Policy Register

Cryptography policy

Where encryption is required, which algorithms and key lengths are allowed, and how keys are managed through their life.

How the register reads it

Also calledencryption policy, cryptographic controls
FamilyOperations and technology
Document typePolicy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerThe information security lead (CISO or ISMS manager).
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenISO 27001 or NIS2 is ticked and no line resolves to it (ISO 27701, DORA require it too, inside a parent document, so they do not list it separately).
TemplateEncryption policy.

Which standards require it, and what each expects it to contain

4 requiring clauses, 4 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27001:2022

ISO 27001 8.24 Use of cryptography

Define and implement rules for effective use of cryptography and key management.

What the ISO 27002 guidance expects the document to say: Requires defined and implemented rules on using cryptography effectively, including how cryptographic keys are managed.

Evidence an auditor accepts: The cryptography rules, defining approved algorithms, key lengths and protocols, and where cryptography must be used; evidence of implementation, sampled across data at rest, data in transit and any application layer encryption; the key management procedures covering generation, distribution, storage, rotation, revocation, archival and destruction
Common gap: Missing documented key lifecycle
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

ISO/IEC 27701:2025

ISO 27701 A.3.26 Use of cryptography

The organization's rules on the use of cryptography shall recognise that some jurisdictions require cryptography to protect particular kinds of PII, such as health data, resident registration numbers, passport numbers and driver's licence numbers, and the organization shall provide information to the customer about the circumstances in which it uses cryptography to protect the PII it processes and about any capabilities it provides that can help the customer apply their own cryptographic protection.

Evidence an auditor accepts: Cryptography rules identifying the PII types that jurisdictions require to be encrypted; customer-facing information on where cryptography is applied to PII and the capabilities offered; evidence of encryption of the identified PII types at rest and in transit
Common gap: Special categories stored in clear because the rule addressed only data in transit
Source: ISO/IEC 27701:2025

DORA (Regulation (EU) 2022/2554)

DORA Art. 9 Protection and prevention

Financial entities shall continuously monitor and control the security and functioning of ICT systems and tools, and minimise ICT risk through appropriate ICT security policies, procedures, protocols and tools ensuring resilience, continuity and availability, and preserving confidentiality, integrity and authenticity of data (incl access management, encryption, secure configuration, network security).

Evidence an auditor accepts: ICT security policies and protective controls (access, encryption, configuration, network); evidence preserving CIA of data
Common gap: Weak or absent protective controls
Source: DORA (Regulation (EU) 2022/2554)

The NIS2 Directive

NIS2 Art. 21(2)(h) Policies and procedures on the use of cryptography and, where appropriate, encryption

The obligation is to have decided, in writing, where cryptography is used and how it is governed. That covers which algorithms and key lengths are permitted, where data is encrypted at rest and in transit, how certificates and keys are generated, stored, rotated and revoked, and who may access key material. Encryption is qualified by where appropriate, which means the entity is expected to reach a reasoned position rather than encrypt everything or nothing. Key management is where this obligation usually fails in practice, because encryption can be deployed correctly while the keys sit somewhere that removes the protection. Expired certificates and forgotten key owners are also the common route by which an availability incident starts.

Evidence an auditor accepts: The cryptographic policy, naming approved algorithms, key lengths and permitted use; the reasoning for where encryption is and is not applied, at rest and in transit; key and certificate lifecycle procedures covering generation, storage, rotation and revocation
Common gap: Encryption deployed while key custody and rotation are undocumented
Source: NIS2 Directive

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Container and orchestration security standard · Database security standard