Overview

The regulation linking qualification, risk, measures and evidence.

The four annexes form an integral part of the Regulation with equal legal value. They're not just support materials.

Publication
22 June 2026
Entry into force
23 June 2026
Articles
35
Structure
5 chapters
Annexes
4, with equal legal value
Official extension
89 pages

Operational path

From identification to continuous operation.

  1. 01
    Article 8

    Autoidentification

    The entity submits the data necessary for qualification and receives a provisional registration.

  2. 02
    Article 9

    Qualification

    The authority shall conduct the hearing of the parties concerned and shall give a final decision and may indicate the level and measures applicable.

  3. 03
    Article 10

    Definitive registration

    The qualification shall consolidate the registration of the entity on the electronic platform.

  4. 04
    Articles 28 and 29

    Risk matrix

    Sector, size, importance and risk scenarios support the determination of the level of compliance.

  5. 05
    Articles 30 and 31

    Measures and evidence

    The entity applies minimum measures and manages residual risks, producing verifiable evidence.

  6. 06
    Articles 12 to 22

    Continuous operation

    Communications, documents, guardians, contacts and incidents pass through the platform and defined procedures.

Risk matrix

Three levels of compliance.

The total results from the matrix and considers scenarios of risk, probability, impact, size and importance of the sector.

The ranges shown reproduce Annex II. The applicable determination shall result from the official procedure and matrix, not from a self-choice.

Annex I

Six goals to manage the full cycle.

The QNRCS organizes cybersecurity controls and measures in a continuous and evolving structure.

Standard text

35 articles in five chapters.

Open each chapter to consult the official titles. This structure supports the future explanation article by article.

Chapter IGeneral provisionsArticles 1 to 3
  1. Article 1 — Subject matter
  2. Article 2 — Scope
  3. Article 3rd — Definitions
Chapter IIElectronic platformArticles 4 to 19
  1. Article 4 — Purposes and functionality of the platform
  2. Article 5 — Provision of the electronic platform
  3. Article 6 — Identification and access to the electronic platform
  4. Article 7 — Authentication mechanisms and legitimacy of representation
  5. Article 8th — Self-identification
  6. Article 9 — Qualification of entities
  7. Article 10 — Final registration on the platform
  8. Article 11th — Permanent update of information
  9. Article 12. — Communications with cybersecurity authorities
  10. Article 13 — Communication of documents
  11. Article 14th — Cybersecurity Officer (RCS)
  12. Article 15 — Permanent contact point
  13. Article 16. — Processing, storage and updating of data and their destruction
  14. Article 17 — Situations of technical unavailability
  15. Article 18 — Mechanisms for interoperability and access to information
  16. Article 19. — Electronic notifications to entities
Chapter IIINotifications of incidentsArticles 20 to 22
  1. Article 20 — Compulsory notification of incidents
  2. Article 21 — Voluntary notification of relevant information
  3. Article 22 — Conduct of mandatory incident notifications
Chapter IVStructured instrumentsArticles 23 to 33
  1. Article 23rd — QNRCS
  2. Article 24 — Subjective scope
  3. Article 25 — Organization and structure of the NQRCS
  4. Article 26 — Joint implementation
  5. Article 27 — Voluntary certification
  6. Article 28 — Risk Matrix
  7. Article 29 — Risk Scenarios
  8. Article 30 — Minimum Cybersecurity Measures
  9. Article 31 — Risk Management
  10. Article 32 — List of publicly accessible assets
  11. Article 33 — Implementing measures
Chapter VFinal provisionsArticles 34 and 35
  1. Article 34 — Entry into force
  2. Article 35 — Taking effect

Practical implementation

Four attachments with different functions.

Annex I

QNRCS

Controls and measures organized by the goals Manage, Identify, Protect, Detect, Answer and Recover.

Key, important and relevant public entitiesUnderstand this Annex
Annex II

Risk matrix

Method to relate sector, size, importance, probability and impact to the level of compliance.

Essential and important entitiesUnderstand this Annex
Annex III

Minimum measures and verification criteria

mandatory compliance level measures and their factual, documentary or technical evidence.

Essential and important entitiesUnderstand this Annex
Annex IV

Measures for relevant public entities

Compulsory measures and verification criteria applicable to the group qualification A or B.

Relevant public entitiesUnderstand this Annex

Attention points

Rules that condition implementation.

Article 9

Hearing in qualification

After self-identification, the entity shall be notified to comment on the draft decision within 10 working days.

Understand this point
Article 11

Permanent update

The submitted data and information shall be the responsibility of the entity and shall remain up to date.

Understand this point
Article 12

Communication channel

The communications provided for in RJCS and the Regulation shall be carried out through the platform, unless otherwise provided.

Understand this point
Article 17

Technical unavailability

The Regulation provides for alternative procedures and further regularisation where the platform or entity is technically unavailable.

Understand this point
Article 28

Level determined

The matrix determines the level of compliance; the entity does not choose freely between Basic, Substantial and High.

Understand this point
Article 35

Taking effect

Some provisions depend on technical or other regulatory instructions and take effect with their publication.

Understand this point

Frequently Asked Questions

Apply without confusing.

The Regulation replaces Decree-Law No. 125/2025?

No. The Regulation implements matters laid down in RJCS. It shall be applied in conjunction with the Decree-Law and with technical instructions or other relevant regulatory.

Can an entity choose its level of compliance?

No. For essential and important entities, the level results from the risk matrix, considering factors such as sector or subsector, dimension, importance, scenarios, probability and impact.

What are verification criteria?

These are factual, documentary or technical evidence of the application of cybersecurity measures as set out in Annexes III and IV.

Are the four annexes just guidelines?

No. Article 1 provides that the Annexes are an integral part of the Regulation with equal legal value.

Did all the provisions take effect on 23 June 2026?

Not necessarily. Article 35 lays down the rules of Decree-Law No. 125/2025 and provisions dependent on technical or other regulatory instructions.

Sources and relation

Consult the official act and the basic regime.

Informational content published on .

Implementation

What measures and evidence apply to your entity?

The response depends on the qualification, level of compliance or group and residual risk.

Identify priorities