For most companies, sensitive information lives in email and files: contracts, offers, prices, data about clients and suppliers. NIS2 requires it to be protected by encryption. All the major suites encrypt data. What makes the difference is who holds the keys.

What NIS2 requires on encryption

Article 13 of OUG 155/2024 sets the minimum risk-management measures for essential and important entities. Three of them concern data and communication protection directly:

DNSC Order No. 1/2026 breaks the measures down into controls, by assurance level. At the self-assessment, each control is scored separately for documentation and for implementation. For encryption, that means two things: a written policy and a technology that applies it every day.

Stored data: who can read the content

With Proton Workspace, email, files in Drive, documents in Docs and Sheets, calendar events and passwords in Pass are stored with zero-access encryption. The data is encrypted with the user’s keys, and Proton cannot read the content.

The same applies to email received from addresses outside Proton: it is encrypted on arrival, before it is stored. If someone stole data from Proton’s servers, they would only get encrypted data.

Data in transit and internet traffic

Messages between Proton users are end-to-end encrypted, from the sender’s device to the recipient. To addresses outside Proton, messages travel encrypted with TLS, as with most providers. For sensitive information, you send a password-protected message with an expiry date, or use PGP.

Proton VPN, included in the subscription, encrypts the connection between the device and the VPN server. It protects employees working on public Wi-Fi, in a hotel or an airport, and its NetShield feature blocks domains known for malware. Access to the company’s internal network remains an architecture decision, made separately.

Encryption keys

Private keys are protected by the users’ passwords, so Proton has no access to them. The keys stay under the company’s control: you can generate, import or export them, including existing OpenPGP keys.

For NIS2, the procedure matters too: who creates the keys, how you recover them when an employee leaves and when you replace them. The technology comes with the subscription. The company writes the procedure.

Authentication: a password is no longer enough

The Proton Workspace administrator can enforce two-factor authentication for all users. The second factor can be an authenticator app or a FIDO2 physical security key. With a physical key, an attacker who learns your password still cannot get into the account without the key in your pocket.

Passwords and secrets: Proton Pass

Proton Pass keeps passwords, 2FA codes and other secrets in encrypted vaults. The team shares only the vaults it needs. When an employee leaves, you remove their access to the company vaults, without changing passwords one by one in every system.

What Proton Workspace covers, requirement by requirement

Requirement in OUG 155/2024, art. 13What Proton Workspace coversWhat the company sets
Encrypting stored data, letter c)Email, files, documents, calendar and passwords are stored with zero-access encryption. Not even Proton can read the content. Email received from outside Proton is encrypted on arrival.The encryption policy and which data goes into each service.
Encrypting data in transit, letters c) and j)Messages between Proton users are end-to-end encrypted. To recipients outside Proton, you send password-protected or PGP messages.The rule for information sent outside the company.
Internet traffic, letter c)Proton VPN, included in the subscription, encrypts the connection between the device and the VPN server, including on public Wi-Fi, and blocks malicious domains.When a VPN connection is mandatory.
Encryption keys, letter c)Private keys stay under the company’s control: they are protected by the users’ passwords and Proton has no access to them. You can generate, import or export them.The procedure for the key lifecycle: generation, replacement, recovery.
Multi-factor authentication, letter j)The administrator enforces 2FA for all users, with an authenticator app or a FIDO2 physical security key.The authentication rule and a record of physical keys.
Access control, letter f)Proton Pass keeps passwords, 2FA codes and other secrets in encrypted vaults, shared only with those who need them.Who has access to what and how access is removed when an employee leaves.

Who holds the keys: Proton, Microsoft and Google

At Proton, zero-access encryption is standard for all data, unlike the big-tech suites. At Microsoft 365 and Google Workspace, data is encrypted, but the provider holds the keys. Your own keys require the top-tier plans.

Proton WorkspaceMicrosoft 365Google Workspace
Stored data is encryptedYes, zero-accessYesYes
Who holds the keys in the regular plansThe companyMicrosoftGoogle
Customer-held keysStandard, for all dataDouble Key Encryption and Customer Key, with Microsoft 365 E5 or Microsoft Purview add-onsClient-side encryption, in Enterprise Plus, Frontline Plus and Education

Microsoft recommends Double Key Encryption only for the most sensitive data, around 5% of an organisation’s data. With Proton Workspace, zero-access encryption applies to all data in the included services, from day one.

Sources, checked on 7 October 2026: Microsoft, encryption at rest · Microsoft, Double Key Encryption · Microsoft, Purview licensing · Google Workspace, encryption · Google, client-side encryption · Proton, encryption keys.

What the company still has to do

Proton Workspace covers the technology for encryption, authentication and access control. NIS2 compliance also requires the other measures in art. 13, from risk analysis to incident handling, which the auditor checks.

How TRU helps

Proton’s official website presents TRU Solutions as “Exclusive Proton Partner in Romania”. We help you choose the subscription, migrate the data and configure Proton Workspace, including 2FA, sharing and the rules for external email.

Through CIO-as-a-Service, we prepare the encryption policy and the evidence for the self-assessment. Audits are performed by DNSC-certified auditors who are TRU partners. The details are on the NIS2 audit and compliance page.

Sources

OUG 155/2024, consolidated version, art. 13 (in Romanian) · DNSC Order No. 1/2026 (in Romanian) · Proton, encryption in Proton Mail · Proton, encryption keys · Proton, enforcing 2FA in an organisation · Proton, business subscriptions.