pqcstatus
Regulation & guidance

NIS2 (Directive (EU) 2022/2555): cryptography requirements and deadlines

EU directive

Cybersecurity risk-management measures include policies on cryptography and encryption; a 2026 proposal adds the PQC transition to national strategies.

At a glance

TypeEU directive
JurisdictionEU
Who it applies toEssential and important entities in the sectors covered by NIS2 (energy, transport, health, digital infrastructure, manufacturing, ...).

Cryptography requirements

ReferenceRequirementWhat a scan and inventory can evidence
Art. 21(2)(h)Policies and procedures regarding the use of cryptography and, where appropriate, encryption.
  • Cryptography policy
  • Cryptographic inventory

Key dates

  1. Commission proposal COM(2026) 13: national strategies must include a policy for the transition to post-quantum cryptography (not yet adopted).

Sources

  1. Directive (EU) 2022/2555 — NIS2 · European Union
  2. COM(2026) 13 — Proposal amending the NIS2 Directive (PQC transition in national strategies) · European Commission (draft)

Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.

Frequently Asked Questions

Who must comply with NIS2 (Directive (EU) 2022/2555)?

Essential and important entities in the sectors covered by NIS2 (energy, transport, health, digital infrastructure, manufacturing, ...).

What does NIS2 (Directive (EU) 2022/2555) require for cryptography?

Art. 21(2)(h): Policies and procedures regarding the use of cryptography and, where appropriate, encryption.

What are the key dates of NIS2 (Directive (EU) 2022/2555)?

January 20, 2026: Commission proposal COM(2026) 13: national strategies must include a policy for the transition to post-quantum cryptography (not yet adopted).