NIS2 — Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union — is the EU's horizontal cybersecurity law. It supersedes the 2016 NIS Directive, widening scope from a handful of operators to "essential" and "important" entities across eighteen critical sectors and imposing a common floor of risk-management measures, incident reporting, and management accountability. As a directive it works through national law: member states were required to transpose it by 17 October 2024, so the operative obligations sit in each country's implementing legislation, on top of the directive's common baseline.
Why it matters
For a post-quantum programme, NIS2's significance is one clause. Article 21(2) lists the minimum cybersecurity risk-management measures every in-scope entity must take, and item (h) is "policies and procedures regarding the use of cryptography and, where appropriate, encryption" (Directive (EU) 2022/2555). Like ISO 27001 A.8.24, the clause is deliberately standard-agnostic — it names no algorithms and no PQC deadline, inheriting its timelines in practice from NIST IR 8547 and, where relevant, CNSA 2.0. But a cryptography policy that cannot say which systems depend on quantum-vulnerable algorithms, or how the entity will transition off them, is a policy in name only — and Article 21 requires the measures to be appropriate and proportionate to the risk, which for long-lived sensitive data now includes harvest-now-decrypt-later exposure.
What the directive requires
Beyond the cryptography clause, NIS2's baseline for essential and important entities includes:
- Risk-management measures (Art. 21) — an all-hazards minimum set spanning risk analysis, incident handling, business continuity, supply-chain security, secure development, cryptography and encryption policies, access control, and multi-factor authentication.
- Incident reporting (Art. 23) — significant incidents reported to the CSIRT or competent authority: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month.
- Management accountability (Art. 20) — management bodies must approve and oversee the risk-management measures and can be held liable for infringements; training is expected.
- Enforcement with teeth — administrative fines up to €10 million or 2% of worldwide annual turnover for essential entities, and €7 million or 1.4% for important entities, alongside supervisory powers.
The directive is the floor — your national transposition is the law
NIS2 obligations reach you through national implementing legislation, and member states can go beyond the directive's minimum. Scope registration, reporting channels, and enforcement detail vary by country — and several transpositions arrived late, so requirements have been landing on staggered dates. Anchor your cryptography evidence to the directive's Article 21 baseline, then verify the specifics against the transposition in each member state where you operate.
How quantakrypto helps
We help you turn Article 21(2)(h) from a line in a policy into evidence — we do not issue NIS2 compliance attestations, and a cryptography assessment alone does not make an entity compliant. Our audit maps explicitly onto the ISO 27001 / DORA / NIS2 control set: a PQC readiness assessment and cryptographic inventory that shows where quantum-vulnerable cryptography lives across your code, protocols, and dependencies, with CI gating so the picture stays current instead of decaying into a point-in-time snapshot. Our migration engineering delivers the documented transition plan, sequenced against the NIST timeline. The same artifacts serve ISO 27001 A.8.24 if that is your certification anchor, and DORA's cryptographic-controls requirements if you are also a financial entity. Incident reporting, registration with your national authority, and the wider Article 21 measures remain organizational obligations outside our scope.
Frequently asked questions
Who is in scope of NIS2?
"Essential" and "important" entities across eighteen sectors — including energy, transport, banking and financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, postal services, waste, chemicals, food, manufacturing, and digital providers. Classification generally follows sector plus size (typically 50+ employees or over €10 million turnover), with some entities in scope regardless of size. The precise scope for you is set by each member state's transposition.
Does NIS2 require post-quantum cryptography?
No. Article 21(2)(h) requires policies and procedures on the use of cryptography and, where appropriate, encryption — it names no algorithms and sets no PQC deadline. But the measures must be appropriate to the risk, and for long-lived sensitive data the quantum threat is part of that risk. In practice, assessing your cryptography and planning the transition against the NIST IR 8547 timeline is how entities evidence that the clause is being managed rather than merely restated.
How does NIS2 relate to DORA?
DORA is lex specialis for the financial sector: where its requirements apply, financial entities follow DORA's ICT-risk, incident-reporting, and testing regime instead of the overlapping NIS2 provisions. NIS2 covers the broader critical-sector economy. The cryptographic groundwork is the same for both — an inventory, a quantum-risk assessment, and a transition plan serve Article 21(2)(h) under NIS2 and the cryptographic-controls requirements under DORA.
Is a PQC readiness assessment a NIS2 compliance attestation?
No. NIS2 compliance spans governance, incident reporting, supply-chain security, and the full Article 21 measure set, under national supervision — no single assessment covers that. What a cryptography-focused assessment produces is evidence for one named measure: proof that you know where your cryptography lives, how exposed it is to quantum attack, and how you plan to transition. That is the artifact an auditor or supervisor can actually inspect.
Work with us on NIS2
Related reading
References
- EUR-Lex: Directive (EU) 2022/2555 (NIS2) — the directive; Article 21(2)(h) is the cryptography measure, Article 23 the reporting regime.
- EUR-Lex: Directive (EU) 2016/1148 (NIS1) — the predecessor NIS2 repeals and replaces.
- ENISA: NIS2 Directive resources — implementation guidance and technical mapping for the Article 21 measures.