Skip to content

NQX network encryption fulfills NIS2 requirements

EU-emblem

The NIS2 Directive (Directive (EU) 2022/2555, "NIS2") is the EU's common cybersecurity law for essential and important entities across 18 sectors, including energy, transport, banking, health, drinking water, digital infrastructure, ICT service management, manufacturing and public administration. Member States were required to transpose it into national law by 17 October 2024. Article 21 requires in-scope entities to take appropriate and proportionate technical, operational and organizational measures to manage the risks to their network and information systems, taking into account the state of the art. Policies and procedures on the use of cryptography and, where appropriate, encryption are explicitly listed among the minimum measures.

The accompanying Commission Implementing Regulation (EU) 2024/2690 sets out the technical and methodological requirements of these measures for digital infrastructure and digital service providers, such as cloud, data center, managed service and managed security service providers. It makes encryption of data in transit, cryptographic key management, network security and network segmentation concrete, auditable requirements, and it calls for a cryptographic agility approach with policies reviewed against the state of the art in cryptography. Its requirements also serve as a practical reference point for other NIS2 entities building their control frameworks.

SSH NQX is a high-performance, quantum-safe network encryptor that protects data in transit at the Ethernet (L2) and IP (L3) layers. This page maps NQX capabilities to the specific NIS2 and Implementing Regulation requirements they support, for use by risk, compliance and network security teams evaluating their NIS2 control coverage.

NQX meets NIS2 Article 21 requirements

NIS2 — Directive (EU) 2022/2555
NIS2 requirement What it requires How NQX aligns with NIS2
Art. 21(1) — Cybersecurity risk-management measures Entities must take appropriate and proportionate technical, operational and organizational measures to manage risks to the security of their network and information systems, taking into account the state of the art. NQX encrypts Ethernet (Layer 2) and IP (Layer 3) traffic with strong symmetric cryptography (e.g. AES-256-GCM) and quantum-resilient key agreement, protecting the confidentiality and integrity of data in transit between sites, networks, clouds and data centers. Hybrid post-quantum key exchange addresses "harvest now, decrypt later" risk, which is part of today's state of the art, and it runs at wire speed up to 100 Gbps.
Art. 21(2)(h) — Cryptography and encryption Entities must have policies and procedures regarding the use of cryptography and, where appropriate, encryption. NQX puts the data-in-transit part of the encryption policy into practice: transparent L2/L3 encryption of internal links and of traffic crossing public, carrier or third-party networks, without changes to applications or surrounding infrastructure. This includes legacy IT, OT/ICS and inter-organization flows that are hard or impossible to upgrade to be quantum-safe.
Art. 21(2)(c) — Business continuity Entities must ensure business continuity, such as backup management, disaster recovery and crisis management. Redundant deployment topologies, high-availability configurations and DDoS resiliency up to 2 million flows/second keep encrypted links available. Automatic node backup, configuration revision management and predefined configurations enable rapid restoration of the encryption layer as part of wider recovery plans.
Art. 21(2)(b) — Incident handling Entities must have measures in place to handle incidents. Central management provides continuous node and tunnel health, status and event monitoring for detecting anomalies on encrypted transport links. Fail-safe emergency features can purge all connections immediately and disable an appliance, supporting fast containment during an attack.
Art. 21(2)(d) — Supply chain security Entities must address security in their relationships with direct suppliers and service providers. Because NQX encrypts traffic end to end across carrier, cloud and third-party networks, the confidentiality and integrity of data in transit do not depend on the security of the network provider. A crypto module lets the customer implement its own key settings, keeping key sovereignty with the entity. NQX cryptography is NCSA-FI certified for national Confidential-level use.
Art. 21(2)(e) — Security in acquisition, development and maintenance Entities must ensure security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure. Secure Boot verifies firmware and software integrity, Remote Attestation secures and controls the appliance lifecycle, and central inventory management of software releases keeps the encryption estate maintained and up to date.
Art. 21(2)(i) — Access control and asset management Entities must have human resources security, access control policies and asset management in place. Administration of NQX is governed by role- and domain-based user policies. Central management maintains an inventory of nodes, configurations, certificates and software releases.
Art. 21(2)(j) — Authentication and secured communications Entities must use, where appropriate, multi-factor or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems. NQX mutually authenticates network peers via X.509 certificates (PKI), PSK key lists and post-quantum pre-shared keys (PPK). The encrypted transport protects the voice, video, text and emergency communication traffic carried over it, including between sites and control centers.
Art. 23 — Reporting obligations Entities must notify significant incidents to the CSIRT or competent authority, with an early warning within 24 hours and an incident notification within 72 hours. NQX node and tunnel health, status and event data, available through the central management interface, helps teams establish quickly whether encrypted transport links were affected and supports the evidence needed for incident reports.
 

NQX meets the cryptography, network security and continuity requirements of the Implementing Regulation

Commission Implementing Regulation (EU) 2024/2690
Implementing Regulation requirement What it requires How NQX aligns with the Implementing Regulation
Annex 9.1, 9.2(a) — Cryptography policy: data in transit Entities must establish and apply a cryptography policy that sets out, in line with asset classification, the type, strength and quality of cryptographic measures required to protect assets, including data at rest and data in transit. NQX delivers the data-in-transit measures: transparent L2/L3 encryption of internal links (data center interconnects, site-to-site, campus/branch) and of traffic crossing external, public or third-party networks, with no changes to applications or surrounding infrastructure.
Annex 9.2(b) — Protocols, algorithms and cryptographic agility The policy must define the protocols, algorithms, cipher strength and cryptographic solutions approved for use, following, where appropriate, a cryptographic agility approach. NQX builds on recognized standards: IPsec/IKEv2, X.509 PKI, NIST P-521 and DH groups for classical exchange, and NIST-standardized ML-KEM (FIPS 203) and FrodoKEM for post-quantum key encapsulation in hybrid mode. Its software-based crypto engine adopts new or updated algorithms without hardware changes.
Annex 9.2(c) — Key management The policy must set out the approach to key management, including generating, distributing, storing, changing and revoking keys, issuing certificates, dealing with compromised keys, and logging key management activities. Built-in key management automates generation, rotation and renewal of keys across all tunnels, maintaining forward security with uninterrupted service. Central management covers node certificate lifecycle and PSK-ID management. Automated renewal and replacement mechanisms remove reliance on manual key handling, which is a common audit finding.
Annex 9.3 — Review against the state of the art Entities must review and, where appropriate, update their cryptography policy at planned intervals, taking into account the state of the art in cryptography. This is NQX's core design principle. Quantum computing is the most significant foreseeable change in the cryptographic state of the art: NQX already supports post-quantum key encapsulation alongside classical algorithms, so policy updates can be implemented through software rather than hardware replacement.
Annex 6.7 — Network security Entities must protect their network and information systems, including by establishing communication between distinct systems only through trusted channels that are isolated by logical, cryptographic or physical separation, with assured identification of end points and protection of channel data from modification or disclosure. This is NQX's primary function. Each connection is a cryptographically separated channel whose peers are mutually authenticated (certificates, PSK, PPK) and whose payloads are protected with authenticated encryption (AES-256-GCM), across corporate backbones, the public internet, and carrier and third-party networks.
Annex 6.8 — Network segmentation Entities must segment systems into networks or zones in line with their risk assessment and separate systems according to their criticality. Discrete encrypted tunnels cryptographically segment traffic between sites and enclaves. Rule-based forwarding provides granular flow control. Fail-safe emergency purge instantly isolates links or disables an appliance.
Annex 6.3 — Configuration management Entities must establish, document, implement and monitor configurations, including security configurations of hardware, software, services and networks. Pre-configured nodes, deployment wizards and predefined configurations enforce a consistent baseline, while configuration revision management tracks changes. Secure Boot verifies firmware and software integrity, and Remote Attestation secures and controls the appliance lifecycle.
Annex 11.4 — Administration systems Entities must restrict and control the use of system administration systems and the channels used to manage network and information systems. NQX management supports console, LAN and inband management channels. Inband management itself uses quantum-resilient authentication keys, and administration is governed by role- and domain-based user policies.
Annex 3.2 — Monitoring and logging Entities must monitor and log activities on their network and information systems to detect events that could be considered incidents. NQX nodes and tunnels produce health, status and event data designed to support operations, troubleshooting and audit requirements, available through the central management interface.
Annex 4.2 — Backup and redundancy management Entities must maintain backup copies of data and ensure sufficient available resources through redundancy of network and information systems. Automatic NQX node backup and configuration revision management keep the encryption layer recoverable, while redundant deployment topologies and high-availability configurations keep protected links available.
Annex 12.4 — Asset inventory Entities must maintain a complete, accurate and up-to-date inventory of their assets. NQX central management provides inventory management of nodes, configurations, certificates and software releases, giving compliance teams a maintained register of the encryption estate.

Learn more about future-proofing data in transit quantum safely.