NIS2 Directive:
Cryptography and PKI for Essential and Important Entities
Overview
| Region | European Union (transposed into national law across all EU Member States) |
| Applicability | Essential Entities: organizations in high-criticality sectors such as energy, transport, banking, health, water, digital infrastructure, and public administration Important Entities: organizations in other regulated sectors, including postal services, waste management, chemicals, food production, and digital providers Management Bodies: executives who approve and oversee cybersecurity risk management measures and can be held personally liable for failures |
| Relevant sections | Article 21(2)(h): Policies and procedures regarding the use of cryptography and encryption Article 21(2)(j): Multi-factor authentication and secured communications Article 21(2)(d): Supply chain security, including supplier cryptographic practices |
NIS2 (Directive (EU) 2022/2555) is the European Union’s updated cybersecurity directive, covering an estimated 160,000 entities across 18 critical sectors. It replaces the original NIS Directive with a significantly broader scope, mandatory incident reporting, and direct management accountability.
In practical terms, Article 21 requires in-scope entities to implement ten categories of cybersecurity risk-management measures, one of which explicitly names cryptography: documented policies and procedures for the use of cryptography and, where appropriate, encryption, applied based on the entity’s size and risk profile, and paired with multi-factor authentication and secured communications.
Why It Matters
NIS2 applies to a large share of the EU economy across 18 sectors, and while national transposition has proceeded unevenly since the October 2024 deadline, enforcement authority and direct effect are steadily expanding as member states finalize their implementing laws.
Non-compliance carries fines of up to €10 million or 2% of global annual turnover for essential entities (€7 million or 1.4% for important entities), whichever is higher, and some national authorities can hold management personally liable and suspend management functions. Article 21(2)(h) is one of the most concrete and auditable requirements in the directive, making it also one of the easiest for a regulator to test.
How This Maps to Cryptography
NIS2 addresses cryptography most directly through Article 21(2)(h), reinforced by the multi-factor authentication and supply chain provisions elsewhere in Article 21. The key control areas with direct cryptographic implications are:
| Section | Function | What it says | Products |
|---|---|---|---|
| Art. 21(2)(h) — Policies and procedures on cryptography and encryption | Cryptography and Encryption Policy | Documented cryptography policy covering approved algorithms and minimum key lengths with evidence of enforcement across the estate | Command |
| Art. 21(1) and 21(2)(h), reinforced by ENISA baseline guidance | Data Confidentiality at Rest and In Transit | State-of-the-art encryption for stored and transmitted data, underpinned by an internal or managed PKI issuing the certificates | EJBCA |
| Art. 21(2)(j) — MFA or continuous authentication solutions | Multi-Factor and Continuous Authentication | Continuous authentication for critical systems and administrative access, commonly implemented via certificate-based authentication | Command |
| Art. 21(2)(j) — Secured voice, video, text, and emergency communications | Secured Communications | Authenticated, encrypted channels for internal and emergency communications, including signed messages and attachments | SignServer |
| Art. 21(2)(d) — Supply chain security | Supply Chain Cryptographic Assurance | Encryption keys as part of suppliers’ assessments of cryptographic practices | EJBCA |
| Implicit under Art. 21(2)(h), per ENISA and national implementing guidance | Key Management and Rotation | Documented key generation, rotation, HSM-backed storage where appropriate, and destruction procedures with a full audit trail | Command |
Audit Readiness
NIS2 supervisory reviews, whether proactive or triggered by an incident, focus on documented policy plus operational evidence rather than intent alone. Key areas that examiners and national authorities commonly assess:
- Cryptographic Policy Documentation: Does the organization have a written cryptography and encryption policy covering approved algorithms, key lengths, and deprecation triggers?
- Encryption Coverage Evidence: Can the organization demonstrate encryption of sensitive data at rest and in transit, including internal systems, not just external-facing ones?
- Certificate and Key Inventory: Are all certificates and cryptographic keys in use inventoried, with named owners and expiry dates?
- MFA Enforcement on Critical Systems: Is MFA or continuous authentication enforced for all administrative and critical-system access?
- Supplier Cryptographic Assessment: Are direct suppliers and service providers assessed for the strength of their cryptographic practices and key custody arrangements?
- Management Body Sign-Off: Has the management body formally approved and overseen the cryptography risk-management measures consistent with NIS2’s governance and management oversight requirements?
TAKE THIS TO MANAGEMENT
NIS2 is the first EU cybersecurity law that names cryptography outright. Article 21(2)(h) makes documented policies and procedures for the use of cryptography and encryption a legal requirement, not a best practice. If we can’t produce that policy and prove it’s enforced, we’re exposed under a law with fines up to €10 million or 2% of global turnover, whichever is higher.
This one also reaches into the boardroom: NIS2 lets national authorities hold management personally liable for failing to oversee these measures. We need our certificate and key inventory, our encryption coverage, and our supplier cryptographic assessments in a state we could hand to an auditor tomorrow, not the day an incident report is due.


