Practical guide | Preparation

How to prepare for MyCiber registration: a company checklist

Preparing for MyCiber registration does not mean guessing the company's qualification. It means gathering accurate information, confirming who can represent the entity, and keeping a clear record of what was submitted.

Use this checklist as operational preparation. Required information may vary by entity and competent authority. Always confirm the platform form, official notices, and the communications received.

1. Assign the person responsible

The process should be handled by the legal representative or a person with authority to represent the entity. Before starting, decide who gathers the data, who authenticates the entity, and who monitors later notices.

  • Assign an internal owner for the process.
  • Confirm whether that person is the legal representative or has a valid mandate.
  • Assign a second person to monitor deadlines and communications.

2. Gather the entity's core data

Regulation no. 756/2026 lists self-identification data that may be needed for qualification. Gather it before opening the form, but do not send information that the platform does not request.

  • Legal name and tax identification number.
  • Address, establishment, and current contact details.
  • Email addresses that should receive notices.
  • Employee count and, when applicable, annual turnover or balance sheet.
  • Relevant sector and subsector, if applicable.
  • EU Member States where covered services are provided, when applicable.

3. Confirm representation and authentication

The platform provides for authentication using a high-assurance electronic identification system and allows representation through legally valid means. Confirm internally that the person submitting the form has the authority to do so.

  • Check the Citizen Card, Digital Mobile Key, or mechanism identified by the platform.
  • Prepare the mandate document if the submitter is not the legal representative.
  • Do not share passwords, codes, or credentials with third parties.

4. Complete, review, and submit

Complete the form carefully, paying attention to names, numbers, and contacts. The platform identifies errors or missing fields before final submission. An internal review can reduce later correction requests.

  • Compare the form data with the entity's official records.
  • Confirm that the listed contacts are monitored regularly.
  • Keep a copy of the submission when the platform allows it.
  • Keep the receipt showing the submission date and time.

5. Organize what happens next

Submission does not end the process. The company should monitor notices, answer information requests, and keep an internal record of decisions. Only after the official response should it finalize the relevant technical preparation plan.

  • Record the submission date and process owner.
  • Create an internal folder for receipts, notices, and responses.
  • Prepare an initial list of systems, domains, suppliers, and dependencies without sending it unless requested.
  • Separate facts confirmed by the authority from internal working assumptions.

An internal systems list helps prepare technical work, but it does not replace the asset list required from entities that have that obligation.

Signs that technical support may help

Support may be useful when the company has no systems inventory, does not know who monitors notices, uses several suppliers, or needs to turn an official response into a practical work plan.

  • Domains, applications, servers, and suppliers are spread across several teams.
  • There is no clear owner for incidents or urgent contacts.
  • The company needs technical documentation before defining measures.
  • Management needs priorities instead of an unstructured list of tools.

Frequently asked questions

Do I need to complete all security work before registration?

That is not the purpose of this stage. First gather the data and register. After the response and applicable scope are clearer, define a proportionate and verifiable technical plan.

Should I send passwords or sensitive files?

No. Send only what the platform or competent authority requests through official channels. Never share credentials in a preparation form or with a provider without a secure, authorized process.

What if the entity's information changes?

Record the change internally and confirm through the platform and official channels how the information should be updated or reported.

Tell us about your project.

Need a homepage, web application, online store, automation, integration, or AI solution? Talk to eluis.pt and explain what you want to create.

The submitted data, including the page where the request was sent, is used to respond to your contact request. We do not use analytics or marketing cookies.