Lead capture

Receive the full diagnosis and personalised recommendations

_ CYBERSECURITY

MyCiber, what is it?

Who has to comply and what are the deadlines for companies?   

João Mota

CTO | CMO

Who has to comply and what are the deadlines for companies?

Cybersecurity is no longer exclusively an issue for large organisations. With the rise in cyber attacks and the increasing digitalisation of businesses, Small and Medium-sized Enterprises (SMEs) are also facing new challenges and responsibilities today.

In this context, the MyCiber, the platform made available by National Cybersecurity Centre, plays an important role in the implementation of the NIS2 Directive in Portugal, enabling organisations to communicate essential information about their activity and legal framework.

But what is MyCiber after all? Who is covered? And what deadlines must companies meet?

What is MyCiber?

O MyCiber it is the online platform created by National Cybersecurity Centre which allows Portuguese organisations to interact with the national cybersecurity authority.

Through this platform, organisations can:

  • Registering as entities covered by the legislation;
  • Update organisation details;
  • Report cybersecurity incidents, where applicable;
  • Manage the obligations set out in the new legal framework of the NIS2 Directive.

In practice, MyCiber will be the main communication channel between the covered companies and the CNCS.

Why was this platform created?

The creation of MyCiber is directly related to the entry into force of the NIS2 Directive, which has significantly reinforced cybersecurity requirements across the European Union.

Automated out-of-office replies make communication with clients and partners easier, but they must be set up with some care.

Compared to the previous NIS Directive, NIS2:

  • It covers a much larger number of companies;
  • It introduces new risk management obligations;
  • Reinforces the responsibilities of top management;
  • Demand more rigorous incident reporting processes;
  • It provides for higher penalties in the event of non-compliance.

In Portugal, the CNCS will be the entity responsible for monitoring the implementation of these obligations, with MyCiber being one of the fundamental tools for this purpose.

Which companies may be covered?

One of the biggest doubts companies have relates precisely to this issue.

Many SMEs mistakenly assume that NIS2 only applies to large companies or critical infrastructure. However, this reality has changed.

The Directive may cover companies of different sizes, depending on factors such as: number of employees, turnover, sector of activity and importance of the services provided.

Even companies that are not directly covered may be called upon by their clients to demonstrate adequate levels of cybersecurity, particularly when they are part of the supply chain.

Find out via the button below all the companies that are covered. In doubtful cases, it is always advisable to register on the platform.

What happens if the company is covered?

Should the organisation be deemed an entity covered by NIS2, it will have to comply with several obligations, among which:

  • Implement cybersecurity risk management measures;
  • Develop internal security policies;
  • Define incident response procedures;
  • Assess risks associated with suppliers;
  • Promote employee training and awareness;
  • Report significant incidents within the legal deadlines;
  • Keep data up to date on the MyCiber platform.

In other words, making a registration is not enough. There is a set of ongoing responsibilities that should form part of the company's strategy.

What are the deadlines that companies need to know about?

This is one of the issues that most concerns managers.

Following the entry into operation of the MyCiber platform, entities that fall within the scope of the NIS2 Directive must proceed with their registration within the deadline defined by the CNCS.

In addition, whenever relevant changes occur within the organisation, such as changes to contact details, persons in charge or other mandatory information, these details must be updated on the platform.

Another critical point relates to the cybersecurity incident report.

The NIS2 Directive establishes very demanding deadlines for reporting significant incidents, providing for an initial notification within a short space of time after their detection, followed by supplementary reports as the investigation evolves.

For this reason, it is essential that companies have internal processes for incident detection, response and communication defined in advance.

Important: National regulation of the NIS2 Directive is still evolving. For this reason, companies must follow the guidance issued by the CNCS, as new requirements or updates to registration procedures may arise.

Is MyCiber just a registration platform?

No. Although many companies associate MyCiber only with mandatory registration, its purpose goes far beyond that function.

The platform has been designed to support the entire relationship between the covered entities and the CNCS, acting as a central point for:

  • Corporate communications;
  • Management of legal obligations;
  • Incident report;
  • Organisation information update.

Therefore, their role will become increasingly relevant as the implementation of NIS2 progresses in Portugal.

How can SMEs prepare?

Regardless of whether or not they are already covered, this is a good time for SMEs to assess their level of cybersecurity maturity.

Some priority measures include:

  • Identify whether the company falls within the scope of NIS2;
  • Assess existing technological risks;
  • Review internal policies and procedures;
  • Implement protection and monitoring solutions;
  • Ensure backups are carried out;
  • Regularly raise awareness among employees;
  • Create an incident response plan.

The earlier these measures are implemented, the lower the effort required to adapt to the new legal requirements.

The role of cybersecurity consultancy

For many SMEs, interpreting legislation and understanding which obligations apply can be a complex process.

An expert consultancy makes it possible to determine whether the organisation falls within the scope, assess the level of compliance and define an implementation plan tailored to the company's reality. Rather than merely complying with legal requirements, it is about reducing operational risks, protecting business continuity and strengthening the trust of clients and partners.

Conclusion

The MyCiber platform represents an important step in the implementation of the NIS2 Directive in Portugal and will be a central element in the relationship between the companies covered and the National Cybersecurity Centre.

Even though many SMEs are still not sure whether they are covered, ignoring this issue could lead to future difficulties, whether through legal imposition or the demands of clients and business partners.

No Quantinfor, we closely monitor the evolution of cybersecurity legislation and help companies identify whether they fall within the scope of NIS2, implement the necessary measures and prepare to comply with the new legal obligations.

We also provide a Permanent Point of Contact service, one of the obligations provided for the covered entities, ensuring technical monitoring and continuous support in the relationship with the CNCS and in compliance with NIS2 requirements.

If you would like to understand how these obligations apply to your company or need support in adapting to NIS2, you can schedule a chat with the João Mota, CTO of Quantinfor:

https://calendly.com/joaomotaquantinfor/30min

Frequently Asked Questions (FAQ)

  • What is the deadline for registering existing entities?

The entities already existing before the publication of the Regulation No. 756/2026 you must register on the platform MyCiber within 60 working days.

  • What is the deadline for entities established after the publication of the Regulation?

Entities established after the publication of the Regulation must register on the platform MyCiber within 30 working days from the start of their activity.

  • When must the Cybersecurity Officer and the Permanent Contact Point be notified?

Following the definitive qualification of the entity, the CNCS must be notified of the Cyber Security Manager and Permanent Point of Contact, within the period of 20 working days.

A Quantinfor do you provide the service of Permanent Point of Contact, supporting organisations in fulfilling this obligation and ensuring the necessary technical monitoring.

  • By when must the minimum cybersecurity measures be implemented?

The covered entities have 24 months, counted from the publication of the Regulation No. 756/2026, to implement the minimum cybersecurity measures provided for.

  • My company has doubts as to whether it is covered by NIS2. What should I do?

Should there be any doubts regarding the scope of application of the legislation, the CNCS recommends that the entity register on the platform MyCiber and await the formal decision on your grading.

  • Where can I obtain clarification on the legal framework?

For clarifications related to the legal regime of NIS2 and the platform MyCiber, the CNCS provides the email address:

maisciber@cncs.gov.pt

Scroll to Top