For years, cryptography was treated as a best practice: something security teams knew they should do well, but rarely something a regulator would test line by line. This is no longer the case, with regulations such as the Network and Information Systems (NIS) directive bringing cryptography inside their scope. In fact, NIS2, the latest version of NIS, is the first EU cybersecurity law to name cryptography outright, moving it from an internal aspiration to a legal requirement with consequences that reach the boardroom.
That shift matters for every security leader whose organization with a stake in compliance. Under NIS2, a documented cryptography policy is not a nice-to-have you can promise to build later. It is something you may be asked to produce and prove, backed by enforcement powers that include significant fines and personal accountability for management. Understanding what the directive asks for, and building a strategy that maps to it, is now part of the job.
What NIS2 is and how far it reaches
NIS2 (Directive (EU) 2022/2555) is the European Union’s updated cybersecurity directive. It replaces the original NIS Directive with a significantly broader scope, mandatory incident reporting, and direct management accountability. In practical terms, it pulls a much larger share of the EU economy under a common set of cybersecurity obligations.
The reach is substantial. NIS2 covers an estimated 160,000 entities across 18 critical sectors, and it splits those organizations into two tiers:
- Essential entities operate in high-criticality sectors such as energy, transport, banking, health, water, digital infrastructure, and public administration.
- Important entities operate in other regulated sectors, including postal services, waste management, chemicals, food production, and digital providers.
Both tiers carry obligations. National transposition has proceeded unevenly since the October 2024 deadline, but enforcement authority and direct effect keep expanding as member states finalize their implementing laws. Waiting for perfect clarity across every jurisdiction is not a safe strategy when the underlying obligations already apply.
Article 21(2)(h): the cryptography mandate
The heart of the cryptography obligation sits in Article 21. It requires in-scope entities to implement ten categories of cybersecurity risk-management measures, and one of them explicitly names cryptography: documented policies and procedures for the use of cryptography, applied based on the entity’s size and risk profile. That requirement is reinforced by higher level security measures such as multi-factor authentication and secured communications under Article 21(2)(j).
For digital-infrastructure and trust-service entities, the expectations go further through a directly applicable implementing regulation. Those detailed requirements describe what a mature cryptography policy actually contains, and they are worth reading closely because they set the bar auditors will use.
At its core, the policy exists to protect the confidentiality, authenticity, and integrity of data, scoped by the entity’s own asset classification and risk assessment. From that classification, the policy has to derive two things:
- The type, strength, and quality of cryptographic protection required for each class of asset, covering both data at rest and data in transit.
- The concrete approved list that follows from it: which protocols, which algorithms, what cipher strength, and which solutions and usage practices are sanctioned.
This is also the one place in the NIS2 stack where cryptographic agility appears as a named expectation. Where appropriate, the policy should follow a cryptographic agility approach, so that algorithms can be changed as the state of the art moves.
The third element is key management, and it reads as a full lifecycle. A compliant policy addresses generation; issuing and obtaining public key certificates; distribution and activation; storage and authorized access; rotation; compromise handling; revocation; recovery; backup and archival; destruction; logging and audit; and activation and deactivation dates that hold keys to a defined cryptoperiod. Finally, the policy has to be reviewed at planned intervals against the state of the art in cryptography, so it does not quietly go stale.
Why this is one of the most testable requirements in the directive
Cryptography stands out under NIS2 because it is concrete. Many risk-management measures are open to interpretation, but a written cryptography policy either exists and is enforced, or it does not exist at all. There is no wiggle room. That makes Article 21(2)(h) one of the most auditable requirements in the directive, and one of the easiest for a regulator to test.
The stakes behind that test are high. Non-compliance carries fines of up to EUR 10 million or 2% of global annual turnover for essential entities, whichever is higher, and up to EUR 7 million or 1.4% for important entities. Beyond the financial exposure, some national authorities can hold management personally liable and even suspend management functions. In other words, the accountability does not stop at the security team: it reaches the people who approve and oversee the risk-management measures.
Building a cryptography strategy that maps to NIS2
A strong response to NIS2 is not a single control. It is a strategy that covers the areas where the directive touches cryptography directly. Six control areas do most of the work:
- Cryptography and encryption policy. A documented policy covering approved algorithms and minimum key lengths, with evidence that it is enforced across the estate.
- Data confidentiality at rest and in transit. State-of-the-art encryption for stored and transmitted data, underpinned by an internal or managed PKI that issues the certificates.
- Multi-factor and continuous authentication. Continuous authentication for critical systems and administrative access, commonly implemented through certificate-based authentication.
- Secured communications. Authenticated, encrypted channels for internal and emergency communications, including signed messages and attachments.
- Supply chain cryptographic assurance. Assessing suppliers for the strength of their cryptographic practices and their key custody arrangements, as required under Article 21(2)(d).
- Key management and rotation. Documented key generation, rotation, storage backed by hardware security modules where appropriate, and destruction procedures with a full audit trail.
Together, these areas turn a legal requirement into an operating model. Each one produces the kind of evidence a supervisory review looks for.
From policy on paper to enforced controls
Here is the point security leaders miss most often: a policy document is only half the requirement. NIS2 supervisory reviews focus on documented policy plus operational evidence, not intent alone. A binder that describes good practice but has never been tested does little to reduce exposure. Entities must establish, implement and apply policies and procedures to assess whether the risk-management measures are effectively implemented and maintained. The controls have to be live, and you have to be able to show it.
Getting audit ready for a NIS2 supervisory review
NIS2 reviews can be proactive or triggered by an incident, so readiness cannot be a last-minute exercise. The most reliable way to prepare is to convert the questions examiners ask into a standing checklist:
- Cryptographic policy documentation: a written cryptography and encryption policy covering approved algorithms, key lengths, and deprecation triggers.
- Encryption coverage evidence: proof that sensitive data is encrypted at rest and in transit, including internal systems, not just external-facing ones.
- Certificate and key inventory: every certificate and cryptographic key inventoried, with named owners and expiry dates.
- MFA enforcement: multi-factor or continuous authentication enforced for all administrative and critical-system access.
- Supplier cryptographic assessment: direct suppliers and service providers assessed for the strength of their cryptographic practices and key custody.
- Management body sign-off: formal approval and oversight of the cryptography risk-management measures by the management body.
It is also necessary to investigate whether other regulations that become binding through NIS2 apply to your organization, and folding certificate discovery, certificate management, and cryptographic agility into the same program. The entities that fare best are the ones that keep their inventory, coverage, and supplier assessments in a state they could hand to an auditor tomorrow, rather than the day an incident report is due.
How Keyfactor can help
Keyfactor’s platform is built to turn the NIS2 cryptography mandate into enforced, evidence-backed controls rather than aspirations on paper.
- Secured, signed communications. SignServer supports authenticated, encrypted channels, including signed messages and attachments, for internal and emergency communications.
- PKI-backed encryption and certificate-based authentication. EJBCA delivers state-of-the-art encryption for data at rest and in transit, underpinned by an internal or managed PKI that issues the certificates behind confidentiality and certificate-based authentication.
- Documented, enforced cryptography policy and key management. Keyfactor Command provides a documented cryptography policy covering approved algorithms and minimum key lengths, along with key generation, rotation, and destruction procedures backed by a full audit trail and enforced across the estate.
For a deeper walkthrough of how these controls map across the major regulations affecting manufacturers, download Keyfactor’s Cryptographic Compliance Guide for Manufacturing.
Take action and get ready
NIS2 has redrawn the line between good security hygiene and legal obligation, and cryptography now sits firmly on the legal side of it. With fines reaching into the millions and personal liability on the table for management, security leaders cannot treat a cryptography strategy as future work.
The practical starting points are clear. Get your certificate and key inventory, your encryption coverage, and your supplier cryptographic assessments into an audit-ready state, secure formal management sign-off, and keep the whole program under regular review against the state of the art. If you want a structured reference to build from, download the Cryptographic Compliance Guide for Manufacturing, and request a demo to see how Keyfactor can help you enforce it.
Got NIS2 questions? We’ve got answers.
What is the NIS2 Directive?
NIS2 (Directive (EU) 2022/2555) is the EU’s updated cybersecurity directive. It replaces the original NIS Directive with broader scope, mandatory incident reporting, and direct management accountability across 18 sectors.
Does NIS2 require encryption?
Article 21(2)(h) requires documented policies and procedures for the use of cryptography and, where appropriate, encryption, applied according to the entity’s size and risk profile. It is the first EU cybersecurity law to name cryptography outright.
Who must comply with NIS2?
Essential entities in high-criticality sectors such as energy, transport, banking, health, and digital infrastructure must comply, along with important entities in other regulated sectors such as postal services, waste management, chemicals, and food production.
What are the penalties under NIS2?
Essential entities face fines up to EUR 10 million or 2% of global annual turnover, whichever is higher. Important entities face up to EUR 7 million or 1.4%.
Can executives be held personally liable under NIS2?
Yes. Some national authorities can hold management personally liable for failing to oversee cybersecurity measures, and they can even suspend management functions.
What does a NIS2 cryptography policy need to include?
It needs asset classification, approved algorithms and protocols, minimum key lengths, deprecation triggers, and evidence of enforcement across the estate. That is supported by a documented key management and rotation process spanning the full key lifecycle.
How does NIS2 treat supply chain security?
Article 21(2)(d) requires entities to assess their suppliers, including the strength of those suppliers’ cryptographic practices and their key custody arrangements.
What should security leaders do first to prepare for NIS2?
Produce a written cryptography and encryption policy, inventory all certificates and keys with named owners and expiry dates, and secure formal management sign-off on the risk-management measures.