Skip to content

NQX Network Encryptor aligns with DORA requirements

EU-emblem

The Digital Operational Resilience Act (Regulation (EU) 2022/2554, "DORA") has applied to EU financial entities since 17 January 2025. It requires banks, insurers, investment firms, payment and crypto-asset service providers, market infrastructures and their critical ICT providers to protect the availability, authenticity, integrity and confidentiality of their data. This requirement explicitly applies to  data in transit.

The accompanying technical standards (Commission Delegated Regulation (EU) 2024/1774, the "RTS on ICT risk management") make encryption of data in transit, cryptographic key management and encryption of network connections concrete, auditable obligations. Uniquely among major regulations, they require financial entities to plan for updating cryptographic technology as cryptanalysis evolves.

SSH NQX is a high-performance, quantum-safe network encryptor that protects data in transit at the Ethernet (L2) and IP (L3) layers. This page maps NQX capabilities to the specific DORA and RTS articles they support, for use by risk, compliance and network security teams evaluating their DORA control coverage.

NQX meets DORA Article 9 requirements

DORA — Regulation (EU) 2022/2554
DORA requirement What it requires How NQX aligns with DORA 
Art. 9(2) — Protection and prevention Financial entities must design, procure and implement ICT security policies, procedures, protocols and tools that maintain high standards of availability, authenticity, integrity and confidentiality of data — whether at rest, in use or in transit. NQX encrypts Ethernet (Layer 2) and IP (Layer 3) traffic with strong symmetric cryptography (e.g. AES-256-GCM) and quantum-resilient key agreement, protecting the confidentiality and integrity of data in transit between sites, networks, clouds and data centers. It does so at wire speed up to 100 Gbps, so protection does not come at the cost of availability.
Art. 9(3)(a) — Security of data transfer Financial entities must use ICT solutions and processes that ensure the security of the means of transfer of data. NQX is purpose-built as a secure means of data transfer: transparent network-layer encryption wraps existing communications over any network, including untrusted or public infrastructure, leaving no trace on public servers or nodes. This includes legacy IT, OT/ICS and inter-organization flows that are hard or impossible to upgrade to be quantum-safe.  
Art. 9(4)(b) — Network and infrastructure management
Following a risk-based approach, entities must establish sound network and infrastructure management, and design the network connection infrastructure so it can be instantaneously severed or segmented to minimize and prevent contagion. NQX establishes discrete encrypted tunnels per connection with rule-based forwarding for granular flow management. Fail-safe emergency features can purge all connections immediately and disable an appliance, supporting instantaneous severance of links during an attack.
Art. 9(4)(d) — Strong authentication and cryptographic key protection Entities must implement policies and protocols for strong authentication mechanisms and protection measures for cryptographic keys, whereby data is encrypted based on approved data classification and ICT risk assessment.
NQX authenticates peers via X.509 certificates (PKI), PSK key lists and post-quantum pre-shared keys (PPK), with peer identity options (FQDN, IP, certificate). Built-in key management protects keys across their lifecycle; a crypto module lets the customer implement its own key settings, keeping key sovereignty with the entity.
Art. 7 — ICT systems, protocols and tools Entities must use ICT systems, protocols and tools that are appropriate, reliable, technologically resilient and equipped with sufficient capacity to handle peak activity. NQX is engineered for mission-critical capacity and resilience: up to 100 Gbps encrypted throughput, 0.4–0.6 ms average latency, DDoS resiliency up to 2 million flows/second without service impact, redundant deployment topologies and high-availability configurations.
Art. 10 — Detection Entities must have mechanisms to promptly detect anomalous activities and monitor ICT network performance.
NQX central management provides continuous node and tunnel health, status and event monitoring, giving operations and security teams the telemetry needed to detect anomalies on encrypted transport links and to evidence controls in audits.
Art. 12 — Backup, restoration and recovery Entities must have backup policies and recovery methods that ensure restoration of ICT systems with minimum downtime and disruption. Automatic NQX node backup, configuration revision management and predefined configurations enable rapid restoration of the encryption layer, keeping secure transport recoverable as part of the entity’s wider recovery plans.

NQX meets encryption, key management and network security chapters of the RTS requirements  

Commission Delegated Regulation (EU) 2024/1774, the "RTS on ICT risk management"
RTS requirement What it requires How NQX aligns with RTS 
RTS Art. 6(2) — Encryption policy: data in transit The encryption and cryptographic controls policy must provide for encryption of data at rest and in transit, and encryption of internal network connections and traffic with external parties, based on data classification and ICT risk assessment. NQX operationalizes the data-in-transit and network-connection encryption requirements. It offers transparent L2/L3 encryption of internal links (data center interconnects, site-to-site, campus/branch) and of traffic crossing external, public or third-party networks. The solution  does not require changes to applications or surrounding infrastructure.
RTS Art. 6(4) — Crypto-agility The policy must include provisions for updating or changing, where necessary, the cryptographic technology on the basis of developments in cryptanalysis. This is NQX’s core design principle. Quantum computing is the most significant foreseeable development in cryptanalysis: NQX already supports post-quantum key encapsulation (ML-KEM / FIPS 203, FrodoKEM) in hybrid mode alongside classical algorithms, and its software-based crypto engine adopts new or updated algorithms without hardware changes.
RTS Art. 6(3) — Selection of cryptographic techniques Where encryption is applied, entities must select cryptographic techniques considering leading practices and recognized standards. NQX builds on recognized standards: IPsec/IKEv2, X.509 PKI, NIST P-521 and DH groups for classical exchange, and NIST-standardized ML-KEM (FIPS 203) for post-quantum key encapsulation. NQX cryptography is NCSA-FI certified for national Confidential-level use.
RTS Art. 7(1)–(3) — Cryptographic key lifecycle Keys must be managed through their whole lifecycle (generation, renewal, storage, backup, retirement, revocation, destruction), protected against loss, unauthorized access and modification, and replaceable if compromised. Built-in key management automates generation, rotation and renewal of keys across all tunnels, maintaining forward security with uninterrupted service. Automated renewal and replacement mechanisms remove reliance on manual key handling which is a common audit finding.
RTS Art. 7(4)–(5) — Certificate register and renewal Entities must maintain an up-to-date register of certificates and certificate-storing devices for ICT assets supporting critical or important functions, and renew certificates before expiry. NQX central management provides lifecycle management of node certificates, PSK-ID management for tunnels, and inventory management of nodes, configurations and software releases . This gives compliance teams a maintained register of the encryption estate.
RTS Art. 12 — Logging Entities must log relevant events to support detection, investigation and audit. NQX nodes and tunnels produce health, status and event data designed to support operations, troubleshooting and audit requirements, available through the central management interface.
RTS Art. 13(a), (j) — Segmentation and isolation Network security policy must cover segregation and segmentation of ICT systems and networks, and the ability to temporarily isolate subnetworks and network components. Discrete encrypted tunnels cryptographically segment traffic between sites and enclaves. Rule-based forwarding provides granular flow control. Fail-safe emergency purge instantly isolates links or disables an appliance.
RTS Art. 13(c) — Secure administration Network security policy must cover the use of a separate and dedicated network for the administration of ICT assets. NQX management supports console, LAN and inband management channels. Inband management itself uses quantum-resilient authentication keys, and administration is governed by role- and domain-based user policies.
RTS Art. 13(e) — Encryption of network connections Network connections passing over corporate networks, public networks, domestic networks, third-party networks and wireless networks must be encrypted, based on data classification and ICT risk assessment. This is NQX’s primary function: encrypting network connections across any transport (corporate backbones, public internet, carrier and third-party networks) with quantum-resilient cryptography, at line rate, for both Ethernet and IP traffic.
RTS Art. 13(k) — Secure configuration baseline Entities must implement a secure configuration baseline of network components and harden them against unauthorized changes. Pre-configured nodes, deployment wizards and predefined configurations enforce a consistent baseline whrere configuration revision management tracks changes, Secure Boot verifies firmware and software integrity, and Remote Attestation secures and controls the appliance lifecycle.
RTS Art. 14 — Securing information in transit Entities must ensure the availability, authenticity, integrity and confidentiality of data during network transmission, and the secure transfer of information with external parties. NQX provides authenticated, integrity-protected, confidential transport: peers are mutually authenticated (certificates, PSK, PPK), payloads are protected with authenticated encryption (AES-256-GCM), and resilience features (HA, DDoS resiliency, automated key renewal) keep protected links available.

More NQX Network Encryptor resources

NQX Datasheet

NQX Datasheet

Quantum-Safe Journey: How to Migrate to Post- Quantum Cryptography (PQC)

Quantum-Safe Journey: How to Migrate to Post- Quantum Cryptography (PQC)

Verne Secures High-Bandwidth Data Center Connections for Managed Customers with Post-Quantum Cryptography (PQC)

Verne Secures High-Bandwidth Data Center Connections for Managed Customers with Post-Quantum Cryptography (PQC)

Learn more about future-proofing your data in transit.