Cryptographic Compliance — NIS2, DORA & EU Frameworks
NIS2 (Network and Information Security Directive 2) and DORA (Digital Operational Resilience Act) require organisations to demonstrate cryptographic governance — knowing what cryptography they use, whether it's secure, and having a plan to replace vulnerable algorithms. QROS provides the evidence base for cryptographic compliance by mapping your entire public cryptographic exposure.
NIS2 cryptographic requirements
NIS2 Article 21 requires "state-of-the-art" cryptographic practices for essential and important entities. This means:
- Inventory of cryptographic assets (certificates, keys, algorithms)
- Assessment of cryptographic risks (weak algorithms, short keys, expired certs)
- Plan for migration to stronger cryptography (including PQC)
- Regular testing and updating of cryptographic controls
QROS automates this by scanning every public host and producing a live cryptographic exposure map that serves as NIS2 audit evidence.
DORA cryptographic inventory
DORA Article 9 requires financial entities to maintain an ICT asset inventory — including cryptographic assets. QROS discovers and inventories:
- TLS certificates (issuer, expiry, algorithm, key length, domains)
- SSH keys and algorithms
- Web technology stacks with cryptographic dependencies
- Quantum-vulnerable assets (RSA, ECC) with risk scores
For each asset, QROS produces a risk score and remediation advice — the evidence DORA auditors expect.
Digital operational resilience and cryptography
Digital operational resilience depends on cryptographic resilience. If your encryption fails — whether through a quantum attack, a broken algorithm, or an expired certificate — your operational resilience fails with it. QROS maps the cryptographic dependencies that underpin your operational resilience and flags the weakest links before they break.
How QROS supports cryptographic compliance
QROS provides:
- Cryptographic inventory — always-up-to-date, automatically discovered from your public surface
- Risk assessment — per-asset quantum and classical risk scores with CVSS-mapped CVEs
- Audit evidence — exportable reports for NIS2/DORA auditors showing what crypto you have, its risk level, and your migration plan
- PQC roadmap — prioritised plan for migrating to post-quantum cryptography, aligned with NIST PQC standards
FAQ
Does NIS2 require a cryptographic inventory?
Yes. NIS2 Article 21 requires essential and important entities to implement state-of-the-art cryptographic practices, which includes maintaining an inventory of cryptographic assets and assessing their risk.
What does DORA require for cryptographic governance?
DORA Article 9 requires financial entities to maintain an ICT asset inventory that includes cryptographic assets. QROS discovers TLS certificates, SSH keys and web technology stacks from your public surface.
What is digital operational resilience?
Digital operational resilience is the ability of an organisation to withstand, respond to, and recover from ICT-related disruptions. Cryptographic resilience is a key component — if your encryption fails, your operational resilience fails with it.
Start your cryptographic risk assessment with QROS
Explore now →