1
Risk analysis and security policy
2026-08-10
Cbw art. 21, third paragraph, opening (a) · NIS-2 art. 21(2)(a) · Cbb art. 6 and 7
Every organisation in scope of the Cybersecurity Act starts with two basics: an approved security policy and a way to assess risk. Without those two, nobody knows where the organisation is heading or which risks it knowingly accepts.
What this means in practice
Your board approves a security policy with a date and version number, assigns roles and authorities so no task is left unowned, and sets up a working security cycle in which the policy is reviewed periodically. You also record a risk management policy: which method you use, when a risk is acceptable, and which security requirements follow from it.
Why this is in the law
Without an approved policy and a risk method, a supervisor has no starting point to judge your other measures — the other nine measure families build on this one.
Measures in this family
- MC-01 — Approved security policy for your IT
- MC-02 — Roles, authorities and separation of duties
- MC-03 — A working security cycle (management system)
- MC-04 — Risk management policy with method and acceptance limits
- MC-05 — Risk analysis, risk overview and security requirements
Sources
Also worth reading
Not sure yet whether this applies to you? Take the free scope check.
Take the free scope check