The Network and Information Security Directive 2, formally Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, is the EU's most consequential cybersecurity law since the GDPR. It replaced the original NIS Directive (Directive (EU) 2016/1148), expanded the scope from a few thousand operators to potentially hundreds of thousands of "essential" and "important" entities, and laid down minimum cybersecurity risk-management measures that include explicit cryptography obligations.
Member States were required to transpose NIS2 into national law by 17 October 2024 under Article 41. Most missed that deadline, but transposition has been progressing through 2025 and 2026, with Belgium, Germany, France, Spain, and Italy among the early movers. The European Commission has launched infringement proceedings against several Member States for delayed transposition.
For a security or compliance team, the question is not whether NIS2 applies. The question is which entities in your supply chain are essential or important, what the cryptography baseline looks like in practice, and how the Article 21 risk-management framework intersects with the post-quantum migration that is already on every regulator's agenda.
The Scope of NIS2
NIS2 covers two categories: "essential entities" and "important entities," defined in Annex I and Annex II of the directive. Essential entities include energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, and space. Important entities include postal and courier services, waste management, manufacturing of critical products including chemicals, food, manufacturing of medical devices, computers, electronics, machinery, motor vehicles, and digital providers.
Article 2 sets the size threshold: medium-sized enterprises (50+ employees, EUR 10 million+ turnover) and large enterprises in the relevant sectors. Some entities are in scope regardless of size, including DNS service providers, top-level domain registries, qualified trust service providers, and providers of public electronic communications networks.
The practical effect: most large and medium-sized organisations operating in the listed sectors across the EU now sit inside a regulatory framework with cryptography obligations.
Article 21: The Cryptography Provisions
Article 21 of NIS2 lists the minimum cybersecurity risk-management measures. Paragraph 2 enumerates ten categories:
(a) policies on risk analysis and information system security; (b) incident handling; (c) business continuity, such as backup management and disaster recovery, and crisis management; (d) supply chain security; (e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure; (f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures; (g) basic cyber hygiene practices and cybersecurity training; (h) policies and procedures regarding the use of cryptography and, where appropriate, encryption; (i) human resources security, access control policies and asset management; (j) the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate.
Sub-paragraph (h) is the explicit cryptography obligation. Sub-paragraph (j) is the explicit encryption obligation for communications. Both are framed in technology-neutral language, but the implementing acts and Commission guidance are pushing toward concrete baselines.
The European Commission adopted Commission Implementing Regulation (EU) 2024/2690 on 17 October 2024, laying down rules for the application of Directive (EU) 2022/2555 with respect to digital infrastructure and digital service providers. Annex I, Section 4.4 of this implementing regulation requires cryptographic procedures aligned with the principle of state-of-the-art technology, with specific reference to ENISA guidance and to algorithms that are robust against known attacks.
How "State of the Art" Translates into Practice
The phrase "state of the art" appears in NIS2 (Article 21, paragraph 1), in the GDPR (Article 32), and across most modern EU cybersecurity legislation. It is technology-neutral, which means national supervisory authorities have to interpret it. In practice, they reach for ENISA guidance and for national catalogues such as Germany's BSI TR-02102-1, France's ANSSI Référentiel général de sécurité, and the Netherlands' Forum Standaardisatie list.
For symmetric cryptography, "state of the art" in 2026 means AES-128 minimum, AES-256 preferred. ChaCha20-Poly1305 is acceptable. SHA-256 minimum, SHA-3 or BLAKE2/BLAKE3 acceptable.
For asymmetric cryptography, the picture is shifting fast. RSA-2048 is still acceptable for short-lived authentication. RSA-3072 is the BSI baseline for new systems. ECDH using Curve25519 or NIST P-256 is acceptable. But for long-term confidentiality, BSI TR-02102-1 now lists ML-KEM in hybrid mode (combined with classical ECDH) as the recommended approach. ML-DSA in hybrid mode is recommended for digital signatures with long-term verification needs.
This is a direct consequence of the "harvest now, decrypt later" threat. Encrypted traffic captured today and stored by an adversary can be decrypted once a cryptographically relevant quantum computer (CRQC) exists. For sectors covered by NIS2 with long-lived data, including health, banking, and critical infrastructure, the regulatory expectation is that operators are planning the transition to post-quantum cryptography now.
For the underlying NIST standards, see NIST FIPS Guide. For the threat model, see Harvest Now Decrypt Later.
Member State Transposition: A Patchwork
NIS2 is a directive, not a regulation. Each Member State must transpose it through national law, which means there are 27 slightly different implementations.
Belgium transposed via the Act of 26 April 2024, in force 18 October 2024. The Belgian Centre for Cyber Security (CCB) is the competent authority. The act requires registration of essential and important entities and imposes 24-hour early-warning incident reporting.
Germany transposed via the NIS2-Umsetzungs- und Cybersicherheitsstaerkungsgesetz (NIS2UmsuCG), with the Federal Office for Information Security (BSI) as the competent authority. The German implementation maintains the BSI's existing TR-02102-1 cryptography catalogue as the de facto state-of-the-art reference.
France's transposition ran past the deadline, with ANSSI as the designated competent authority. ANSSI publishes its own référentiel and increasingly aligns with ENISA guidance.
The Netherlands transposed via the Cyberbeveiligingswet, with the Nationaal Cyber Security Centrum (NCSC-NL) as the competent authority. Dutch transposition was delayed past the October 2024 deadline; entities are operating under both legal uncertainty and active enforcement signals.
Spain, Italy, Sweden, Denmark, Finland, Ireland, Portugal, Austria, and the Czech Republic have all either transposed or have draft legislation in advanced stages.
What this patchwork means for cryptography compliance: the underlying obligation is uniform under Article 21, but the supervisory authority you report to, the technical baselines they reference, and the enforcement intensity vary by Member State. A multinational operator must comply with each jurisdiction's transposition.
Incident Reporting and Cryptography
Article 23 of NIS2 imposes a multi-stage incident reporting obligation. Within 24 hours of becoming aware of a "significant incident," the entity must submit an early warning. Within 72 hours, an incident notification with an initial assessment. Within one month, a final report.
A "significant incident" under Article 23(3) is one that has caused or is capable of causing severe operational disruption, financial loss, or considerable material or non-material damage to other natural or legal persons.
Cryptographic incidents are within scope. A compromise of a private signing key, a deprecation of a TLS profile that affects authentication, a breach where encrypted data is stolen but the attackers may have access to keys, or a vulnerability that requires emergency rotation across an estate: all of these can qualify as significant incidents.
For organisations running classical cryptography on long-lived data, the question is whether the existence of "harvest now, decrypt later" risk itself qualifies as a known weakness that, if exploited, would constitute a significant incident. The conservative interpretation, consistent with how supervisory authorities have started messaging, is that the migration to post-quantum cryptography is part of due diligence under Article 21, not a future compliance topic.
Supply Chain Security Under Article 21(2)(d)
Article 21(2)(d) requires supply chain security measures, and recital 85 to 90 of NIS2 emphasise the need to assess the cybersecurity of suppliers and service providers. The Commission's Coordinated Risk Assessment of Critical Supply Chains (Commission Recommendation (EU) 2023/1992) explicitly references cryptographic dependencies.
For a NIS2-covered entity, supply chain security includes asking the right cryptography questions: what algorithms do my suppliers use, are their TLS endpoints configured according to current ENISA guidance, do they have a post-quantum migration plan, do they sign their software updates with algorithms that will remain trustworthy through the relevant data lifetime?
Many software vendors are now publishing post-quantum readiness statements. Cloudflare, Google, AWS, and Microsoft have all rolled out hybrid post-quantum TLS in production. Open-source projects including OpenSSH (release 9.0, April 2022, sntrup761x25519) and OpenSSL 3.5 (April 2025, hybrid ML-KEM in TLS) have shipped post-quantum support.
A NIS2-covered entity that relies on suppliers without post-quantum readiness statements is incurring supply chain risk that supervisory authorities will increasingly want to see addressed in the Article 21(2)(d) assessment.
Penalties
Article 34 of NIS2 sets minimum penalty levels. Essential entities can be fined up to EUR 10 million or 2 percent of total worldwide annual turnover, whichever is higher. Important entities can be fined up to EUR 7 million or 1.4 percent of total worldwide annual turnover, whichever is higher.
Article 32 also empowers supervisory authorities to suspend certifications, prohibit the exercise of management functions, and impose administrative fines on individual managers under Article 32(6).
These are GDPR-level penalties, applied to a wider range of obligations and a wider range of entities.
Building a NIS2 Cryptography Programme
The starting point is an inventory: what cryptographic algorithms, key lengths, protocols, and libraries are in use across the estate, and what data lifetimes do they protect? See How to Inventory Cryptographic Assets.
The next step is a gap analysis against ENISA, BSI, ANSSI, or your national authority's current guidance.
The third step is the migration plan. For organisations with long-lived data, this includes a roadmap to hybrid post-quantum cryptography. ML-KEM-768 with X25519 for key establishment, ML-DSA-65 with Ed25519 for signatures, and AES-256-GCM for symmetric encryption form a defensible 2026 baseline. See Hybrid Encryption and ML-KEM Explained.
The fourth step is governance: who owns cryptographic risk, how is it tracked, what is the change-management process when an algorithm is deprecated?
FAQ
Does NIS2 apply to my small business? NIS2 applies primarily to medium-sized and large enterprises in the listed sectors (Article 2(1) and Article 2(2)). Small businesses are generally out of scope unless they are in a critical role, such as a DNS provider or a qualified trust service provider. Member State transposition can extend scope.
What does "state of the art" cryptography mean under NIS2? NIS2 does not define specific algorithms. National authorities reference ENISA, BSI TR-02102-1, ANSSI guidance, and similar catalogues. In 2026, this means AES-256, SHA-3 or BLAKE3 for hashing, hybrid post-quantum KEM (ML-KEM with classical ECDH) for new long-term key establishment, and hybrid post-quantum signatures (ML-DSA with classical) for long-term verification.
Is post-quantum cryptography required by NIS2? NIS2 does not name post-quantum algorithms. But the Article 21 obligation to take "state-of-the-art" technical measures, combined with the data lifetime in many NIS2-covered sectors, is being interpreted by national authorities as requiring active planning for post-quantum migration. The CNSA 2.0 timeline and ENISA's 2024 post-quantum cryptography report both treat this as urgent.
What is the deadline for NIS2 compliance? Member States had until 17 October 2024 to transpose. National laws typically apply from the transposition date, with some grace periods. Most Member States are now actively enforcing.
How does NIS2 interact with DORA? DORA (Regulation (EU) 2022/2554) applies to financial entities and is directly applicable from 17 January 2025. For financial entities that are also NIS2 essential entities, DORA is generally lex specialis and takes precedence on overlapping provisions.
Sources
- Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 (NIS2), https://eur-lex.europa.eu/eli/dir/2022/2555/oj
- Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024, https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj
- ENISA, Post-Quantum Cryptography: Current state and quantum mitigation, May 2021 (with subsequent updates), https://www.enisa.europa.eu/publications
- BSI Technical Guideline TR-02102-1 Cryptographic Mechanisms: Recommendations and Key Lengths, https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-02102/tr-02102.html
- NSA Commercial National Security Algorithm Suite 2.0, September 2022, https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/3148990/
Related Articles
Protect Your Data Before Q-Day Arrives
QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.