Quadro Nacional de Referência para a Cibersegurança
NIS2 says what you must achieve, never how you demonstrate it. Portugal answers with QNRCS. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
Adoption of the QNRCS itself is voluntary and a QNRCS certificate is not a NIS2 compliance certificate. Your obligations come from Decreto-Lei n.º 125/2025 and the CNCS regulation; the QNRCS is the reference against which conformity levels are expressed.
We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 is the usual alternative. Note the QNRCS shares the NIST CSF function structure, so an organisation already working to CSF will recognise the shape immediately.
3 routes, chosen by scope and depth
The entry capability level for each measure.
Organisations starting out, or of limited size
The middle capability level.
Organisations with an established security function
The highest capability level for each measure.
Organisations with high exposure or criticality
What it is built on
QNRCS does not invent its own taxonomy. It sits on NIST Cybersecurity Framework — the five functions Identify, Protect, Detect, Respond, Recover.
Five functions — Identificar, Proteger, Detetar, Responder, Recuperar — with three capability levels defined for each measure.
Where it is heading
How it covers article 21(2)
Function-level mapping onto the five NIST CSF functions the QNRCS adopts. Deliberately coarse: the function names are published and stable, the measure identifiers under them are not yet transcribed from the CNCS text.
Function level is the coarsest mapping in this hub. A function covers many measures at three capability levels each, so a function match locates the area to read and nothing more. The measure count is not recorded yet.
| Art. 21(2) | Measure | QNRCS — QNRCS function |
|---|---|---|
| (a) | Risk analysis and security policies | IDENTIFICAR |
| (b) | Incident handling | DETETAR RESPONDER |
| (c) | Business continuity | RECUPERAR PROTEGER |
| (d) | Supply chain security | IDENTIFICAR PROTEGER |
| (e) | Security in acquisition, development and maintenance | IDENTIFICAR PROTEGER |
| (f) | Assessing the effectiveness of the measures | IDENTIFICAR |
| (g) | Basic cyber hygiene and cybersecurity training | PROTEGER |
| (h) | Cryptography and encryption | PROTEGER |
| (i) | Human resources security, access control and asset management | IDENTIFICAR PROTEGER |
| (j) | Multi-factor authentication and secured communications | PROTEGER |
5 QNRCS function units, in full
- IDENTIFICAR — Identify — organisational context, critical assets and risks
- PROTEGER — Protect — safeguards that keep operations resilient
- DETETAR — Detect — capability to identify cybersecurity events
- RESPONDER — Respond — processes to react to an incident
- RECUPERAR — Recover — controlled restoration of services
What you already have, for the same measure
Nobody in scope starts from nothing. QNRCS is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.
| Art. 21(2) | QNRCS | ISO 27001 ISO/IEC 27001:2022 Annex A control | NIST 800-53 NIST SP 800-53 Rev. 5 control family |
|---|---|---|---|
| (a) Risk analysis | IDENTIFICAR | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RA PL PM |
| (b) Incident handling | DETETAR RESPONDER | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | IR AU SI |
| (c) Continuity | RECUPERAR PROTEGER | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | CP PE |
| (d) Supply chain | IDENTIFICAR PROTEGER | 5.19 5.20 5.21 5.22 5.23 | SR SA |
| (e) Secure development | IDENTIFICAR PROTEGER | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | SA CM MA RA SI |
| (f) Effectiveness | IDENTIFICAR | 5.33 5.35 5.36 8.16 | CA PM |
| (g) Hygiene and training | PROTEGER | 5.37 6.3 8.7 | AT SI CM |
| (h) Cryptography | PROTEGER | 8.24 | SC |
| (i) HR, access, assets | IDENTIFICAR PROTEGER | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | PS AC IA CM MP PE |
| (j) MFA and comms | PROTEGER | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | IA AC SC |
A crosswalk is not an equivalence
Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:
- ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
- NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
Use a row to find the evidence you already hold, then read the requirement itself.
- https://diariodarepublica.pt/dr/detalhe/regulamento/756-2026-1134399056
- https://www.cncs.gov.pt/pt/quadro-nacional/
- https://www.cncs.gov.pt/pt/quadro-nacional-de-certificacao-da-ciberseguranca/
- https://www.ipac.pt/docs/publicdocs/requisitos/OEC037_CertificacaoQNRCS_v201224.pdf
We are not affiliated with CNCS — Centro Nacional de Cibersegurança. QNRCS and related marks belong to their owners.