Requires an encryption policy that can change cryptographic technology as cryptanalysis evolves, plus full key and certificate lifecycle management.
At a glance
| Type | EU regulation |
|---|---|
| Jurisdiction | EU |
| Who it applies to | EU financial entities (banks, insurers, investment firms, payment institutions...) and, indirectly, their critical ICT providers. |
Cryptography requirements
| Reference | Requirement | What a scan and inventory can evidence |
|---|---|---|
| Art. 6 | Encryption and cryptographic controls policy, including provisions for updating or changing cryptographic technology on the basis of developments in cryptanalysis. |
|
| Art. 7 | Cryptographic key management over the whole lifecycle, and a register of certificates for ICT assets supporting critical or important functions. |
|
Sources
Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.