NIS2Art. 21(2)(h)voice-validated

NIS2 Art21h: Art. 21(2)(h)

Network and Information Security Directive 2 (EU 2022/2555)

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Essential and important entities must implement policies and procedures regarding the use of cryptography and, where appropriate, encryption. This includes key management, cryptographic algorithm selection, transport and storage encryption, and protection of cryptographic material throughout its lifecycle.

ATT&CK techniques this article tests · 15

TechniqueWhy it mapsConfidence
T10031. Weak key management or inadequate protection of cryptographic material (Art. 21(2)(h)) allows attackers to dump credentials from systems, bypassing security measures.
90%
T1003.0011. Inadequate protection of cryptographic material (Art. 21(2)(h)) can expose memory containing credentials, enabling LSASS dumping by adversaries.
80%
T1003.0021. Poor cryptographic protection of the Security Account Manager (SAM) database (Art. 21(2)(h)) allows attackers to extract hashed credentials.
80%
T10051. Lack of storage encryption (Art. 21(2)(h)) allows attackers to collect sensitive data directly from local systems without cryptographic barriers.
90%
T10121. Insecure storage of cryptographic material or keys in the registry (Art. 21(2)(h)) can be discovered and exploited by attackers querying the registry.
70%
T10211. Inadequate transport encryption (Art. 21(2)(h)) for remote services exposes communication to interception and compromise, facilitating unauthorized access.
80%
T10271. Attackers may use encryption to obfuscate malicious files or C2 traffic; robust cryptographic policies (Art. 21(2)(h)) can help detect or prevent such misuse.
70%
T10401. Absence of robust transport encryption (Art. 21(2)(h)) allows attackers to sniff network traffic and capture sensitive data in cleartext.
90%
T10411. Weak or absent transport encryption (Art. 21(2)(h)) on C2 channels facilitates interception of exfiltrated data, compromising confidentiality.
80%
T10481. Lack of storage or transport encryption (Art. 21(2)(h)) makes exfiltrated data vulnerable to interception and compromise regardless of the protocol used.
80%
T10561. Inadequate protection of cryptographic material (Art. 21(2)(h)) can lead to compromise of input capture mechanisms or the data they collect.
70%
T1071.0011. Failure to enforce strong cryptographic algorithm selection and transport encryption (Art. 21(2)(h)) for application layer protocols exposes C2 communications.
80%
T10781. Weak cryptographic protection of authentication material (Art. 21(2)(h)) can lead to compromise and misuse of valid accounts by adversaries.
80%
T10831. Lack of storage encryption for sensitive files (Art. 21(2)(h)) increases the impact of file and directory discovery, exposing confidential information.
80%
T11141. Inadequate transport and storage encryption for email (Art. 21(2)(h)) allows attackers to collect sensitive communications without cryptographic protection.
70%

Defending mitigations · 7

MitigationWhat it doesConfidence
M10131. Implementing encryption for data at rest and in transit directly addresses the requirements for transport and storage encryption (Art. 21(2)(h)).
95%
M10151. Multi-factor authentication mechanisms often rely on strong cryptographic principles for secure token generation and exchange, protecting valid accounts as per Art. 21(2)(h).
85%
M10171. Secure key management and protection of cryptographic material (Art. 21(2)(h)) are integral to robust user account management, preventing credential compromise.
80%
M10261. Strict privileged account management protects access to cryptographic material and key management systems, as required by Art. 21(2)(h).
90%
M10351. Limiting access to cryptographic material and key management infrastructure is a fundamental aspect of protecting cryptographic material throughout its lifecycle (Art. 21(2)(h)).
90%
M10401. Data Loss Prevention solutions can detect and prevent unauthorized exfiltration of sensitive data, especially if it bypasses or lacks the required encryption (Art. 21(2)(h)).
80%
M10471. Defense in depth strategies, including cryptographic controls, enhance overall security posture, ensuring protection of cryptographic material (Art. 21(2)(h)).
85%

Underlying weaknesses · 6

CWEWhy it persistsConfidence
CWE-3261. Selection of weak cryptographic algorithms or insufficient key lengths directly violates the requirement for cryptographic algorithm selection (Art. 21(2)(h)).
95%
CWE-3271. Employing known broken or risky cryptographic algorithms undermines the security objectives of Art. 21(2)(h) regarding algorithm selection.
95%
CWE-3111. Failure to encrypt sensitive data during transport or storage directly contravenes the requirements for encryption (Art. 21(2)(h)).
90%
CWE-3121. Storing sensitive information, including cryptographic material, in cleartext violates the control's mandate for storage encryption and protection (Art. 21(2)(h)).
90%
CWE-3191. Transmitting sensitive information without encryption directly violates the requirement for transport encryption (Art. 21(2)(h)).
90%
CWE-3301. Insufficiently random values used in cryptographic operations, especially key generation, weaken the overall cryptographic strength required by Art. 21(2)(h).
80%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0188 compute · voice-rubric self-validated · 1 hallucination(s) dropped at validation