Implementation model

To comply is to connect four elements.

A policy without implementation is insufficient. A configuration without obligation, responsibility and registration also does not form a controlled system.

  1. 01

    Obligation

    Identify the source, scope, entity and result required.

  2. 02

    Measure

    Define the organizational, technical or procedural control to be applied.

  3. 03

    Document

    To formalise decisions, rules, procedures, records and responsibilities.

  4. 04

    Evidence

    To demonstrate that the measure exists, works and is reviewed.

Implementation map

Nine areas to organize the work.

Open each domain to consult the link between source, actions, measures, documents and evidence.

01Governance and responsibilitiesCybersecurity Management Body (RCS)

Objective

Fix responsibility, supervision, reporting and decision-making capacity.

References

  • RJCS: Articles 25 to 32
  • Regulation: Articles 13 to 15

Actions

  • Approving the governance model
  • Designate the cybersecurity officer
  • Constituting the permanent contact point
  • Define reporting to the management body

Measures

  • Responsibilities formally assigned
  • Segregation of functions
  • Supervision by the management body
  • Defined replacement and scaling

Documents

  • Cybersecurity policy
  • Order or minutes of appointment of the Cybersecurity Officer (RCS)
  • RACI Matrix
  • Committee reference terms
  • Reporting plan and model

Evidence

  • Approval minutes
  • Communication of the Cybersecurity Officer (RCS) and PCP in MyCiber
  • Periodic reports
  • Meetings and decisions records

Responsible: Cybersecurity Management Body (RCS) · Cadence: Annual review and after relevant changes

02Risk and treatment planCybersecurity Officer (RCS), risk owners and management body

Objective

Know the risk, select proportional measures and follow the residual risk.

References

  • RJCS: Articles 26 to 29
  • Regulation: Articles 28 to 31 and Annex II

Actions

  • Set methodology
  • Identify scenarios, threats and vulnerabilities
  • Evaluate probability and impact
  • Approving treatment and acceptance of residual risk

Measures

  • Consistent assessment criteria
  • Risk owners
  • Timetable and priority treatment
  • Reassessment of residual risk

Documents

  • Risk methodology
  • Risk matrix
  • Risk recording
  • Treatment plan
  • Statements of acceptance

Evidence

  • Approved matrix
  • History of changes
  • Treatment tasks completed
  • Acceptance decisions

Responsible: Cybersecurity Officer (RCS), risk owners and management body · Cadence: Continuous and after changes or incidents

03Assets and inventoriesIT, Asset Owners and Cybersecurity Officer (RCS)

Objective

Learn what supports services and which assets are directly accessible via the Internet.

References

  • RJCS, Article 35
  • Regulation: Article 32
  • Regulation: Annexes III and IV

Actions

  • Invent assets, systems, data and services
  • Assign owner and criticality
  • Link dependencies
  • Report and update publicly accessible assets

Measures

  • Unique identification
  • Classification and criticality
  • Controlled life cycle
  • Periodic technical reconciliation

Documents

  • Asset management policy
  • Asset inventory
  • Map of dependencies
  • List of public assets
  • Update procedure

Evidence

  • Inventory exports
  • Discovery records
  • Owner approvals
  • Communication receipts MyCiber

Responsible: IT, Asset Owners and Cybersecurity Officer (RCS) · Cadence: Continuous update and periodic reconciliation

04Protection, accesses and configurationIT, security and system owners

Objective

Reduce the probability and impact of improper access, error and technical exploration.

References

  • RJCS: Article 26
  • Regulation: Annexes III and IV

Actions

  • Set identities and profiles
  • Apply strong authentication
  • Normalize secure settings
  • Manage vulnerabilities, fixes and changes

Measures

  • Less privilege
  • Multifactor authentication
  • Hardening
  • Risk-based corrections
  • Access revision

Documents

  • Access control policy
  • Profile matrix
  • Configuration Baselines
  • Vulnerability procedure
  • Change management procedure

Evidence

  • Access listings
  • Review results
  • Vulnerability reports
  • Patch records
  • Change tickets

Responsible: IT, security and system owners · Cadence: Continuous, with scheduled revisions

05Third parties and supply chainPurchases, legal, contract owners and Cybersecurity Officer (RCS)

Objective

Control dependencies and risk introduced by suppliers and providers.

References

  • RJCS: Article 26
  • Regulation: Annexes III and IV

Actions

  • Classify third parties by criticality
  • Evaluate before hiring
  • Set contractual requirements
  • Monitor performance, incidents and output

Measures

  • Proportional due diligence
  • Notification requirements
  • Right of audit
  • Management of subcontractors
  • External access control

Documents

  • Third party policy
  • Supplier Inventory
  • Assessment questionnaire
  • Safety clauses
  • Exit plan and reversibility

Evidence

  • Assessments completed
  • Contracts and additions
  • Service meetings
  • Reports and certificates
  • Reversibility tests

Responsible: Purchases, legal, contract owners and Cybersecurity Officer (RCS) · Cadence: Before hiring and during the contract

06Incident detection and managementPCP, Cybersecurity Officer (RCS), technical teams and crisis management

Objective

Detect, contain, communicate, recover and learn within applicable time limits.

References

  • RJCS: Articles 40 to 45
  • Regulation: Articles 20 to 22

Actions

  • Set criteria and severity
  • Operationalise detection and scaling
  • Prepare notifications
  • Run post-incident analysis

Measures

  • Monitoring
  • Screening and scaling
  • Proof preservation
  • Coordinated communication
  • Lessons Learned

Documents

  • Incident response plan
  • Severeness matrix
  • Playbooks
  • Models for notification
  • Post-incident report

Evidence

  • Alerts and tickets
  • Chronology of the incident
  • Severe decisions
  • Notification receipts
  • Exercises and corrective actions

Responsible: PCP, Cybersecurity Officer (RCS), technical teams and crisis management · Cadence: Permanent and Exercise-tested

07Continuity, recovery and crisisManagement, Continuity, IT, Cybersecurity Officer (RCS) and owners of services

Objective

Maintain or recover essential services within approved objectives.

References

  • RJCS: Article 26
  • Regulation: Annexes III and IV

Actions

  • Perform impact analysis
  • Setting priorities and recovery objectives
  • Create strategies and plans
  • Test scenarios and fix failures

Measures

  • Proportional redundancy
  • Protected backups
  • Tested Recovery
  • Alternative channels
  • Crisis management

Documents

  • Business impact analysis
  • Continuity plan
  • Recovery plan
  • Crisis reporting plan
  • Exercise program

Evidence

  • Test results
  • Restoration reports
  • Exercise records
  • Remedial actions
  • Approval of recovery objectives

Responsible: Management, Continuity, IT, Cybersecurity Officer (RCS) and owners of services · Cadence: Scheduled tests and after relevant changes

08People, training and cultureHuman resources, Cybersecurity Officer (RCS) and heads

Objective

Ensure appropriate competences for functions and reduce human risk.

References

  • RJCS: Articles 25 and 26
  • Regulation: Annexes III and IV

Actions

  • Map functions and competencies
  • Form management body and teams
  • Sensitize users
  • Evaluate effectiveness and strengthen behavior

Measures

  • Risk and function training
  • Recurrent awareness
  • Exercises and simulations
  • Input, change and exit rules

Documents

  • Training policy
  • Competence matrix
  • Annual plan
  • Content by function
  • Onboarding and offboarding procedure

Evidence

  • Presences and conclusions
  • Evaluation results
  • Campaigns and simulations
  • Improvement plans
  • Onboarding and offboarding logs

Responsible: Human resources, Cybersecurity Officer (RCS) and heads · Cadence: At the entrance, periodically and after changes

09Conformity and continuous improvementCybersecurity Officer (RCS), audit, conformity and management body

Objective

Demonstrate compliance, identify deviations and sustain improvement.

References

  • RJCS: Articles 30 and 34
  • Regulation: Articles 13, 27 and 30 to 33
  • Regulation: Annexes III and IV

Actions

  • Map applicable measures
  • Collect verification criteria
  • Evaluate efficacy
  • Treat non-conformities
  • Prepare report and supervision

Measures

  • Document control
  • Self-assessment
  • Proportional independent audit
  • Monitoring actions
  • Review by management

Documents

  • Compliance matrix
  • Audit plan
  • Assessment report
  • Remedial action plan
  • Annual report, where applicable

Evidence

  • Verification criteria satisfied
  • Reports and samples
  • Non-conformities closed
  • Review minutes
  • Submissions and receipts

Responsible: Cybersecurity Officer (RCS), audit, conformity and management body · Cadence: Annual program and continuous monitoring

Workflow

Implementation does not start with the purchase of technology.

  1. 01

    Frame

    Confirm qualification, level or group and applicable sources.

  2. 02

    Map

    To relate each obligation to verification measures and criteria.

  3. 03

    Assess

    Identify current status, gaps, dependencies and risk.

  4. 04

    Plan

    Assign priority, responsibility, deadlines and resources.

  5. 05

    Run

    Implement measures and produce documentation and records.

  6. 06

    Demonstrate

    Test effectiveness, store evidence and correct deviations.

Verification criteria

Three complementary ways to demonstrate.

The evidence should be current, attributable, intact, relevant to the measure and sufficient to support the conclusion.

Fact

Verifiable observation of a practice, condition or result in operation.

Interview, observation, demonstration or sample.
Documentary

Approved document or controlled record demonstrating decision and enforcement.

Policy, record, ticket, list or receipt.
Technique

Result extracted from systems, tools or tests.

Configuration, log, scan report, alert or restoration test.

Priority matrix

Order by deadline, risk and dependency.

P0

XO

Legal deadline under way, critical exposure or lack of response capacity.

MyCiber, contacts, incidents and critical accesses.
P1

Fundamental

Dependency required to implement or prove several other measures.

Governance, risk, assets, Cybersecurity Officer (RCS) and PCP.
P2

Risk reduction

Relevant lacuna with material impact on services or data.

Protection, third parties, continuity and recovery.
P3

Optimisation

Improved effectiveness, integration, automation or maturity.

Metrics, automation of evidence and certification.

Frequently Asked Questions

Documenting is not the same as implementing.

Is a document sufficient to demonstrate implementation?

Not necessarily. A document may demonstrate intention and governance, but effectiveness usually also requires factual or technical records of the implementation of the measure.

Do all entities apply the same measures?

No. Measures shall depend on the qualification, level of compliance or applicable group, risk and any additional sectoral standards.

What is a verification criterion?

It is the factual, documentary or technical evidence used to verify the application of a measure, as set out in Annexes III and IV of the Regulation No. 756/2026.

Who should be responsible for each measure?

There shall be an operational owner with authority and resources, without withdrawing from the management body and the legally provided functions their responsibilities.

Does the Implementation Center replace CyberComply?

No. This center is public knowledge. CyberComply is an external platform that can support document management, evidence and roadmaps.

Does implementation end when all documents exist?

No. Compliance requires continuous operation, monitoring, testing, updating and improvement, in addition to documentation.

Sources and routes

Start with the qualification and confirm the official sources.

Informational content published on .

Roadmap implementation

What gaps should be addressed first?

The starting point is a proportional assessment that links risk, obligations, dependencies and existing evidence.

Identify priorities