Scope

Who should assess whether they are in scope?

Classification does not depend on sector alone. It may depend on size, services provided, establishment, special criteria and a qualification decision.

Essential entities

Organizations qualified as essential according to the scope, size, sector and criteria established by the RJCS.

Important entities

Organizations qualified as important under the applicable legal criteria.

Relevant public entities

Public bodies falling within scope and qualified in accordance with the framework and its regulation.

Do not assume that you are in scope — or out of scope.

The CNCS tool supports the assessment, but it is non-binding and does not replace self-identification where mandatory. Some criteria require specific analysis.

Operational view

What changes for an organization in scope?

The framework cannot be treated as an isolated documentation project. It requires governance, risk management, operations, communication and evidence.

01

Governance

Involvement of management, executive or administrative bodies and a clear allocation of responsibilities.

02

Risk management

Technical, operational and organizational measures appropriate and proportionate to risk.

03

Incidents

The ability to manage incidents and meet the legally applicable communication and notification duties.

04

Continuity

Backups, recovery, crisis management and business continuity.

05

Supply chain

Management of risks associated with direct suppliers and service providers.

06

Evidence

Factual, documentary or technical criteria demonstrating that measures have been applied.

07

Officers and contacts

Appointment and communication of the Cybersecurity Officer and Permanent Point of Contact, where applicable.

08

Continuous improvement

Assessment of measure effectiveness, training, monitoring and continuous development of the system.

First steps

A practical sequence for getting started.

Before selecting tools or producing policies, confirm the scope, responsibilities and required information.

  1. 01

    Assess the scope

    Confirm sector, size, services, establishment and special criteria. The CNCS simulator is a non-binding support tool.

  2. 02

    Prepare self-identification

    Gather the legal, organizational and operational information required for the process on the electronic platform.

  3. 03

    Define governance

    Clarify the responsible governing bodies, Cybersecurity Officer, point of contact and decision model.

  4. 04

    Connect risk to measures

    Inventory services and assets, assess risks and associate measures, owners, deadlines and verification criteria.

  5. 05

    Organize evidence

    Create a documentary and technical structure that makes compliance easy to locate, review and demonstrate.

Frequently asked questions

Direct answers.

Are NIS2 and the RJCS the same thing?

No. NIS2 is Directive (EU) 2022/2555. The RJCS is the national framework approved by Decree-Law no. 125/2025, which transposes that directive into Portuguese law.

Is Decree-Law no. 125/2025 already in force?

Yes. It entered into force on 3 April 2026. Some provisions have specific rules on when they take effect and must be assessed in the applicable context.

Does the CNCS simulator definitively confirm whether an organization is in scope?

No. CNCS presents it as a non-binding support tool. It does not replace mandatory self-identification or assessment of legal criteria that may not be covered by the tool.

Do all organizations have exactly the same measures?

No. The framework provides for qualification, a risk matrix, compliance levels and proportionality. Applicable measures depend on the entity's specific circumstances.

Information published on . Content and references reviewed on .

Initial assessment

We start with the organization's actual context, without assuming its qualification or anticipating conclusions.

Identify priorities