Implementation Center
From obligation to verifiable evidence.
Turn legal requirements into enforceable work: actions, measures, documents, responsible, deadlines and proof of application.
Implementation model
To comply is to connect four elements.
A policy without implementation is insufficient. A configuration without obligation, responsibility and registration also does not form a controlled system.
- 01
Obligation
Identify the source, scope, entity and result required.
- 02
Measure
Define the organizational, technical or procedural control to be applied.
- 03
Document
To formalise decisions, rules, procedures, records and responsibilities.
- 04
Evidence
To demonstrate that the measure exists, works and is reviewed.
Implementation map
Nine areas to organize the work.
Open each domain to consult the link between source, actions, measures, documents and evidence.
01Governance and responsibilitiesCybersecurity Management Body (RCS)
Objective
Fix responsibility, supervision, reporting and decision-making capacity.
References
- RJCS: Articles 25 to 32
- Regulation: Articles 13 to 15
Actions
- Approving the governance model
- Designate the cybersecurity officer
- Constituting the permanent contact point
- Define reporting to the management body
Measures
- Responsibilities formally assigned
- Segregation of functions
- Supervision by the management body
- Defined replacement and scaling
Documents
- Cybersecurity policy
- Order or minutes of appointment of the Cybersecurity Officer (RCS)
- RACI Matrix
- Committee reference terms
- Reporting plan and model
Evidence
- Approval minutes
- Communication of the Cybersecurity Officer (RCS) and PCP in MyCiber
- Periodic reports
- Meetings and decisions records
Responsible: Cybersecurity Management Body (RCS) · Cadence: Annual review and after relevant changes
02Risk and treatment planCybersecurity Officer (RCS), risk owners and management body
Objective
Know the risk, select proportional measures and follow the residual risk.
References
- RJCS: Articles 26 to 29
- Regulation: Articles 28 to 31 and Annex II
Actions
- Set methodology
- Identify scenarios, threats and vulnerabilities
- Evaluate probability and impact
- Approving treatment and acceptance of residual risk
Measures
- Consistent assessment criteria
- Risk owners
- Timetable and priority treatment
- Reassessment of residual risk
Documents
- Risk methodology
- Risk matrix
- Risk recording
- Treatment plan
- Statements of acceptance
Evidence
- Approved matrix
- History of changes
- Treatment tasks completed
- Acceptance decisions
Responsible: Cybersecurity Officer (RCS), risk owners and management body · Cadence: Continuous and after changes or incidents
03Assets and inventoriesIT, Asset Owners and Cybersecurity Officer (RCS)
Objective
Learn what supports services and which assets are directly accessible via the Internet.
References
- RJCS, Article 35
- Regulation: Article 32
- Regulation: Annexes III and IV
Actions
- Invent assets, systems, data and services
- Assign owner and criticality
- Link dependencies
- Report and update publicly accessible assets
Measures
- Unique identification
- Classification and criticality
- Controlled life cycle
- Periodic technical reconciliation
Documents
- Asset management policy
- Asset inventory
- Map of dependencies
- List of public assets
- Update procedure
Evidence
- Inventory exports
- Discovery records
- Owner approvals
- Communication receipts MyCiber
Responsible: IT, Asset Owners and Cybersecurity Officer (RCS) · Cadence: Continuous update and periodic reconciliation
04Protection, accesses and configurationIT, security and system owners
Objective
Reduce the probability and impact of improper access, error and technical exploration.
References
- RJCS: Article 26
- Regulation: Annexes III and IV
Actions
- Set identities and profiles
- Apply strong authentication
- Normalize secure settings
- Manage vulnerabilities, fixes and changes
Measures
- Less privilege
- Multifactor authentication
- Hardening
- Risk-based corrections
- Access revision
Documents
- Access control policy
- Profile matrix
- Configuration Baselines
- Vulnerability procedure
- Change management procedure
Evidence
- Access listings
- Review results
- Vulnerability reports
- Patch records
- Change tickets
Responsible: IT, security and system owners · Cadence: Continuous, with scheduled revisions
05Third parties and supply chainPurchases, legal, contract owners and Cybersecurity Officer (RCS)
Objective
Control dependencies and risk introduced by suppliers and providers.
References
- RJCS: Article 26
- Regulation: Annexes III and IV
Actions
- Classify third parties by criticality
- Evaluate before hiring
- Set contractual requirements
- Monitor performance, incidents and output
Measures
- Proportional due diligence
- Notification requirements
- Right of audit
- Management of subcontractors
- External access control
Documents
- Third party policy
- Supplier Inventory
- Assessment questionnaire
- Safety clauses
- Exit plan and reversibility
Evidence
- Assessments completed
- Contracts and additions
- Service meetings
- Reports and certificates
- Reversibility tests
Responsible: Purchases, legal, contract owners and Cybersecurity Officer (RCS) · Cadence: Before hiring and during the contract
06Incident detection and managementPCP, Cybersecurity Officer (RCS), technical teams and crisis management
Objective
Detect, contain, communicate, recover and learn within applicable time limits.
References
- RJCS: Articles 40 to 45
- Regulation: Articles 20 to 22
Actions
- Set criteria and severity
- Operationalise detection and scaling
- Prepare notifications
- Run post-incident analysis
Measures
- Monitoring
- Screening and scaling
- Proof preservation
- Coordinated communication
- Lessons Learned
Documents
- Incident response plan
- Severeness matrix
- Playbooks
- Models for notification
- Post-incident report
Evidence
- Alerts and tickets
- Chronology of the incident
- Severe decisions
- Notification receipts
- Exercises and corrective actions
Responsible: PCP, Cybersecurity Officer (RCS), technical teams and crisis management · Cadence: Permanent and Exercise-tested
07Continuity, recovery and crisisManagement, Continuity, IT, Cybersecurity Officer (RCS) and owners of services
Objective
Maintain or recover essential services within approved objectives.
References
- RJCS: Article 26
- Regulation: Annexes III and IV
Actions
- Perform impact analysis
- Setting priorities and recovery objectives
- Create strategies and plans
- Test scenarios and fix failures
Measures
- Proportional redundancy
- Protected backups
- Tested Recovery
- Alternative channels
- Crisis management
Documents
- Business impact analysis
- Continuity plan
- Recovery plan
- Crisis reporting plan
- Exercise program
Evidence
- Test results
- Restoration reports
- Exercise records
- Remedial actions
- Approval of recovery objectives
Responsible: Management, Continuity, IT, Cybersecurity Officer (RCS) and owners of services · Cadence: Scheduled tests and after relevant changes
08People, training and cultureHuman resources, Cybersecurity Officer (RCS) and heads
Objective
Ensure appropriate competences for functions and reduce human risk.
References
- RJCS: Articles 25 and 26
- Regulation: Annexes III and IV
Actions
- Map functions and competencies
- Form management body and teams
- Sensitize users
- Evaluate effectiveness and strengthen behavior
Measures
- Risk and function training
- Recurrent awareness
- Exercises and simulations
- Input, change and exit rules
Documents
- Training policy
- Competence matrix
- Annual plan
- Content by function
- Onboarding and offboarding procedure
Evidence
- Presences and conclusions
- Evaluation results
- Campaigns and simulations
- Improvement plans
- Onboarding and offboarding logs
Responsible: Human resources, Cybersecurity Officer (RCS) and heads · Cadence: At the entrance, periodically and after changes
09Conformity and continuous improvementCybersecurity Officer (RCS), audit, conformity and management body
Objective
Demonstrate compliance, identify deviations and sustain improvement.
References
- RJCS: Articles 30 and 34
- Regulation: Articles 13, 27 and 30 to 33
- Regulation: Annexes III and IV
Actions
- Map applicable measures
- Collect verification criteria
- Evaluate efficacy
- Treat non-conformities
- Prepare report and supervision
Measures
- Document control
- Self-assessment
- Proportional independent audit
- Monitoring actions
- Review by management
Documents
- Compliance matrix
- Audit plan
- Assessment report
- Remedial action plan
- Annual report, where applicable
Evidence
- Verification criteria satisfied
- Reports and samples
- Non-conformities closed
- Review minutes
- Submissions and receipts
Responsible: Cybersecurity Officer (RCS), audit, conformity and management body · Cadence: Annual program and continuous monitoring
Workflow
Implementation does not start with the purchase of technology.
- 01
Frame
Confirm qualification, level or group and applicable sources.
- 02
Map
To relate each obligation to verification measures and criteria.
- 03
Assess
Identify current status, gaps, dependencies and risk.
- 04
Plan
Assign priority, responsibility, deadlines and resources.
- 05
Run
Implement measures and produce documentation and records.
- 06
Demonstrate
Test effectiveness, store evidence and correct deviations.
Verification criteria
Three complementary ways to demonstrate.
The evidence should be current, attributable, intact, relevant to the measure and sufficient to support the conclusion.
Verifiable observation of a practice, condition or result in operation.
Interview, observation, demonstration or sample.Approved document or controlled record demonstrating decision and enforcement.
Policy, record, ticket, list or receipt.Result extracted from systems, tools or tests.
Configuration, log, scan report, alert or restoration test.Priority matrix
Order by deadline, risk and dependency.
XO
Legal deadline under way, critical exposure or lack of response capacity.
MyCiber, contacts, incidents and critical accesses.Fundamental
Dependency required to implement or prove several other measures.
Governance, risk, assets, Cybersecurity Officer (RCS) and PCP.Risk reduction
Relevant lacuna with material impact on services or data.
Protection, third parties, continuity and recovery.Optimisation
Improved effectiveness, integration, automation or maturity.
Metrics, automation of evidence and certification.Frequently Asked Questions
Documenting is not the same as implementing.
Is a document sufficient to demonstrate implementation?
Not necessarily. A document may demonstrate intention and governance, but effectiveness usually also requires factual or technical records of the implementation of the measure.
Do all entities apply the same measures?
No. Measures shall depend on the qualification, level of compliance or applicable group, risk and any additional sectoral standards.
What is a verification criterion?
It is the factual, documentary or technical evidence used to verify the application of a measure, as set out in Annexes III and IV of the Regulation No. 756/2026.
Who should be responsible for each measure?
There shall be an operational owner with authority and resources, without withdrawing from the management body and the legally provided functions their responsibilities.
Does the Implementation Center replace CyberComply?
No. This center is public knowledge. CyberComply is an external platform that can support document management, evidence and roadmaps.
Does implementation end when all documents exist?
No. Compliance requires continuous operation, monitoring, testing, updating and improvement, in addition to documentation.
Sources and routes
Start with the qualification and confirm the official sources.
Information and structural content. The specific plan shall consider the qualification of the entity, the applicable level or group, the risk, technical instructions and sectoral standards in force.