Directive NIS2 European Union
QNRCS, with certification scheme EC QNRCS · referenced by Regulamento n.º 756/2026 of 22 June 2026

Quadro Nacional de Referência para a Cibersegurança

NIS2 says what you must achieve, never how you demonstrate it. Portugal answers with QNRCS. If you operate there, this is what your regulator reads.

Published
Implementation routes
3
Member states using it
1

Reviewed . Verify against the scheme owner before relying on this for a certification decision.

This framework is not compliance

Adoption of the QNRCS itself is voluntary and a QNRCS certificate is not a NIS2 compliance certificate. Your obligations come from Decreto-Lei n.º 125/2025 and the CNCS regulation; the QNRCS is the reference against which conformity levels are expressed.

We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 is the usual alternative. Note the QNRCS shares the NIST CSF function structure, so an organisation already working to CSF will recognise the shape immediately.

Implementation routes

3 routes, chosen by scope and depth


Inicial

The entry capability level for each measure.

Organisations starting out, or of limited size

Intermédio

The middle capability level.

Organisations with an established security function

Avançado

The highest capability level for each measure.

Organisations with high exposure or criticality

What it is built on

QNRCS does not invent its own taxonomy. It sits on NIST Cybersecurity Framework — the five functions Identify, Protect, Detect, Respond, Recover.

Five functions — Identificar, Proteger, Detetar, Responder, Recuperar — with three capability levels defined for each measure.

Where it is heading

Mapping

How it covers article 21(2)


Basis

Function-level mapping onto the five NIST CSF functions the QNRCS adopts. Deliberately coarse: the function names are published and stable, the measure identifiers under them are not yet transcribed from the CNCS text.

Limit of this mapping

Function level is the coarsest mapping in this hub. A function covers many measures at three capability levels each, so a function match locates the area to read and nothing more. The measure count is not recorded yet.

Mapped at the level of
QNRCS function
Units in the framework
5
Units carrying article 21(2)
5
Each of the ten risk-management measures of article 21(2), mapped to the QNRCS function units of QNRCS
Art. 21(2) Measure QNRCS — QNRCS function
(a) Risk analysis and security policies IDENTIFICAR
(b) Incident handling DETETAR RESPONDER
(c) Business continuity RECUPERAR PROTEGER
(d) Supply chain security IDENTIFICAR PROTEGER
(e) Security in acquisition, development and maintenance IDENTIFICAR PROTEGER
(f) Assessing the effectiveness of the measures IDENTIFICAR
(g) Basic cyber hygiene and cybersecurity training PROTEGER
(h) Cryptography and encryption PROTEGER
(i) Human resources security, access control and asset management IDENTIFICAR PROTEGER
(j) Multi-factor authentication and secured communications PROTEGER
5 QNRCS function units, in full
  • IDENTIFICAR — Identify — organisational context, critical assets and risks
  • PROTEGER — Protect — safeguards that keep operations resilient
  • DETETAR — Detect — capability to identify cybersecurity events
  • RESPONDER — Respond — processes to react to an incident
  • RECUPERAR — Recover — controlled restoration of services
The chain continues

What you already have, for the same measure


Nobody in scope starts from nothing. QNRCS is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.

The ten measures of article 21(2), each mapped to QNRCS and to the enterprise frameworks an organisation is likely to already operate
Art. 21(2) QNRCS ISO 27001 ISO/IEC 27001:2022 Annex A control NIST 800-53 NIST SP 800-53 Rev. 5 control family
(a) Risk analysis IDENTIFICAR 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 RA PL PM
(b) Incident handling DETETAR RESPONDER 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 IR AU SI
(c) Continuity RECUPERAR PROTEGER 5.29 5.30 7.5 7.11 7.12 8.13 8.14 CP PE
(d) Supply chain IDENTIFICAR PROTEGER 5.19 5.20 5.21 5.22 5.23 SR SA
(e) Secure development IDENTIFICAR PROTEGER 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 SA CM MA RA SI
(f) Effectiveness IDENTIFICAR 5.33 5.35 5.36 8.16 CA PM
(g) Hygiene and training PROTEGER 5.37 6.3 8.7 AT SI CM
(h) Cryptography PROTEGER 8.24 SC
(i) HR, access, assets IDENTIFICAR PROTEGER 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 PS AC IA CM MP PE
(j) MFA and comms PROTEGER 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 IA AC SC

A crosswalk is not an equivalence

Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:

  • ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
  • NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.

Use a row to find the evidence you already hold, then read the requirement itself.

Cart 0