnail","hentry","category-sin-categorizar","area-de-practica-comercial","area-de-practica-commercial-law","area-de-practica-ma","area-de-practica-societario","publicaciones-patricia-boavida","idioma-publicacion-ingles"],"acf":[],"_links":{"self":[{"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/publicacion\/21735","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/publicacion"}],"about":[{"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/types\/publicacion"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/media\/18971"}],"wp:attachment":[{"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/media?parent=21735"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/categories?post=21735"},{"taxonomy":"area-de-practica","embeddable":true,"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/area-de-practica?post=21735"},{"taxonomy":"publicaciones","embeddable":true,"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/publicaciones?post=21735"},{"taxonomy":"idioma-publicacion","embeddable":true,"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/idioma-publicacion?post=21735"},{"taxonomy":"areas-practica-publicacciones","embeddable":true,"href":"https:\/\/belzuz.com\/en\/wp-json\/wp\/v2\/areas-practica-publicacciones?post=21735"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}