Guide
The three QNRCS compliance levels
Basic, Substantial and High: what each QNRCS compliance level means, how to know which one applies to your company, and what changes in practice between them.
Anyone starting to deal with compliance under Portugal’s cybersecurity legal framework quickly runs into three words: Basic, Substantial and High. These are the QNRCS compliance levels, and they determine how many and which cybersecurity measures your company has to meet.
This guide explains what the QNRCS is, how the three levels work and, above all, what changes in practice from one level to the next.
What is the QNRCS?
The QNRCS is the National Cybersecurity Reference Framework (Quadro Nacional de Referência para a Cibersegurança): the Portuguese framework that translates the legal obligations into concrete controls and measures. Its current version was approved by Regulation 756/2026 from the CNCS, in force since June 2026.
It wasn’t invented from scratch. The QNRCS builds on well-established international standards, such as the NIST Cybersecurity Framework 2.0, ISO/IEC 27001 and the CIS Controls. In practice, this means that whoever complies with the QNRCS is following the same good practices used across Europe, organised for the Portuguese context.
The QNRCS is organised into six objectives, describing the full cybersecurity cycle in an organisation:
- Govern: the cross-cutting framework: policies, risk management, roles and responsibilities, supply chain;
- Identify: knowing what you have: inventory of equipment, software, data and services;
- Protect: the defences: access control, training, backups, network protection;
- Detect: noticing the problem: monitoring and detection of anomalous activity;
- Respond: acting when it happens: incident response plan, communication, containment;
- Recover: returning to normal: service recovery and lessons learned.
In total, the QNRCS defines 107 controls spread across these six objectives.
Each measure is described in three columns: the control (what is intended), the measure (what the company must do) and the verification criterion (what evidence demonstrates compliance). That third column deserves attention: it tells you, in black and white, what you will need to show. Complying without being able to demonstrate it is not enough.
The three levels and the minimum measures
Not every company has to meet all 107 controls. The regulation defines, for each compliance level, a set of minimum measures:
- Basic: 43 minimum measures;
- Substantial: 75 minimum measures;
- High: 92 minimum measures.
The levels are cumulative: a company at the Substantial level also ensures the Basic measures, and one at the High level ensures those of both lower levels.
There is an important detail that tends to confuse people: the same controls repeat across levels, with increasing requirements. These are not separate lists of different controls; it’s the same topic, taken further.
A real example from the regulation, about assessing supplier risks (control GR.CA-7):
- At the Basic level, the company must assess supply chain risks at least once a year;
- At the Substantial level, it must additionally mitigate the risks that assessment identifies;
- At the High level, it must assess its suppliers’ cybersecurity with formal evidence: certificates, audit reports, test results.
Another example, about equipment inventory: at the Basic level a documented, up-to-date inventory is enough; at the High level, dedicated inventory management tools are required. The topic is the same; the degree of rigour and formalisation is what goes up.
How do I know my company’s level?
The compliance level is not the company’s choice. It results from the regulatory framing defined by the CNCS: the regulation approves risk matrices per sector and subsector of activity, which combine the sector’s risk with the company’s size (small, medium or large) and the sector’s importance. The applicable level results from that calculation.
The general intuition: the more critical the sector and the larger the company, the higher the level. A medium-sized company in a sector from annex II of the legal framework will tend towards a lower level than a large company in a high-criticality sector. But the concrete rule is the framing defined by the CNCS for each case, and that is what counts.
Two practical notes:
- If a company falls under more than one level (for example, because it operates in several sectors), the most demanding one applies;
- When the framing or the minimum measures change, the company generally has six months to adapt (extendable up to one year upon a reasoned request).
What changes in practice between levels
Reading the measures across the three levels, the pattern is clear:
At Basic, the essentials, documented. The Basic level asks for the foundations: policies approved by management, an inventory of what exists, an incident response plan, an annual risk assessment, training. It is demanding enough for a company that has never formalised its security, but it is achievable with organisation and without major technology investments.
At Substantial, managed processes. The Substantial level asks for practices to stop being one-off and become processes: mitigating the risks identified (identifying them is not enough), mapping networks and communication flows, integrating cybersecurity requirements into supplier contracts, testing plans.
At High, verification and tooling. The High level adds formalisation and continuous proof: management and monitoring tools, tests involving suppliers, formal assessments with certificates and audits, regular review of the risk management strategy.
The minimum is the floor, not the ceiling
The arithmetic is simple: the QNRCS has 107 controls and the most demanding level has 92 minimum measures. The remaining controls are not “extra”: they are available to anyone who wants to go beyond the required minimum.
And going beyond the minimum is not overzealousness. The minimum measures are the legal starting point; the legal framework itself requires companies to adopt whatever additional measures result from their own risk analysis. Every control above the minimum is added maturity and real risk reduced. An SME that meets its level and keeps climbing is simply managing its risk well.
In summary
- The QNRCS is the national cybersecurity reference framework: 107 controls across six objectives (Govern, Identify, Protect, Detect, Respond, Recover), based on international standards.
- There are three compliance levels, with growing minimum measures: Basic (43), Substantial (75) and High (92). The levels are cumulative and the same controls repeat with increasing requirements.
- Your company’s level results from the framing defined by the CNCS (sector, size and risk matrix), not from a choice by the company.
- Every measure has a verification criterion: complying also means being able to demonstrate it.
- The minimum is the floor, not the ceiling: the controls above your level remain available to anyone who wants to reduce risk further.
For the full legal context, see Decree-Law 125/2025 explained for SMEs. To turn this into a concrete plan, the next step is NIS2 compliance: where to start.
This guide is informational and does not constitute legal advice. It reflects Regulation 756/2026 as of September 2026; NIS2PME follows CNCS updates and guidance.
Frequently asked questions
How many controls does the QNRCS have?
107 in total, spread across six objectives. Each compliance level requires a minimum subset: 43 measures at Basic, 75 at Substantial and 92 at High.
How do I know my company compliance level?
The level follows from the regulatory framework defined by the CNCS, which approves risk matrices by sector and subsector, combining sector risk with company size. It is not a company choice. If a company falls into more than one level, the most demanding one applies.
What changes in practice between Basic and High?
The subject of the controls is the same; what rises is the degree of rigour and formalisation. Basic asks for the essentials documented: approved policies, an inventory, an incident response plan, an annual risk assessment and training. Substantial turns practices into managed processes. High adds formal verification and dedicated tooling, with certificates, audits and tests.
Do I have to implement all 107 controls?
No. Each level requires only its minimum measures. The remaining controls are available to anyone who wants to go beyond the minimum, which is an informed risk management decision rather than a legal requirement.
Sources
This guide is based on the legislation published in the Diário da República and on the framework defined by the CNCS.
Related guides
Decree-Law 125/2025 explained for SMEs
What Portuguese Decree-Law 125/2025 requires from companies, in plain language: who is covered, which obligations it brings, and the deadlines and fines it sets.
NIS2 compliance: where to start
A first-steps plan for SMEs: confirm your regulatory framing, assess what already exists, follow an order of priority and turn compliance into routine.
From reading to doing?
Try the platform's free diagnosis or book a 30-minute call about your situation.