7
Cryptography
2026-08-10
Cbw art. 21, third paragraph, opening (h) · NIS-2 art. 21(2)(h) · Cbb art. 13
Cryptography protects data in transit and at rest. This family isn't about picking a specific algorithm — it's about the policy and management around it.
What this means in practice
You approve a policy on the use of cryptography, set working rules on when and how you encrypt, arrange key management with clearly named owners, and keep an overview of the cryptography in use, including a migration plan for when a method becomes outdated.
Why this is in the law
Cryptography without key management is false security: lose or mismanage the key and you lose the protection anyway.
Measures in this family
- MC-29 — Approved policy on the use of cryptography
- MC-30 — Working rules on when and how you encrypt
- MC-31 — Key management with clearly named owners
- MC-32 — Overview of cryptography in use and a migration plan
Sources
Also worth reading
Not sure yet whether this applies to you? Take the free scope check.
Take the free scope check