A deadline that arrives quietly
Portuguese organisations covered by Decreto-Lei n.º 125/2025 have been counting working days since 23 June 2026, when the Centro Nacional de Cibersegurança opened its registration platform. Entities already operating were given 60 working days to identify and register themselves. That window closes in mid-September 2026 - by our count, around 15 September, with entities that started activity after the platform opened working to a shorter 30-working-day clock.
The registration form itself takes an afternoon. What most teams underestimate is everything that starts the moment they press submit. Registration is a declaration to a supervisor that you are in scope, and it turns a directive that felt abstract into a supervisory relationship with a named regulator who now has your contact details, your sector classification, and a reason to ask questions.
What the registration actually asks for
The MyCiber submission is essentially an identity and scope declaration. Expect to provide your legal entity details, the sector and subsector that places you in scope, whether you consider yourself an essential or important entity, the member states in which you provide services, and a designated point of contact for security matters.
Two of those fields carry more weight than they look. The essential versus important classification determines your maximum exposure - up to 10 million euros or 2% of worldwide annual turnover for essential entities, against 7 million euros or 1.4% for important ones - and it also determines whether you face ex-ante supervision or only reactive supervision after an incident. The cross-border services field determines whether you can expect coordinated inspections from more than one national supervisor. Neither is a box to tick casually.
Registration is a snapshot. Supervision is continuous.
The mismatch that catches organisations out is temporal. You register once, describing your organisation as it is on a Tuesday in September. Supervision then runs continuously against an organisation that changes every week - new suppliers, new systems, new people with new access, new data flowing into new places.
When CNCS opened its first audit activity earlier this year, the pattern we described in our breakdown of what CNCS is actually checking was consistent: supervisors are less interested in whether a policy document exists and far more interested in whether the organisation can show what happened, when, and who approved it. A policy is a claim. An audit is a request for evidence that the claim was true continuously, not on the day it was written.
What to keep, starting the day you register
Treat the registration date as the start of your evidence period. From that day forward, the following should be recorded in a form you can hand to a third party without editing it first:
- Every change to the scope declaration you submitted - a new subsidiary, a new member state, a reclassification - with the date the change took effect, not the date you noticed it
- Risk assessments and their revisions, each one timestamped so the sequence of your thinking is reconstructable
- Supplier and ICT third-party inventory changes, including onboarding, contract changes, and offboarding
- Incident detection, triage, and notification records, with the clock start visible - Portugal's regime, like the directive, works on an early-warning-then-full-report cadence
- Access decisions for systems holding regulated data: who was granted what, by whom, and when it was revoked
- Business continuity and recovery test results, including the ones that failed
The difference between records and evidence
Every organisation already keeps records. Logs, tickets, spreadsheets, minutes. The problem is that a record you control is a record you could have changed, and a supervisor knows that. When an auditor asks whether a risk assessment predated an incident, an internal document with an editable date field does not settle the question.
This is where cryptographic verification stops being a technical nicety and becomes a practical shortcut. If each record carries an independently verifiable proof that it existed in a specific state at a specific moment, the conversation about whether it was altered ends before it starts. We wrote about the mechanics of this in our guide to cryptographic audit trails, and the practical framing has not changed: the goal is not to prove you are trustworthy, it is to make trustworthiness unnecessary to the argument.
If you have not registered yet
- Confirm scope first, classification second - getting the sector wrong is harder to unwind than getting the tier wrong
- Nominate a security point of contact who will still be reachable in twelve months, and register a role mailbox rather than a personal one
- Do not wait for perfect internal readiness before registering - late registration is a supervisory failure in itself, and it is separate from any underlying security gap
- Run a gap check against the technical and organisational measures in the decree before the deadline, so your first supervisory contact is not also your first honest self-assessment
For a fuller walkthrough of what the decree requires beyond registration, see our analysis of what Decreto-Lei n.º 125/2025 means for Portuguese organisations. If you want to see where your organisation currently stands against the NIS2 control set, the ROOTKey NIS2 Simulator will produce a gap view in a few minutes.
And if the deeper problem is that your evidence lives in systems you would rather not hand to an auditor unedited, that is a solvable problem. You can start building a verifiable evidence layer today.
Erhalten Sie Einblicke zur Cyber-Resilienz per E-Mail
Praktische, auditfähige Hinweise zu Datenintegrität, Compliance und Kontinuität – sobald wir veröffentlichen.





