The Regulation does not replace the RJCS

Regulation No. 756/2026 implements matters provided for in the Portuguese Cybersecurity Legal Framework. The two acts should be read together, including the Regulation's four annexes, which form an integral part of the act and have equal legal value.

Publication of the Regulation makes procedures that previously depended on regulation concrete, but some provisions remain subject to their own taking-effect rules and technical instructions.

Self-identification, hearing, and decision

The entity submits information on the platform, receives a provisional registration, and may be asked to provide additional information. Before the final qualification decision, there is a right-to-be-heard procedure with a prescribed period of 10 business days.

Submission should be treated as a formal process: validated data, grounds, supporting evidence, and receipts should be preserved.

The entity does not choose its level

For essential and important entities, the risk matrix determines the compliance level. The outcome is categorized as Basic, Substantial, or High according to the score and applicable factors.

The level guides minimum measures but does not eliminate assessment of residual risk or other applicable obligations.

  • Basic: 0 to 99.
  • Substantial: 100 to 199.
  • High: 200 to 1,200.

Verification criteria change the conversation

The annexes associate measures with factual, documentary, or technical criteria. The organization needs to show implementation, not merely intent.

A policy may be necessary but may not be sufficient: configurations, records, approvals, tests, reports, and outcomes complete the evidence.

Compliance requires maintenance

Submitted data is the entity's responsibility and must remain up to date. People, contacts, assets, documents, and communications need review and replacement processes.

The most likely mistake is treating qualification as the end of the project. In practice, it is the beginning of continuous operation.