Skip to main content
IAMRoadmapIAMRoadmap
Back to Compliance
Security Standard

NIS2

NIS 2 Directive (Directive (EU) 2022/2555 on a high common level of cybersecurity across the Union)

European Union
Effective: October 18, 2024

Overview

The NIS 2 Directive sets cybersecurity risk-management and incident-reporting obligations for essential and important entities in the sectors listed in its annexes (sectors of high criticality and other critical sectors). It entered into force on 16 January 2023, Member States had until 17 October 2024 to transpose it, and it repealed the first NIS Directive from 18 October 2024. Because it is a directive, the obligations apply through national laws, and transposition is still incomplete: in July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify transposition measures. On 20 January 2026 the Commission proposed targeted amendments to simplify compliance; these are a proposal, not adopted law. For identity and access management, Article 21 requires access control policies and, where appropriate, multi-factor or continuous authentication.

IAM Requirements

Risk-Management Measures (Article 21)

  • Human resources security, access control policies and asset management (Article 21(2)(i))
  • Use of multi-factor authentication or continuous authentication solutions, where appropriate (Article 21(2)(j))
  • Supply chain security, including security aspects of relationships with direct suppliers and service providers (Article 21(2)(d))
  • Basic cyber hygiene practices and cybersecurity training (Article 21(2)(g))
  • Policies and procedures to assess the effectiveness of the measures (Article 21(2)(f))

Access Rights and Privileged Accounts (Implementing Regulation (EU) 2024/2690)

  • Applies to DNS, cloud, data centre, content delivery, managed service and managed security service providers, online marketplaces, search engines, social networks and trust service providers
  • Assign and revoke access rights on the principles of need-to-know, least privilege and separation of duties
  • Modify access rights on termination or change of employment and maintain a register of access rights granted
  • Review access rights at planned intervals and document the results
  • Use dedicated accounts for system administration and strong authentication such as multi-factor authentication for privileged accounts
  • Limit third-party access rights in scope and in duration

Identity Lifecycle and Authentication (Implementing Regulation (EU) 2024/2690)

  • Manage the full life cycle of identities of network and information systems and their users
  • Set up unique identities and link each user identity to a single person; shared identities need explicit approval and documentation
  • Review identities regularly and deactivate those no longer needed without delay
  • Match authentication strength to the classification of the asset and require separate credentials for privileged or administrative accounts
  • Block users after a predefined number of unsuccessful log-in attempts and terminate inactive sessions

Governance and Incident Reporting

  • Management bodies approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements (Article 20)
  • Members of management bodies are required to follow cybersecurity training (Article 20)
  • Early warning within 24 hours of becoming aware of a significant incident (Article 23)
  • Incident notification within 72 hours and a final report not later than one month after the notification (Article 23)

Compliance Checklist

1
Determine whether the organisation is an essential or important entity under the national transposition law
2
Check the transposition status and local requirements in each Member State of operation
3
Have the management body approve and oversee the cybersecurity risk-management measures
4
Document access control policies covering staff, suppliers and system accounts
5
Deploy multi-factor or continuous authentication where appropriate, starting with privileged and remote access
6
Apply least privilege, need-to-know and separation of duties when granting access rights
7
Maintain a register of access rights and review it at planned intervals
8
Separate administration accounts from everyday accounts
9
Remove or change access promptly when staff leave or change roles
10
Limit supplier and service-provider access in scope and duration
11
Prepare incident reporting to meet the 24-hour, 72-hour and one-month deadlines
12
Train management and staff on cybersecurity

Penalties for Non-Compliance

Essential entities: administrative fines of a maximum of at least €10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities: a maximum of at least €7 million or 1.4% of total worldwide annual turnover, whichever is higher (Article 34). Exact amounts are set in national law.

Quick Facts

Region
European Union
Effective Date
October 18, 2024
Enforcing Body
National competent authorities and CSIRTs in each EU Member State; the European Commission monitors transposition

Related Certifications

Related Regulations & Frameworks