SentriKat is live, launch pricing and hands-on onboarding for founding customers. Get started
All articles

NIS2 Cryptography & Encryption (Article 21(2)(h)): Policy, Not Just Padlocks

NIS2 Article 21(2)(h) requires policies on cryptography and, where appropriate, encryption. The measure isn't 'turn on HTTPS', it's having a deliberate, documented approach to protecting data.

Denis Sota · · 2 min read

Article 21(2)(h) calls for “policies and procedures regarding the use of cryptography and, where appropriate, encryption.” The wording matters: NIS2 doesn’t just want encryption switched on somewhere, it wants a deliberate, documented approach to where and how you protect data with cryptography.

Not legal advice, just orientation. Each member state transposes NIS2 into its own law (Italy did so with D.Lgs. 138/2024, administered by the ACN), so check the wording that actually binds you with your national authority.

What a cryptography policy covers

A practical policy answers a few questions consistently across the organisation:

  • Data in transit, TLS for everything that crosses a network (web, APIs, email transport, internal service-to-service where feasible), with modern protocol versions and no broken ciphers.
  • Data at rest, encryption for sensitive data on disks, laptops, backups, and databases, so a lost device or stolen backup isn’t a breach.
  • Key management, where keys live, who can access them, how they’re rotated, and what happens if one is compromised. Weak key management quietly undoes strong encryption.
  • Standards, which algorithms and key lengths are acceptable, and a path away from deprecated ones.

“Where appropriate” gives you room to be proportionate, but the policy (the decision-making framework) is expected regardless.

The common gaps

The usual weak points aren’t the absence of TLS; they’re: backups stored unencrypted, laptops without full-disk encryption, sensitive data sitting in plaintext in a database or log, and keys checked into a repository. A short policy plus a quick inventory of “where is our sensitive data and is it encrypted at each stage” surfaces most of them.

Honest scope note

Cryptography isn’t what SentriKat does, we focus on exploited-first vulnerability management, not key management. So treat this measure on its own: write the policy, encrypt laptops and backups, get key handling under control. Where the two worlds touch is that vulnerable crypto libraries (an outdated OpenSSL, a library with a known exploited CVE) are a vulnerability-management problem, and that part, SentriKat will flag.

Start here

Write a one-to-two-page cryptography policy (in-transit, at-rest, key management, acceptable algorithms), confirm full-disk encryption on all laptops, and verify your backups are encrypted. That covers the bulk of real-world risk for this measure.

See how cryptography ranks among your ten NIS2 measures with the free NIS2/DORA readiness check.

Ready to automate your vulnerability management?

Deploy SentriKat on-premises in minutes. Track CISA KEV vulnerabilities, generate NIS2 compliance reports, and protect your infrastructure.

Request a Demo