Start with Identity
← Guides
Compliance · Intermediate

Identity Controls for NIS2

By SWI Community Team · Updated 2026-08-29 · 10 min

The EU NIS2 Directive raises baseline cybersecurity obligations for essential and important entities across many sectors, and identity controls are central to its risk-management requirements. Member-state transposition has made these expectations enforceable, with management accountability attached.

What NIS2 expects of identity

NIS2 requires appropriate technical and organizational measures, and the identity-relevant ones include:

  • Access control policies and least privilege.
  • Multi-factor or continuous authentication for relevant access.
  • Asset and identity management, including non-human identities in operational environments.
  • Supply-chain security, which includes governing third-party and vendor access.

What good looks like

  • MFA across the workforce, with phishing-resistant factors for privileged and remote access.
  • PAM for operational-technology and IT privileged access, a priority in NIS2's industrial and infrastructure sectors.
  • IGA for least privilege, joiner-mover-leaver, and evidenced reviews.
  • Governed third-party access and ITDR to detect identity-based attacks and meet reporting duties.

Common pitfalls

  • Assuming NIS2 is only for IT; its sectors include energy, manufacturing, transport, and more, where OT access is the gap.
  • Unmanaged vendor and contractor access in scope of supply-chain requirements.
  • No detection capability to support the incident-reporting timelines.

Energy & utilities and manufacturing verticals. Vendors: PAM, ITDR, IGA.

Evidence an auditor will ask for

NIS2 attaches management accountability, which changes what "we have MFA" needs to mean. Be able to produce:

  • MFA coverage as a number, with the exemption list, why each exemption exists, and when it was last reviewed. An unreviewed exemption list is the finding.
  • Privileged access records: who holds standing elevated rights, session recordings for OT and IT administration, and the approval trail for elevation.
  • Access review output showing revocations, not just completion. See access certification.
  • Third-party access inventory with time-bounded grants and an owner per vendor.
  • Detection coverage mapped to the incident-reporting timeline, since the 24-hour early warning is unachievable if nobody sees the identity attack.

The OT gap

The sectors NIS2 covers include energy, manufacturing, transport, and water, where the hard problem is not the corporate directory but operational technology: shared operator accounts, engineering workstations with local credentials, and vendor remote access into plant systems.

Those environments frequently cannot take an agent, which is why inline authentication controls that extend MFA to protocols agents cannot reach matter more here than in a pure IT estate. Vendor and contractor remote access is the specific supply-chain exposure the directive names, and it is usually the least governed path in the organization.

Where to start

Last reviewed By SWI Community TeamSuggest a correctionHow we research