NIS2 Article 21(2)(h): cryptography and encryption
Measure (h) asks you to have rules for how your company uses cryptography and encryption. Writing the rules is your job. Whether your public services actually follow them is something we can look at from outside, and you can see the result for free.
Check my domain's cryptography
Written by the SkyQon engineering team · Last checked against the legal texts on 2 October 2026
What the law says
Article 21(2)(h) of the NIS2 Directive (EU) 2022/2555 asks for policies and procedures on the use of cryptography and, where appropriate, encryption. You won't find a list of approved algorithms in it. The Directive leaves it to you to decide what you accept, write that down, and apply it.
Implementing Regulation (EU) 2024/2690 goes into more detail for the digital providers it covers, such as cloud, data centre, DNS and managed service providers. Its section on cryptography expects the policy to say which types and strengths of algorithms and protocols you use, how keys are handled from creation to destruction, and to be reviewed as the state of the art moves on. If you're not one of those providers, it is still the clearest picture of what a regulator has in mind.
Official text: Directive (EU) 2022/2555 · Implementing Regulation (EU) 2024/2690
What we can see from outside
Our free check connects to your domain much like a browser or a mail server would, and reads what it is offered. For this measure, that gives you:
- The certificate's signature algorithm and key size. We flag weak algorithms and RSA keys shorter than 2048 bits.
- Whether the certificate's key is ready for post-quantum cryptography, which tells you what will need replacing when you plan that move.
- Encryption for incoming email. We look at whether your mail servers offer STARTTLS, and whether you publish MTA-STS and TLS-RPT, which tell other mail servers to insist on encryption and to report back when it fails.
- DNSSEC, meaning whether your DNS answers are signed so nobody can quietly swap them on the way.
- Revocation information: whether your certificate tells visitors where to check that it hasn't been withdrawn.
A typical case
The website certificate is modern and renews by itself, so the team assumes encryption is handled. The check tells a different story for email: DNSSEC was never switched on and there is no MTA-STS policy, so a sending server can fall back to unencrypted delivery without anyone noticing. Neither fix is hard, but nobody had looked.
This is a composite of things we often see, not a specific customer.
What we can't see
We look at the public side of one domain, on the day you run the check. We don't list every TLS version and cipher your servers will accept. We can't see encryption inside your network, on your databases or on staff laptops, and we have no view of how your keys are created, stored or destroyed. Those parts of measure (h) live in your own policy and records.
What an auditor will want
An auditor will want to see the policy working, not just written: a list of the cryptography you use, weak or outdated algorithms spotted and followed until they were fixed, and that record kept over months. ENISA's June 2025 implementation guidance gives exactly these kinds of records as examples of evidence.
Turning checks into a record
In the SkyQon Digital Trust Center we keep checking every domain and certificate you add, and we note each weak-algorithm problem on the day it appears and on the day it is gone. With the NIS2 Evidence Pack, that becomes a signed monthly report. Our NIS2 mapping counts it as direct evidence for 21(2)(h), for the services you expose to the internet.
NIS2 Evidence Pack pricing · Open a sample signed report (PDF) · Check a report's signature yourself
See what your domain offers today
You don't need an account. Type your domain and the result appears on screen.
The other measures
Article 21(2) has ten measures in total. Most of them are about how you work inside the company, and we can't see those from outside. Our longer guide goes through all ten and says which ones leave something visible.
- All ten measures: what counts as evidence
- 21(2)(d) Supply chain security: check a supplier from outside
- 21(2)(e) Maintenance and vulnerability handling
- 21(2)(f) Showing that your measures work
- 21(2)(g) Basic cyber hygiene
- A one-page NIS2 summary for your managing director
We explain the law here as plainly as we can, but this is not legal advice. NIS2 reaches you through your own country's law, and the details differ from one country to the next.