An appointment does not create capability by itself
The launch of MyCiber made two functions established in the Portuguese Cybersecurity Legal Framework more visible: the Cybersecurity Officer (RCS) and Permanent Contact Point (PCP). For many organizations, the first impulse will be to identify names, enter contacts, and complete the communication.
That step is necessary but insufficient. A name on a form does not guarantee access to information, authority to coordinate, availability to respond, or the ability to maintain communication during a demanding situation.
The most important question is not only who will be named. It is whether that person or team can effectively perform the function when the organization needs it.
Two functions, one shared purpose
The RCS and PCP have different natures but serve a shared purpose: ensuring that the organization can govern cybersecurity, maintain reliable information flows, and respond in a coordinated manner.
The RCS works primarily at the connection between risk, measures, evidence, and decisions. The PCP maintains the operational and technical channel with the competent cybersecurity authority. One helps the organization understand what must be decided and monitored; the other helps ensure that an important communication does not go unanswered.
Separating the roles helps explain their responsibilities. Connecting them helps the organization function.
The Cybersecurity Officer connects risk to management
Article 31 of Decree-Law No. 125/2025 requires essential and important entities to appoint a Cybersecurity Officer for cybersecurity and information-security management. The appointed person must be a member of the management, executive, or administrative bodies, or report organically and directly to them.
The legally established functions include proposing risk-management measures, providing information to the bodies overseeing those measures, supporting compliance with oversight and implementation obligations, promoting a cybersecurity culture, ensuring risk management, and monitoring the annual report.
This places the RCS between operational reality and decision-making. To perform the role, the person needs knowledge of services, assets, dependencies, incidents, suppliers, risks, ongoing measures, and actual limitations. They must also be able to present that information to management clearly and in an actionable form.
The Permanent Contact Point protects communication flow
Article 32 establishes that essential and important entities must maintain at least one Permanent Contact Point. The function may be performed by one person or a team and supports operational and technical information flows with the competent authority.
Continuous availability, 24 hours a day and seven days a week, is limited to activation periods initiated and ended through communication from the competent cybersecurity authority. This should not be confused with an obligation to keep one person permanently on the telephone without context; it means the entity must be able to activate and sustain a functioning channel when such a period is communicated.
Regulation No. 756/2026 provides for identification of the team or third party performing the function and communication of primary and alternative contact methods. Redundancy is part of the function: a single email address, telephone, or employee may fail precisely when they matter most.
Different does not mean isolated
The law provides that the RCS coordinates PCP actions when the RCS does not personally perform that function. This connection is essential: receiving a communication without knowing the context delays response; understanding risk without an operational channel leaves decisions without execution.
The organization should define how the PCP acknowledges receipt, who assesses the information, when the RCS becomes involved, how it reaches decision-makers, and which technical or operational teams are mobilized. It should also know who replaces each participant and how context is recovered during a shift change or period of unavailability.
The objective is not to create a heavy chain of command. It is to reduce the time between receiving, understanding, deciding, and acting.
Why we address operation before the form
At Cyberprotech, we begin with the organization's context: who decides, who operates, which services cannot stop, which teams exist, what support is contracted, and which channels remain available outside normal operations.
We work this way because an appointment must correspond to reality. If the procedure depends on access the person does not have, a mailbox no one monitors, or knowledge concentrated in one employee, documentary compliance does not become operational capability.
We then organize responsibilities, escalation, replacements, primary and alternative channels, required information, and evidence. Only then does communication on the platform represent something that can truly work.
Decide, communicate, and respond without improvising
A simple process may be more effective than an extensive manual. What matters is that it is known, accessible, and tested: a communication reaches the PCP, is recorded and acknowledged, its context is assessed, the RCS is involved where applicable, management receives appropriate information, and the responsible teams act.
Each handoff should preserve enough information for the next person to understand what happened, what has already been done, what remains to be decided, and which deadline is running. This discipline reduces noise, repetition, and contradictory decisions.
Preparation becomes visible when the process continues to work without depending on one person's memory, presence, or equipment.
What should be ready before communication
Not every organization needs the same structure. A small team may adopt a short procedure; a distributed organization may need shifts, teams, and differentiated escalation. In both cases, certain elements should be clear.
- Instrument appointing the Cybersecurity Officer, where applicable, and definition of direct reporting.
- Functions, authority, access to information, and resources required by the RCS.
- Identification of the person, team, or entity performing the PCP function.
- Monitored and tested primary and alternative email addresses and telephone numbers.
- Rules for activation, acknowledgment, escalation, and recording communications.
- Deputies and a procedure for unavailability, vacation, shift changes, or a person's departure.
- Current list of internal teams, providers, and decision-makers who may need to be involved.
- Periodic exercise confirming that contacts, access, and response times remain appropriate.
External models require clarity, not assumptions
The framework allows the PCP to be performed by a team or third party. For the RCS, the statutory language concerning organic and direct reporting requires prudent analysis of the adopted structure, the entity in scope, and guidance from the competent authority.
For that reason, no vCISO or CISOaaS contract should be presumed to automatically constitute the statutory appointment of the RCS. An external service may support governance, risk, coordination, and evidence, but compatibility of the specific model with the appointment must be confirmed before being presented as a conclusion.
Prudence does not prevent preparation. On the contrary, it allows responsibilities, autonomy, information, confidentiality, continuity, replacement, and conflicts of interest to be defined while the applicable framework is validated.
The best evidence is a function that works
Appointment instruments, organization charts, procedures, contact lists, test records, and update histories are important evidence. But the value of these documents lies in the behavior they support.
A prepared organization can explain who monitors risk, who informs management, who receives an urgent communication, who replaces an unavailable person, and how information reaches the correct team. It can also demonstrate that contacts were verified and the pathway was exercised.
That is why we treat these functions as part of governance and continuity, not as an isolated MyCiber task. Communication completes an administrative step; capability needs to remain active, current, and ready for the moment it is called upon to respond.
