Risk Matrix · High Level

200 ≤ total ≤ 1200

High Level

The High Level corresponds to a total between 200 and 1200 and represents the most demanding level predicted by the matrix for essential and important entities.

Without replacing matrix

How the total is built.

The interval is the final result. These are the factors that help to understand where the points come from.

01

Scenarios and actors

The matrix considers dominant risk scenarios and types of actors relevant to the sector or subsector.

02

Probability

Use a scale of 1 to 5 and historical information, CERT.PT and expert contributions in accordance with Annex II.

03

Impact

It uses a scale of 1 to 5, from limited impact to generalized or catastrophic consequences.

04

Size

The value is weighted depending on whether the entity is large, medium or small.

05

Importance of sector

Sectors in Annex I RJCS have weighting 1,5; Annex II sectors have weighting 1.

06

Total

The calculated values for each scenario and actor are added and the total interval determines the level.

Operational Reading

Where to focus your attention.

  • Integrate all three levels into a single cybersecurity program
  • Ensure supervision of management and proportionate resources
  • Continuously monitor assets, threats and events
  • Test response, continuity and recovery
  • Review residual risk, exceptions and effectiveness of controls

Start without complicating

Four practical steps.

  1. 01

    Unify the three levels

    Construct a cumulative matrix without duplication, with measurement, criterion, responsibility, evidence and state.

  2. 02

    Prioritize the critic

    Relating measures with essential services, dominant scenarios and more serious impacts.

  3. 03

    Validate operationally

    Test controls, incident response, continuity, recovery and external dependencies.

  4. 04

    Report and improve

    Take risk, effectiveness, deviations and investment to management in a defined cadence.

Proof

Key evidence.

  • Cumulative three-level matrix
  • Results of technical tests and exercises
  • Indicators, minutes and management decisions
  • Monitoring records, incidents, continuity and improvement

Warning

Avoid wrong readings.

  • Do not treat High as project with end date.
  • Do not confuse quantity of documents effectively.
  • Do not leave exceptions and residual risk without formal decision.

Frequently Asked Questions

Two straight answers.

The High Level replaces the lower levels?

No. It is cumulative and includes the minimum measures of the substantive and basic levels.

Can an entity with multiple activities have more than one level?

More than one result may occur; Article 30 provides for the application of the most demanding level to manage risks in the High, Substantial and Basic order.

Primary source

Regulation No. 756/2026 of 22 June

Information guide. The level is determined by the official matrix and communicated when applicable in the qualification procedure; it does not result from a self-choice or from this guide.

Consult official act

Content and references checked on .

Compare levels

Back to the Risk Matrix.

Compare Basic, Substantial and High and continue for verification measures and criteria.

Back to three levels