Identity Controls for NIS2
The EU NIS2 Directive raises baseline cybersecurity obligations for essential and important entities across many sectors, and identity controls are central to its risk-management requirements. Member-state transposition has made these expectations enforceable, with management accountability attached.
What NIS2 expects of identity
NIS2 requires appropriate technical and organizational measures, and the identity-relevant ones include:
- Access control policies and least privilege.
- Multi-factor or continuous authentication for relevant access.
- Asset and identity management, including non-human identities in operational environments.
- Supply-chain security, which includes governing third-party and vendor access.
What good looks like
- MFA across the workforce, with phishing-resistant factors for privileged and remote access.
- PAM for operational-technology and IT privileged access, a priority in NIS2's industrial and infrastructure sectors.
- IGA for least privilege, joiner-mover-leaver, and evidenced reviews.
- Governed third-party access and ITDR to detect identity-based attacks and meet reporting duties.
Common pitfalls
- Assuming NIS2 is only for IT; its sectors include energy, manufacturing, transport, and more, where OT access is the gap.
- Unmanaged vendor and contractor access in scope of supply-chain requirements.
- No detection capability to support the incident-reporting timelines.
Related
Energy & utilities and manufacturing verticals. Vendors: PAM, ITDR, IGA.
Evidence an auditor will ask for
NIS2 attaches management accountability, which changes what "we have MFA" needs to mean. Be able to produce:
- MFA coverage as a number, with the exemption list, why each exemption exists, and when it was last reviewed. An unreviewed exemption list is the finding.
- Privileged access records: who holds standing elevated rights, session recordings for OT and IT administration, and the approval trail for elevation.
- Access review output showing revocations, not just completion. See access certification.
- Third-party access inventory with time-bounded grants and an owner per vendor.
- Detection coverage mapped to the incident-reporting timeline, since the 24-hour early warning is unachievable if nobody sees the identity attack.
The OT gap
The sectors NIS2 covers include energy, manufacturing, transport, and water, where the hard problem is not the corporate directory but operational technology: shared operator accounts, engineering workstations with local credentials, and vendor remote access into plant systems.
Those environments frequently cannot take an agent, which is why inline authentication controls that extend MFA to protocols agents cannot reach matter more here than in a pure IT estate. Vendor and contractor remote access is the specific supply-chain exposure the directive names, and it is usually the least governed path in the organization.
Where to start
Related on Start with Identity
- GuideIdentity Controls for DORA
The EU Digital Operational Resilience Act (DORA) applies to financial entities and their critical ICT providers, and it makes strong identity and access managem
- GuideIdentity Controls for HIPAA
HIPAA's Security Rule requires safeguards for electronic protected health information (ePHI), and its access-related standards are about identity: who can reach
- GuideIdentity Controls for ISO 27001
ISO/IEC 27001 is the international standard for information security management. It does not prescribe products, but its Annex A controls lean heavily on identi
- GlossaryAML
Anti-Money Laundering. The set of regulations and processes used to detect and report suspicious financial activity. AML programs sit on top of KYC and include
- GlossaryFedRAMP
Federal Risk and Authorization Management Program. The US government cloud services authorization framework. Levels: Low, Moderate, High. Required for SaaS used
- GlossaryGDPR
General Data Protection Regulation. EU privacy law in force since 2018. Establishes user rights (access, rectification, erasure, portability) and obligations on