RJCS · Articles 26 to 29

Risk and measures: from inventory to residual risk

The minimum measures are a starting point. The organization needs to understand assets, threats, dependencies and impact to justify appropriate measures and treat the risk that remains.

For whom

When this article must enter into the plan.

Entities subject to risk management obligations and cybersecurity measures, in proportion to their context and qualification.

Brief tutorial

Four steps to start with method.

Adapt the depth, the responsible and the evidence to the concrete framework of the entity.

  1. 01

    Set context

    Identify critical services, assets, information, dependencies, responsible and impact criteria.

  2. 02

    Evaluate the risk

    Register existing scenarios, threats, vulnerabilities, probability, impact and controls.

  3. 03

    Select measures

    Relate legal and technical measures with each risk and supply chain.

  4. 04

    Treat residual

    Reassess the risk after measures, define additional treatment or formal acceptance and periodically review.

Proof

Evidence to prepare.

  • Inventory of assets and services
  • Methodology and risk matrix
  • Treatment plan
  • Residual risk record and acceptances

Warning

Errors that weaken implementation.

  • Confused checklist of measures with risk assessment
  • Ignore suppliers and dependencies
  • Accept risk without decision and revision deadline

Quick control

Initial checklist.

  • Documented context
  • Risks assessed
  • Related measures
  • Third parties concerned
  • Residual risk determined

Frequently Asked Questions

Two key answers.

Is compliance with the minimum measures sufficient?

Not necessarily. The residual risk shall be assessed and treated in accordance with the entity's context.

Does the supply chain enter the analysis?

Yes. Article 28 integrates supply chain security into the risk approach.

Primary source

Decree-Law No. 125/2025 of 4 December

Information tutorial. Always confirm the official text, the applicable regulations and the specific framework of the organization.

Consult official act

Content and references checked on .

Continue the route

Return to the full map of the Decree-Law.

See the other articles, chapters, attachments and operational tutorials.

Back to Operational Reading