DORA's Cryptography Rules: What Articles 6 And 7 Of RTS 2024/1774 Ask For
The DORA technical standards on ICT risk require an encryption policy, full key lifecycle management and a certificate register. Here is what each paragraph asks for and the evidence that supports it.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
The EU’s Digital Operational Resilience Act (DORA) has applied to banks, insurers, investment firms, payment institutions and many other financial entities since 17 January 2025.1 DORA itself sets out principles. The detail sits in technical standards, and one of them, Commission Delegated Regulation (EU) 2024/1774, contains two articles devoted to cryptography.2
This article walks through Articles 6 and 7 of that regulation paragraph by paragraph. It explains what each one asks for, what evidence tends to support it, and how the text relates to quantum computing. The articles themselves never name it, although recital 9 recognises quantum developments as a source of cryptographic risk and asks financial entities to manage such threats through monitoring and mitigation.3
Where These Rules Come From
The Delegated Regulation is a regulatory technical standard, often shortened to RTS, that specifies the tools, methods and policies DORA expects for managing ICT (information and communication technology) risk. It was adopted on 13 March 2024, published in the Official Journal on 25 June 2024 and entered into force on 15 July 2024. Its rules apply to financial entities through DORA, which has applied since 17 January 2025.21 Because it is a regulation, it applies directly in every Member State without national transposition.
Articles 6 and 7 sit in Title II, which covers financial entities subject to DORA’s full ICT risk management framework. Smaller entities listed in Article 16 of DORA, such as small and non-interconnected investment firms and some exempted payment and e-money institutions, follow a simplified framework instead.1 That simplified framework, in Title III of the same regulation, has no equivalent article on cryptography, although cryptography still feeds into the general proportionality rule in Article 1.2
Article 6: The Encryption Policy
Article 6 requires financial entities to develop, document and implement a policy on encryption and cryptographic controls, as part of their wider ICT security policies.2
The policy must be built on an approved data classification and ICT risk assessment. It needs rules for encrypting data at rest and in transit, for encrypting data in use where necessary, for encrypting internal network connections and traffic with external parties, and for managing cryptographic keys (paragraph 2). Where data in use cannot be encrypted, it has to be processed in a separated and protected environment or given equivalent protection.
Paragraph 3 asks for criteria for choosing cryptographic techniques, based on leading practices, recognised standards and the classification of the assets involved. If an entity cannot follow leading practices or standards, it must adopt mitigation and monitoring measures.
Paragraph 4 is the one that matters most for quantum readiness. The policy must allow cryptographic technology to be updated or changed where necessary “on the basis of developments in cryptanalysis”.2 Cryptanalysis is the study of how to break cryptography. If updating is not possible, the entity must again adopt mitigation and monitoring measures that keep it resilient.
Paragraph 5 closes the loop. Whenever mitigation and monitoring measures are used under paragraphs 3 or 4, the entity must record them and give a reasoned explanation for the choice.
Article 7: Key Management And The Certificate Register
Article 7 deals with cryptographic keys and certificates.2
- Paragraph 1: key management requirements must cover the whole lifecycle, from generation, renewal, storage, backup and archiving through retrieval, transmission, retirement, revocation and destruction.
- Paragraph 2: keys must be protected throughout that lifecycle against loss, unauthorised access, disclosure and modification, with controls based on data classification and risk assessment.
- Paragraph 3: there must be methods to replace keys that are lost, compromised or damaged.
- Paragraph 4: the entity must create and maintain a register of all certificates and certificate-storing devices, at least for ICT assets supporting critical or important functions, and keep it up to date.
- Paragraph 5: certificates must be renewed promptly, before they expire.
Mapping Each Paragraph To Evidence
Supervisors and internal auditors will look for documents and records that show each paragraph is met. The table below is a practical guide.
| Paragraph | What It Asks For | Evidence That Typically Supports It |
|---|---|---|
| Art. 6(1) | A documented and implemented encryption policy | Approved policy document, with owner, version and approval record |
| Art. 6(2) | Rules for data at rest, in transit, in use, network traffic and key management, based on data classification | Policy sections for each area, linked to the data classification scheme and risk assessment |
| Art. 6(3) | Criteria for selecting cryptographic techniques | Approved algorithm and protocol list, with the standards it follows and a record of exceptions |
| Art. 6(4) | Ability to update cryptography as cryptanalysis develops | Monitoring process, change procedure, and knowledge of where each algorithm is used |
| Art. 6(5) | Record of mitigations with reasons | Exception or risk register entries with compensating controls and a written justification |
| Art. 7(1) to 7(3) | Full key lifecycle, protection and replacement | Key management procedure, records from hardware security modules (HSMs, tamper-resistant devices that generate, store and use keys) or other key stores, and a tested key replacement process |
| Art. 7(4) | Up-to-date certificate register for at least critical or important functions | A certificate and certificate-storing device register with evidence of regular updates |
| Art. 7(5) | Prompt renewal before expiry | Expiry monitoring, alerts and renewal records |
What This Means For Quantum Readiness
Neither article names quantum computing. In the author’s reading, though, a quantum computer able to break RSA and elliptic curve cryptography would be exactly the kind of development in cryptanalysis that paragraph 4 anticipates. EU guidance points the same way: the NIS Cooperation Group’s April 2026 FAQ on the EU post-quantum roadmap describes post-quantum cryptography as crucial for protecting financial systems under DORA.4 That FAQ is guidance and does not change the legal text.
Two practical consequences follow. First, you cannot update cryptography as cryptanalysis develops unless you know where each algorithm is used. Article 7(4) only requires a certificate register, but meeting Article 6(4) in practice depends on a wider view of algorithms, protocols and keys. Second, if some systems cannot be migrated in time, paragraph 5 means the decision and its reasons must be written down.
- In effect
European Union · European Commission Binding
Encryption policy, key lifecycle and certificate register rules apply through DORA from this date: the policy must provide for updating cryptography based on developments in cryptanalysis, and a register of certificates and certificate-storing devices must be kept up to date, at least for ICT assets supporting critical or important functions. The RTS itself entered into force on 15 July 2024.
Footnotes
-
European Parliament and Council, “Regulation (EU) 2022/2554 on digital operational resilience for the financial sector”, Articles 16 and 64, 14 December 2022. eur-lex.europa.eu ↩ ↩2 ↩3
-
European Commission, “Commission Delegated Regulation (EU) 2024/1774”, Articles 1, 6 and 7, 13 March 2024. eur-lex.europa.eu ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
European Commission, “Commission Delegated Regulation (EU) 2024/1774”, recital 9, 13 March 2024. eur-lex.europa.eu ↩
-
NIS Cooperation Group, “EU Roadmap on PQC: Frequently Asked Questions”, section 6.2, 15 April 2026. ec.europa.eu ↩
-
European Parliament and Council, “Directive (EU) 2022/2555 (NIS2 Directive)”, Article 4 and recital 28, 14 December 2022. eur-lex.europa.eu ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.