NIS2 Directive
NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

NIS2 Directive Art.21.2.h: Policies and procedures on the use of cryptography and, where appropriate, encryption

The obligation is to have decided, in writing, where cryptography is used and how it is governed. That covers which algorithms and key lengths are permitted, where data is encrypted at rest and in transit, how certificates and keys are generated, stored, rotated and revoked, and who may access key material. Encryption is qualified by where appropriate, which means the entity is expected to reach a reasoned position rather than encrypt everything or nothing. Key management is where this obligation usually fails in practice, because encryption can be deployed correctly while the keys sit somewhere that removes the protection. Expired certificates and forgotten key owners are also the common route by which an availability incident starts.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 48 controls across 16 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

C5 (Germany) · 5 controls

  • C5-COS-08 Policies for data transmission
  • C5-CRY-01 Policy for the use of encryption procedures and key management
  • C5-CRY-02 Encryption of data for transmission (transport encryption)
  • C5-CRY-03 Encryption of sensitive data for storage
  • C5-CRY-04 Secure key management

CMMC 2.0 · 4 controls

FedRAMP High · 4 controls

  • SC-12 Cryptographic Key Establishment and Management
  • SC-13 Cryptographic Protection
  • SC-28(1) Cryptographic Protection
  • SC-8(1) Cryptographic Protection

FedRAMP Moderate · 4 controls

  • SC-12 Cryptographic Key Establishment and Management
  • SC-13 Cryptographic Protection
  • SC-28(1) Cryptographic Protection
  • SC-8(1) Cryptographic Protection

NIST SP 800-171 Rev 3 · 4 controls

  • 03.08.09 System Backup - Cryptographic Protection
  • 03.13.08 Transmission Confidentiality and Integrity
  • 03.13.10 Cryptographic Key Establishment and Management
  • 03.13.11 Cryptographic Protection

NIST SP 800-53 Rev 5 · 4 controls

PCI DSS 4.0 · 4 controls

  • 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
  • 3.6.1.1 3.6.1.1 Service provider cryptographic architecture documented
  • 3.6.1.3 3.6.1.3 Cleartext key component access limited to minimum custodians
  • 3.7.4 3.7.4 Key changes at end of cryptoperiod

CIS Controls v8 · 3 controls

  • CIS-3.10 Encrypt Sensitive Data in Transit
  • CIS-3.11 Encrypt Sensitive Data at Rest
  • CIS-3.6 Encrypt Data on End-User Devices
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected

ISO 27001:2022 · 2 controls

  • 5.17 Authentication information
  • 8.24 Use of cryptography

ISO 27002:2022 · 2 controls

  • 5.17 Authentication information
  • 8.24 Use of cryptography

SOC 2 · 2 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal

DORA · 1 control

EU AI Act · 1 control

GDPR · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.21.2.h is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 48 it maps to, and the evidence behind each claim, over MCP and REST.