Practical application · Annex III
Measures and evidence
Annex III transforms compliance levels into mandatory minimum measures and associates each measure with verification criteria.
Framework
To whom it applies.
Essential and important entities, according to their level of compliance.
Simple Reading
Five essential points.
- Group measures by Basic, Substantial and High Levels
- Connects each measure to a cybersecurity control
- Indicates verification criteria to demonstrate application
- Apply cumulatively
- It requires treatment of risks remaining after measures
Start without complicating
Four practical steps.
- 01
Confirm level
Start from the reported level and also include all measures at the lower levels.
- 02
Create matrix
Record measure, criterion, responsibility, evidence, status and deadline in a single controlled instrument.
- 03
Validate execution
Confirm that policies and procedures are effectively applied and supported by records.
- 04
Treat gaps
Prioritize deviations, residual risk and additional necessary measures.
Proof
Which should be organized.
- Cumulative matrix of measures
- Adopted policies and procedures
- Facts and technical evidence
- Tests, reviews, exceptions and corrective actions
Warning
Avoid wrong readings.
- Do not just apply the highest level lines.
- Do not use the number of documents as an effective measure.
- Do not accept evidence without date, scope or responsibility.
Frequently Asked Questions
Two straight answers.
Do the Substantial Level measures include those of the Basic?
Yes. The levels are cumulative; the High includes also the measures of the Substantial and the Basic.
What is a verification criterion?
It is the indication of factual, documentary or technical evidence that allows to demonstrate the application of a measure.
Primary source
Regulation No. 756/2026 of 22 June
Information guide and simplified. To apply a measure or interpret a criterion, always confirm the full text of the official act.