Risk matrix · Substantial level

100 ≤ total ≤ 199

Substantial Level

The Substantial level corresponds to a total of between 100 and 199 and reflects a higher requirement for control, formalisation and verification.

Without replacing matrix

How the total is built.

The interval is the final result. These are the factors that help to understand where the points come from.

01

Scenarios and actors

The matrix considers dominant risk scenarios and types of actors relevant to the sector or subsector.

02

Probability

Use a scale of 1 to 5 and historical information, CERT.PT and expert contributions in accordance with Annex II.

03

Impact

It uses a scale of 1 to 5, from limited impact to generalized or catastrophic consequences.

04

Size

The value is weighted depending on whether the entity is large, medium or small.

05

Importance of sector

Sectors in Annex I RJCS have weighting 1,5; Annex II sectors have weighting 1.

06

Total

The calculated values for each scenario and actor are added and the total interval determines the level.

Operational Reading

Where to focus your attention.

  • Consolidate governance and integration of risk management
  • Deepen inventories, dependencies and criticality
  • Formalise controls on suppliers and supply chain
  • Strengthen protection, detection, response and recovery
  • Demonstrate regular execution, review and improvement

Start without complicating

Four practical steps.

  1. 01

    Consolidate Basic

    Confirm that lower level measures are implemented and have current evidence.

  2. 02

    Add Substance

    Incorporating additional measurements of the Substantial level into a single and versioned matrix.

  3. 03

    Evaluate dependencies

    Give priority to critical services, suppliers, assets and scenarios with the greatest impact.

  4. 04

    Test effectiveness

    Set periodic checks, indicators and corrective actions.

Proof

Key evidence.

  • Basic and Substantial Cumulative Matrix
  • Risk management records and decisions
  • Technical evidence and efficacy tests
  • Monitoring of suppliers, incidents and corrective actions

Warning

Avoid wrong readings.

  • Not just implement the substantive measures.
  • Don't accept outdated evidence or no scope.
  • Do not separate cybersecurity from cross-border risk management.

Frequently Asked Questions

Two straight answers.

Does the Substantial level include the Basic?

Yes. Article 30 provides that entities subject to Substantial and High Levels shall also ensure measures at lower levels.

Is the score calculated by the entity itself?

The level results from the official matrix and the applicable procedure. The organization can prepare data and scenarios, but does not freely choose the level.

Primary source

Regulation No. 756/2026 of 22 June

Information guide. The level is determined by the official matrix and communicated when applicable in the qualification procedure; it does not result from a self-choice or from this guide.

Consult official act

Content and references checked on .

Compare levels

Back to the Risk Matrix.

Compare Basic, Substantial and High and continue for verification measures and criteria.

Back to three levels