# The three QNRCS compliance levels

> Basic, Substantial and High: what each QNRCS compliance level means, how to know which one applies to your company, and what changes in practice between them.

By: Daniel Barreiros  
Published: 2026-10-01  
Online version: https://nis2pme.pt/en/guides/qnrcs-compliance-levels/

## The essentials in 30 seconds

- The QNRCS defines 107 controls, organised into six objectives: Govern, Identify, Protect, Detect, Respond and Recover.
- There are three compliance levels with increasing minimum measures: Basic (43), Substantial (75) and High (92).
- The levels are cumulative, and the same controls repeat from level to level with increasing demands.
- The level is not chosen by the company: it follows from the regulatory framework defined by the CNCS, combining sector, size and a risk matrix.
- Minimum measures are the floor and not the ceiling: controls above your level remain available to anyone wanting to reduce risk further.

---

Anyone starting to deal with compliance under Portugal's cybersecurity legal framework quickly runs into three words: **Basic**, **Substantial** and **High**. These are the QNRCS compliance levels, and they determine how many and which cybersecurity measures your company has to meet.

This guide explains what the QNRCS is, how the three levels work and, above all, what changes in practice from one level to the next.

## What is the QNRCS?

The QNRCS is the **National Cybersecurity Reference Framework** (Quadro Nacional de Referência para a Cibersegurança): the Portuguese framework that translates the legal obligations into concrete controls and measures. Its current version was approved by Regulation 756/2026 from the CNCS, in force since June 2026.

It wasn't invented from scratch. The QNRCS builds on well-established international standards, such as the NIST Cybersecurity Framework 2.0, ISO/IEC 27001 and the CIS Controls. In practice, this means that whoever complies with the QNRCS is following the same good practices used across Europe, organised for the Portuguese context.

The QNRCS is organised into **six objectives**, describing the full cybersecurity cycle in an organisation:

- **Govern**: the cross-cutting framework: policies, risk management, roles and responsibilities, supply chain;
- **Identify**: knowing what you have: inventory of equipment, software, data and services;
- **Protect**: the defences: access control, training, backups, network protection;
- **Detect**: noticing the problem: monitoring and detection of anomalous activity;
- **Respond**: acting when it happens: incident response plan, communication, containment;
- **Recover**: returning to normal: service recovery and lessons learned.

In total, the QNRCS defines **107 controls** spread across these six objectives.

Each measure is described in three columns: the **control** (what is intended), the **measure** (what the company must do) and the **verification criterion** (what evidence demonstrates compliance). That third column deserves attention: it tells you, in black and white, what you will need to show. Complying without being able to demonstrate it is not enough.

## The three levels and the minimum measures

Not every company has to meet all 107 controls. The regulation defines, for each compliance level, a set of **minimum measures**:

- **Basic**: 43 minimum measures;
- **Substantial**: 75 minimum measures;
- **High**: 92 minimum measures.

The levels are cumulative: a company at the Substantial level also ensures the Basic measures, and one at the High level ensures those of both lower levels.

There is an important detail that tends to confuse people: **the same controls repeat across levels, with increasing requirements**. These are not separate lists of different controls; it's the same topic, taken further.

A real example from the regulation, about assessing supplier risks (control GR.CA-7):

- At the **Basic** level, the company must assess supply chain risks at least once a year;
- At the **Substantial** level, it must additionally mitigate the risks that assessment identifies;
- At the **High** level, it must assess its suppliers' cybersecurity with formal evidence: certificates, audit reports, test results.

Another example, about equipment inventory: at the Basic level a documented, up-to-date inventory is enough; at the High level, dedicated inventory management tools are required. The topic is the same; the degree of rigour and formalisation is what goes up.

## How do I know my company's level?

The compliance level is **not the company's choice**. It results from the regulatory framing defined by the CNCS: the regulation approves risk matrices per sector and subsector of activity, which combine the sector's risk with the company's size (small, medium or large) and the sector's importance. The applicable level results from that calculation.

The general intuition: the more critical the sector and the larger the company, the higher the level. A medium-sized company in a sector from annex II of the legal framework will tend towards a lower level than a large company in a high-criticality sector. But the concrete rule is the framing defined by the CNCS for each case, and that is what counts.

Two practical notes:

- If a company falls under more than one level (for example, because it operates in several sectors), **the most demanding one** applies;
- When the framing or the minimum measures change, the company generally has **six months** to adapt (extendable up to one year upon a reasoned request).

## What changes in practice between levels

Reading the measures across the three levels, the pattern is clear:

**At Basic, the essentials, documented.** The Basic level asks for the foundations: policies approved by management, an inventory of what exists, an incident response plan, an annual risk assessment, training. It is demanding enough for a company that has never formalised its security, but it is achievable with organisation and without major technology investments.

**At Substantial, managed processes.** The Substantial level asks for practices to stop being one-off and become processes: mitigating the risks identified (identifying them is not enough), mapping networks and communication flows, integrating cybersecurity requirements into supplier contracts, testing plans.

**At High, verification and tooling.** The High level adds formalisation and continuous proof: management and monitoring tools, tests involving suppliers, formal assessments with certificates and audits, regular review of the risk management strategy.

## The minimum is the floor, not the ceiling

The arithmetic is simple: the QNRCS has 107 controls and the most demanding level has 92 minimum measures. The remaining controls are not "extra": they are available to anyone who wants to go beyond the required minimum.

And going beyond the minimum is not overzealousness. The minimum measures are the legal starting point; the legal framework itself requires companies to adopt whatever additional measures result from their own risk analysis. Every control above the minimum is added maturity and real risk reduced. An SME that meets its level and keeps climbing is simply managing its risk well.

## In summary

- The QNRCS is the national cybersecurity reference framework: 107 controls across six objectives (Govern, Identify, Protect, Detect, Respond, Recover), based on international standards.
- There are three compliance levels, with growing minimum measures: Basic (43), Substantial (75) and High (92). The levels are cumulative and the same controls repeat with increasing requirements.
- Your company's level results from the framing defined by the CNCS (sector, size and risk matrix), not from a choice by the company.
- Every measure has a verification criterion: complying also means being able to demonstrate it.
- The minimum is the floor, not the ceiling: the controls above your level remain available to anyone who wants to reduce risk further.

For the full legal context, see [Decree-Law 125/2025 explained for SMEs](/en/guides/dl-125-2025-explained-smes/). To turn this into a concrete plan, the next step is [NIS2 compliance: where to start](/en/guides/nis2-compliance-where-to-start/).

---

*This guide is informational and does not constitute legal advice. It reflects Regulation 756/2026 as of September 2026; NIS2PME follows CNCS updates and guidance.*

## Frequently asked questions

### How many controls does the QNRCS have?

107 in total, spread across six objectives. Each compliance level requires a minimum subset: 43 measures at Basic, 75 at Substantial and 92 at High.

### How do I know my company compliance level?

The level follows from the regulatory framework defined by the CNCS, which approves risk matrices by sector and subsector, combining sector risk with company size. It is not a company choice. If a company falls into more than one level, the most demanding one applies.

### What changes in practice between Basic and High?

The subject of the controls is the same; what rises is the degree of rigour and formalisation. Basic asks for the essentials documented: approved policies, an inventory, an incident response plan, an annual risk assessment and training. Substantial turns practices into managed processes. High adds formal verification and dedicated tooling, with certificates, audits and tests.

### Do I have to implement all 107 controls?

No. Each level requires only its minimum measures. The remaining controls are available to anyone who wants to go beyond the minimum, which is an informed risk management decision rather than a legal requirement.

## Sources

- [Decree-Law 125/2025, of 4 December (Diário da República)](https://diariodarepublica.pt/dr/detalhe/decreto-lei/125-2025-962603401)
- [Regulation 756/2026, of 22 June (Diário da República)](https://diariodarepublica.pt/dr/detalhe/regulamento/756-2026-1134399056)

---

*Informational content. It does not constitute legal advice.*
