Annex I · Objective 01

Manage

Managing sets out the cross-cutting governance conditions guiding the other NH objectivesRCS.

Complete structure

Categories and controls.

Select each category to see all the codes and titles that make up it.

GR.COOrganizational context6 checks
  1. GR.CO-1

    The mission, vision, risk management strategy and objectives of the entity shall be defined and communicated.

  2. GR.CO-2

    The needs and expectations of internal and external stakeholders are understood and reflected in the management of cybersecurity risks.

  3. GR.CO-3

    Legal, regulatory and contractual requirements for cybersecurity are understood and managed.

  4. GR.CO-4

    The critical services of the entity on which external stakeholders depend are identified and reported.

  5. GR.CO-5

    The resilience requirements necessary to support the provision of critical services are defined.

  6. GR.CO-6

    The external services on which the entity depends are identified and reported.

GR.GRRisk Management Strategy5 checks
  1. GR.GR-1

    The entity's appetite and risk tolerance are defined, approved, communicated and reviewed regularly.

  2. GR.GR-2

    Cybersecurity risk management processes are included in the entity’s cross-cutting risk management strategy.

  3. GR.GR-3

    The entity shall define its risk management strategy.

  4. GR.GR-4

    The entity shall establish an internal communication channel for sharing cybersecurity risks.

  5. GR.GR-5

    The entity shall define a Cybersecurity Risk Management Policy with methodology to manage those risks.

GR.FRFunctions, Responsibilities and Authorities4 checks
  1. GR.FR-1

    The management, management and administration bodies understand their functions and responsibilities and promote a culture of cybersecurity, ethics and continuous improvement.

  2. GR.FR-2

    Appropriate and proportionate resources are allocated to cybersecurity strategy, functions, responsibilities and policies.

  3. GR.FR-3

    The cybersecurity functions, responsibilities and authorities shall be defined and communicated to staff, suppliers and stakeholders.

  4. GR.FR-4

    Cybersecurity is covered in human resources management processes.

GR.PPCybersecurity policies and plans3 checks
  1. GR.PP-1

    Cybersecurity management policies are defined on the basis of the entity's context, strategy and priorities.

  2. GR.PP-2

    The Incident Response Plan is defined, communicated, maintained and improved.

  3. GR.PP-3

    The Disaster Recovery Plan is defined, communicated, maintained and improved.

GR.SPSupervision3 checks
  1. GR.SP-1

    The results of the risk management strategy are analyzed to inform management and adapt the strategy when necessary.

  2. GR.SP-2

    The cybersecurity risk management strategy is regularly reviewed and adapted to organizational requirements and risks.

  3. GR.SP-3

    The performance of cybersecurity risk management shall be assessed and reviewed for the necessary changes.

GR.CARisk Management in Supply Chain10 checks
  1. GR.CA-1

    The supply chain risk management policies and processes are identified, established, evaluated and managed.

  2. GR.CA-2

    The roles and responsibilities of partners, suppliers and customers are defined, communicated and coordinated.

  3. GR.CA-3

    The management of supply chain risks is part of the entity’s cross-cutting processes and risk strategy.

  4. GR.CA-4

    Suppliers shall be periodically evaluated.

  5. GR.CA-5

    The entity is part of the contracts and agreements requirements for managing supply chain risks.

  6. GR.CA-6

    Prior to hiring, due diligence procedures are carried out to reduce risks.

  7. GR.CA-7

    The entity shall assess the cybersecurity risks of the supply chain.

  8. GR.CA-8

    The response and recovery plans are tested with the monitoring of suppliers.

  9. GR.CA-9

    Supply chain practices integrate cybersecurity programs and are monitored throughout the life cycle.

  10. GR.CA-10

    Procedures include arrangements for activities during or after termination of contracts with suppliers or partners.

Application

How to work every control.

  • Confirm full description in Annex I
  • Set scope and responsibility
  • Relating control with risk and critical services
  • Associate implementation and evidence
  • Record gaps, priority and deadline
  • Review implementation and effectiveness

Primary source

Regulation No. 756/2026, of 22 June — Annex I

The codes and titles reproduce the structure of Annex I. Please refer to the official act for the full description and normative references of each control.

Consult official act

Content and references checked on .

Complete cycle

Back to six goals.

Continue the course between Manage, Identify, Protect, Detect, Answer and Recover.

Return to Annex I