NIS2 - Cybersecurity Risk-Management Cryptography (Post-Quantum)
Description
PQC-scoped view of the EU NIS2 Directive (Directive (EU) 2022/2555). Article 21(2)(h) requires policies and procedures on the use of cryptography and encryption — implying a cryptographic inventory. NIS2 sets no post-quantum deadline, so quantum-vulnerable cryptography is surfaced as advisory migration debt.
Rationale
NIS2 makes cryptography and encryption policies a risk-management requirement for essential and important entities, without naming a PQC timeline. Modelling the inventory obligation as hard and the post-quantum exposure as advisory stays faithful to the directive.
Benefits
Entities in NIS2 scope get an inventory-backed view of post-quantum exposure aligned with their cryptography-policy obligations without overstating a deadline the directive does not set.
NIS2 — Cryptographic Inventory Maintained
ID |
nis2_pqc/crypto_inventory_established |
Severity |
high |
Category |
cryptography/post_quantum |
Optional |
false |
Tags |
crypto, inventory, nis2, pqc |
Description
Checks that a cryptographic inventory (a CBOM) is maintained for the project, supporting the NIS2 Article 21(2)(h) cryptography and encryption policy obligation.
Rationale
NIS2 requires policies on the use of cryptography and encryption; a cryptographic inventory is the prerequisite for such a policy and for any post-quantum planning.
NIS2 — Quantum-Vulnerable Cryptography (Advisory)
ID |
nis2_pqc/no_quantum_vulnerable_crypto |
Severity |
info |
Category |
cryptography/post_quantum |
Optional |
true |
Tags |
crypto, nis2, pqc, quantum |
Description
Surfaces quantum-vulnerable (Shor-broken) public-key cryptography in the project’s inventory as advisory migration debt. NIS2 sets no post-quantum deadline, so this control never fails — it reports a partial result while such algorithms are present.
Rationale
NIS2 requires cryptography and encryption policies but states no PQC timeline. Reporting the exposure without a fabricated deadline keeps the assessment honest while flagging the migration as part of cybersecurity risk management.