Cybersecurity risk-management measures include policies on cryptography and encryption; a 2026 proposal adds the PQC transition to national strategies.
At a glance
| Type | EU directive |
|---|---|
| Jurisdiction | EU |
| Who it applies to | Essential and important entities in the sectors covered by NIS2 (energy, transport, health, digital infrastructure, manufacturing, ...). |
Cryptography requirements
| Reference | Requirement | What a scan and inventory can evidence |
|---|---|---|
| Art. 21(2)(h) | Policies and procedures regarding the use of cryptography and, where appropriate, encryption. |
|
Key dates
- Commission proposal COM(2026) 13: national strategies must include a policy for the transition to post-quantum cryptography (not yet adopted).
Sources
- Directive (EU) 2022/2555 — NIS2 · European Union
- COM(2026) 13 — Proposal amending the NIS2 Directive (PQC transition in national strategies) · European Commission (draft)
Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.