Regulation No. 756/2026
From legal regime to verifiable enforcement.
The Regulation implements how entities identify, communicate, are qualified and demonstrate measures through verification criteria.
Overview
The regulation linking qualification, risk, measures and evidence.
The four annexes form an integral part of the Regulation with equal legal value. They're not just support materials.
- Publication
- 22 June 2026
- Entry into force
- 23 June 2026
- Articles
- 35
- Structure
- 5 chapters
- Annexes
- 4, with equal legal value
- Official extension
- 89 pages
Operational path
From identification to continuous operation.
- 01Article 8
Autoidentification
The entity submits the data necessary for qualification and receives a provisional registration.
- 02Article 9
Qualification
The authority shall conduct the hearing of the parties concerned and shall give a final decision and may indicate the level and measures applicable.
- 03Article 10
Definitive registration
The qualification shall consolidate the registration of the entity on the electronic platform.
- 04Articles 28 and 29
Risk matrix
Sector, size, importance and risk scenarios support the determination of the level of compliance.
- 05Articles 30 and 31
Measures and evidence
The entity applies minimum measures and manages residual risks, producing verifiable evidence.
- 06Articles 12 to 22
Continuous operation
Communications, documents, guardians, contacts and incidents pass through the platform and defined procedures.
Risk matrix
Three levels of compliance.
The total results from the matrix and considers scenarios of risk, probability, impact, size and importance of the sector.
Basic
Level resulting from the total value calculated under the risk matrix.
Understand this levelSubstantial
It adds measures corresponding to a higher risk and requirement.
Understand this levelHigh
More demanding level predicted by the matrix for essential and important entities.
Understand this levelThe ranges shown reproduce Annex II. The applicable determination shall result from the official procedure and matrix, not from a self-choice.
Annex I
Six goals to manage the full cycle.
The QNRCS organizes cybersecurity controls and measures in a continuous and evolving structure.
Manage
Governance, context, responsibilities, policy, risk and supply chain.
See categories and controlsIdentify
Assets, vulnerabilities, threats, impact, risk and improvement.
See categories and controlsProtect
Identities, accesses, data, platforms, resilience and awareness.
See categories and controlsDetect
Monitoring, adverse event analysis and incident detection.
See categories and controlsAnswer
Management, analysis, mitigation, reporting and reporting of incidents.
See categories and controlsRecover
Execution of plans, replacement, verification and communication of recovery.
See categories and controlsStandard text
35 articles in five chapters.
Open each chapter to consult the official titles. This structure supports the future explanation article by article.
Chapter IGeneral provisionsArticles 1 to 3
- Article 1 — Subject matter
- Article 2 — Scope
- Article 3rd — Definitions
Chapter IIElectronic platformArticles 4 to 19
- Article 4 — Purposes and functionality of the platform
- Article 5 — Provision of the electronic platform
- Article 6 — Identification and access to the electronic platform
- Article 7 — Authentication mechanisms and legitimacy of representation
- Article 8th — Self-identification
- Article 9 — Qualification of entities
- Article 10 — Final registration on the platform
- Article 11th — Permanent update of information
- Article 12. — Communications with cybersecurity authorities
- Article 13 — Communication of documents
- Article 14th — Cybersecurity Officer (RCS)
- Article 15 — Permanent contact point
- Article 16. — Processing, storage and updating of data and their destruction
- Article 17 — Situations of technical unavailability
- Article 18 — Mechanisms for interoperability and access to information
- Article 19. — Electronic notifications to entities
Chapter IIINotifications of incidentsArticles 20 to 22
- Article 20 — Compulsory notification of incidents
- Article 21 — Voluntary notification of relevant information
- Article 22 — Conduct of mandatory incident notifications
Chapter IVStructured instrumentsArticles 23 to 33
- Article 23rd — QNRCS
- Article 24 — Subjective scope
- Article 25 — Organization and structure of the NQRCS
- Article 26 — Joint implementation
- Article 27 — Voluntary certification
- Article 28 — Risk Matrix
- Article 29 — Risk Scenarios
- Article 30 — Minimum Cybersecurity Measures
- Article 31 — Risk Management
- Article 32 — List of publicly accessible assets
- Article 33 — Implementing measures
Chapter VFinal provisionsArticles 34 and 35
- Article 34 — Entry into force
- Article 35 — Taking effect
Practical implementation
Four attachments with different functions.
QNRCS
Controls and measures organized by the goals Manage, Identify, Protect, Detect, Answer and Recover.
Key, important and relevant public entitiesUnderstand this AnnexRisk matrix
Method to relate sector, size, importance, probability and impact to the level of compliance.
Essential and important entitiesUnderstand this AnnexMinimum measures and verification criteria
mandatory compliance level measures and their factual, documentary or technical evidence.
Essential and important entitiesUnderstand this AnnexMeasures for relevant public entities
Compulsory measures and verification criteria applicable to the group qualification A or B.
Relevant public entitiesUnderstand this AnnexAttention points
Rules that condition implementation.
Hearing in qualification
After self-identification, the entity shall be notified to comment on the draft decision within 10 working days.
Understand this pointPermanent update
The submitted data and information shall be the responsibility of the entity and shall remain up to date.
Understand this pointCommunication channel
The communications provided for in RJCS and the Regulation shall be carried out through the platform, unless otherwise provided.
Understand this pointTechnical unavailability
The Regulation provides for alternative procedures and further regularisation where the platform or entity is technically unavailable.
Understand this pointLevel determined
The matrix determines the level of compliance; the entity does not choose freely between Basic, Substantial and High.
Understand this pointTaking effect
Some provisions depend on technical or other regulatory instructions and take effect with their publication.
Understand this pointFrequently Asked Questions
Apply without confusing.
The Regulation replaces Decree-Law No. 125/2025?
No. The Regulation implements matters laid down in RJCS. It shall be applied in conjunction with the Decree-Law and with technical instructions or other relevant regulatory.
Can an entity choose its level of compliance?
No. For essential and important entities, the level results from the risk matrix, considering factors such as sector or subsector, dimension, importance, scenarios, probability and impact.
What are verification criteria?
These are factual, documentary or technical evidence of the application of cybersecurity measures as set out in Annexes III and IV.
Are the four annexes just guidelines?
No. Article 1 provides that the Annexes are an integral part of the Regulation with equal legal value.
Did all the provisions take effect on 23 June 2026?
Not necessarily. Article 35 lays down the rules of Decree-Law No. 125/2025 and provisions dependent on technical or other regulatory instructions.
Sources and relation
Consult the official act and the basic regime.
Information and structural guide. The actual application depends on the qualification of the entity, the applicable level or group and the technical or other regulatory instructions in force.