Skip to content
Back to the knowledge base

5

Secure acquisition, development and maintenance

2026-08-10

Cbw art. 21, third paragraph, opening (e) · NIS-2 art. 21(2)(e) · Cbb art. 11

Software, hardware and services you buy or build yourself carry their own risk. This family covers how you secure that process, from procurement to management.

What this means in practice

You approve a policy for securely acquiring software, hardware and services, develop securely across every phase of a system, manage the configuration of networks and systems, roll out changes with review and a fallback, and find and fix vulnerabilities in time.

Why this is in the law

A vulnerability you build in or buy in yourself is just as much a risk as an outside attack — this is where you address that at the source.

Measures in this family

  • MC-20 — Policy for securely acquiring software, hardware and services
  • MC-21 — Secure development across every phase of a system
  • MC-22 — Configuration management of networks and systems
  • MC-23 — Change management with review and a fallback
  • MC-24 — Finding and fixing vulnerabilities in time

Sources

Also worth reading

Not sure yet whether this applies to you? Take the free scope check.

Take the free scope check