Annex I · Objective 01
Manage
Managing sets out the cross-cutting governance conditions guiding the other NH objectivesRCS.
Complete structure
Categories and controls.
Select each category to see all the codes and titles that make up it.
GR.COOrganizational context6 checks
- GR.CO-1
The mission, vision, risk management strategy and objectives of the entity shall be defined and communicated.
- GR.CO-2
The needs and expectations of internal and external stakeholders are understood and reflected in the management of cybersecurity risks.
- GR.CO-3
Legal, regulatory and contractual requirements for cybersecurity are understood and managed.
- GR.CO-4
The critical services of the entity on which external stakeholders depend are identified and reported.
- GR.CO-5
The resilience requirements necessary to support the provision of critical services are defined.
- GR.CO-6
The external services on which the entity depends are identified and reported.
GR.GRRisk Management Strategy5 checks
- GR.GR-1
The entity's appetite and risk tolerance are defined, approved, communicated and reviewed regularly.
- GR.GR-2
Cybersecurity risk management processes are included in the entity’s cross-cutting risk management strategy.
- GR.GR-3
The entity shall define its risk management strategy.
- GR.GR-4
The entity shall establish an internal communication channel for sharing cybersecurity risks.
- GR.GR-5
The entity shall define a Cybersecurity Risk Management Policy with methodology to manage those risks.
GR.FRFunctions, Responsibilities and Authorities4 checks
- GR.FR-1
The management, management and administration bodies understand their functions and responsibilities and promote a culture of cybersecurity, ethics and continuous improvement.
- GR.FR-2
Appropriate and proportionate resources are allocated to cybersecurity strategy, functions, responsibilities and policies.
- GR.FR-3
The cybersecurity functions, responsibilities and authorities shall be defined and communicated to staff, suppliers and stakeholders.
- GR.FR-4
Cybersecurity is covered in human resources management processes.
GR.PPCybersecurity policies and plans3 checks
- GR.PP-1
Cybersecurity management policies are defined on the basis of the entity's context, strategy and priorities.
- GR.PP-2
The Incident Response Plan is defined, communicated, maintained and improved.
- GR.PP-3
The Disaster Recovery Plan is defined, communicated, maintained and improved.
GR.SPSupervision3 checks
- GR.SP-1
The results of the risk management strategy are analyzed to inform management and adapt the strategy when necessary.
- GR.SP-2
The cybersecurity risk management strategy is regularly reviewed and adapted to organizational requirements and risks.
- GR.SP-3
The performance of cybersecurity risk management shall be assessed and reviewed for the necessary changes.
GR.CARisk Management in Supply Chain10 checks
- GR.CA-1
The supply chain risk management policies and processes are identified, established, evaluated and managed.
- GR.CA-2
The roles and responsibilities of partners, suppliers and customers are defined, communicated and coordinated.
- GR.CA-3
The management of supply chain risks is part of the entity’s cross-cutting processes and risk strategy.
- GR.CA-4
Suppliers shall be periodically evaluated.
- GR.CA-5
The entity is part of the contracts and agreements requirements for managing supply chain risks.
- GR.CA-6
Prior to hiring, due diligence procedures are carried out to reduce risks.
- GR.CA-7
The entity shall assess the cybersecurity risks of the supply chain.
- GR.CA-8
The response and recovery plans are tested with the monitoring of suppliers.
- GR.CA-9
Supply chain practices integrate cybersecurity programs and are monitored throughout the life cycle.
- GR.CA-10
Procedures include arrangements for activities during or after termination of contracts with suppliers or partners.
Application
How to work every control.
- Confirm full description in Annex I
- Set scope and responsibility
- Relating control with risk and critical services
- Associate implementation and evidence
- Record gaps, priority and deadline
- Review implementation and effectiveness
Primary source
Regulation No. 756/2026, of 22 June — Annex I
The codes and titles reproduce the structure of Annex I. Please refer to the official act for the full description and normative references of each control.