Prepare before you begin
The quality of registration depends on prior work: activities, sectors, size, services, establishment, representation, and supporting evidence. The checker can support reflection, but its result is indicative and does not replace mandatory self-identification where applicable.
The entity should retain a framework assessment record explaining the data and criteria used.
One entity, one registration
Initial access belongs to the legal representative or a representative with admissible, documented authority. The entity maintains a single registration even when it operates in several sectors or subsectors.
Roles, replacements, and contacts should be defined before an absence or urgent situation occurs.
Submission may require interaction
After completion and submission, the authority may request additional information. A draft decision and right-to-be-heard procedure follow, with a period of 10 business days for a response.
Responding requires coordination between management, legal, operations, and technical owners; it should not depend on a single mailbox.
Qualification creates concrete obligations
The final decision may qualify the entity, consolidate its registration, and indicate the applicable framework. In the cases provided for, communication of the Cybersecurity Officer and permanent contact point follows.
Here, PCP means permanent contact point, not business continuity plan.
Operate and maintain
Information must remain up to date. The platform supports notifications and communications associated with documents, assets, incidents, and other duties.
The best preparation combines owners, a calendar, evidence, replacements, and periodic verification of the registration.
