Risk matrix · Substantial level
100 ≤ total ≤ 199
Substantial Level
The Substantial level corresponds to a total of between 100 and 199 and reflects a higher requirement for control, formalisation and verification.
Without replacing matrix
How the total is built.
The interval is the final result. These are the factors that help to understand where the points come from.
Scenarios and actors
The matrix considers dominant risk scenarios and types of actors relevant to the sector or subsector.
Probability
Use a scale of 1 to 5 and historical information, CERT.PT and expert contributions in accordance with Annex II.
Impact
It uses a scale of 1 to 5, from limited impact to generalized or catastrophic consequences.
Size
The value is weighted depending on whether the entity is large, medium or small.
Importance of sector
Sectors in Annex I RJCS have weighting 1,5; Annex II sectors have weighting 1.
Total
The calculated values for each scenario and actor are added and the total interval determines the level.
Operational Reading
Where to focus your attention.
- Consolidate governance and integration of risk management
- Deepen inventories, dependencies and criticality
- Formalise controls on suppliers and supply chain
- Strengthen protection, detection, response and recovery
- Demonstrate regular execution, review and improvement
Start without complicating
Four practical steps.
- 01
Consolidate Basic
Confirm that lower level measures are implemented and have current evidence.
- 02
Add Substance
Incorporating additional measurements of the Substantial level into a single and versioned matrix.
- 03
Evaluate dependencies
Give priority to critical services, suppliers, assets and scenarios with the greatest impact.
- 04
Test effectiveness
Set periodic checks, indicators and corrective actions.
Proof
Key evidence.
- Basic and Substantial Cumulative Matrix
- Risk management records and decisions
- Technical evidence and efficacy tests
- Monitoring of suppliers, incidents and corrective actions
Warning
Avoid wrong readings.
- Not just implement the substantive measures.
- Don't accept outdated evidence or no scope.
- Do not separate cybersecurity from cross-border risk management.
Frequently Asked Questions
Two straight answers.
Does the Substantial level include the Basic?
Yes. Article 30 provides that entities subject to Substantial and High Levels shall also ensure measures at lower levels.
Is the score calculated by the entity itself?
The level results from the official matrix and the applicable procedure. The organization can prepare data and scenarios, but does not freely choose the level.
Primary source
Regulation No. 756/2026 of 22 June
Information guide. The level is determined by the official matrix and communicated when applicable in the qualification procedure; it does not result from a self-choice or from this guide.