Keyfactor Tech Days 2027 – Be Part of The Trust Security Conference in San Diego Register now!

NIS2 Directive:

Cryptography and PKI for Essential and Important Entities

Updated: August 24, 2026

Overview

Region European Union (transposed into national law across all EU Member States) 
Applicability Essential Entities: organizations in high-criticality sectors such as energy, transport, banking, health, water, digital infrastructure, and public administration Important Entities: organizations in other regulated sectors, including postal services, waste management, chemicals, food production, and digital providers Management Bodies: executives who approve and oversee cybersecurity risk management measures and can be held personally liable for failures 
Relevant sections Article 21(2)(h):  Policies and procedures regarding the use of cryptography and encryption Article 21(2)(j): Multi-factor authentication and secured communications Article 21(2)(d): Supply chain security, including supplier cryptographic practices 

NIS2 (Directive (EU) 2022/2555) is the European Union’s updated cybersecurity directive, covering an estimated 160,000 entities across 18 critical sectors. It replaces the original NIS Directive with a significantly broader scope, mandatory incident reporting, and direct management accountability. 

In practical terms, Article 21 requires in-scope entities to implement ten categories of cybersecurity risk-management measures, one of which explicitly names cryptography: documented policies and procedures for the use of cryptography and, where appropriate, encryption, applied based on the entity’s size and risk profile, and paired with multi-factor authentication and secured communications. 

Why It Matters 

NIS2 applies to a large share of the EU economy across 18 sectors, and while national transposition has proceeded unevenly since the October 2024 deadline, enforcement authority and direct effect are steadily expanding as member states finalize their implementing laws. 

Non-compliance carries fines of up to €10 million or 2% of global annual turnover for essential entities (€7 million or 1.4% for important entities), whichever is higher, and some national authorities can hold management personally liable and suspend management functions. Article 21(2)(h) is one of the most concrete and auditable requirements in the directive, making it also one of the easiest for a regulator to test. 

How This Maps to Cryptography 

NIS2 addresses cryptography most directly through Article 21(2)(h), reinforced by the multi-factor authentication and supply chain provisions elsewhere in Article 21. The key control areas with direct cryptographic implications are: 

Section Function What it says Products
Art. 21(2)(h) — Policies and procedures on cryptography and encryption Cryptography and Encryption Policy Documented cryptography policy covering approved algorithms and  minimum key lengths with evidence of enforcement across the estate Command 
Art. 21(1) and 21(2)(h), reinforced by ENISA baseline guidance Data Confidentiality at Rest and In Transit State-of-the-art encryption for stored and transmitted data, underpinned by an internal or managed PKI issuing the certificates  EJBCA 
Art. 21(2)(j) — MFA or continuous authentication solutions Multi-Factor and Continuous Authentication Continuous authentication for critical systems and administrative access, commonly implemented via certificate-based authentication Command 
Art. 21(2)(j) — Secured voice, video, text, and emergency communications Secured Communications Authenticated, encrypted channels for internal and emergency communications, including signed messages and attachments SignServer 
Art. 21(2)(d) — Supply chain security Supply Chain Cryptographic Assurance Encryption keys as part of suppliers’ assessments of cryptographic practices 
 
EJBCA 
Implicit under Art. 21(2)(h), per ENISA and national implementing guidance Key Management and Rotation Documented key generation, rotation, HSM-backed storage where appropriate, and destruction procedures with a full audit trail Command 

Audit Readiness 

NIS2 supervisory reviews, whether proactive or triggered by an incident, focus on documented policy plus operational evidence rather than intent alone. Key areas that examiners and national authorities commonly assess: 

  • Cryptographic Policy Documentation: Does the organization have a written cryptography and encryption policy covering approved algorithms, key lengths, and deprecation triggers? 
  • Encryption Coverage Evidence: Can the organization demonstrate encryption of sensitive data at rest and in transit, including internal systems, not just external-facing ones? 
  • Certificate and Key Inventory: Are all certificates and cryptographic keys in use inventoried, with named owners and expiry dates? 
  • MFA Enforcement on Critical Systems: Is MFA or continuous authentication enforced for all administrative and critical-system access? 
  • Supplier Cryptographic Assessment: Are direct suppliers and service providers assessed for the strength of their cryptographic practices and key custody arrangements? 
  • Management Body Sign-Off: Has the management body formally approved and overseen the cryptography risk-management measures consistent with NIS2’s governance and management oversight requirements?