Skip to content
Back to the knowledge base

7

Cryptography

2026-08-10

Cbw art. 21, third paragraph, opening (h) · NIS-2 art. 21(2)(h) · Cbb art. 13

Cryptography protects data in transit and at rest. This family isn't about picking a specific algorithm — it's about the policy and management around it.

What this means in practice

You approve a policy on the use of cryptography, set working rules on when and how you encrypt, arrange key management with clearly named owners, and keep an overview of the cryptography in use, including a migration plan for when a method becomes outdated.

Why this is in the law

Cryptography without key management is false security: lose or mismanage the key and you lose the protection anyway.

Measures in this family

  • MC-29 — Approved policy on the use of cryptography
  • MC-30 — Working rules on when and how you encrypt
  • MC-31 — Key management with clearly named owners
  • MC-32 — Overview of cryptography in use and a migration plan

Sources

Also worth reading

Not sure yet whether this applies to you? Take the free scope check.

Take the free scope check