NIS2
NIS 2 Directive (Directive (EU) 2022/2555 on a high common level of cybersecurity across the Union)
Overview
The NIS 2 Directive sets cybersecurity risk-management and incident-reporting obligations for essential and important entities in the sectors listed in its annexes (sectors of high criticality and other critical sectors). It entered into force on 16 January 2023, Member States had until 17 October 2024 to transpose it, and it repealed the first NIS Directive from 18 October 2024. Because it is a directive, the obligations apply through national laws, and transposition is still incomplete: in July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify transposition measures. On 20 January 2026 the Commission proposed targeted amendments to simplify compliance; these are a proposal, not adopted law. For identity and access management, Article 21 requires access control policies and, where appropriate, multi-factor or continuous authentication.
IAM Requirements
Risk-Management Measures (Article 21)
- Human resources security, access control policies and asset management (Article 21(2)(i))
- Use of multi-factor authentication or continuous authentication solutions, where appropriate (Article 21(2)(j))
- Supply chain security, including security aspects of relationships with direct suppliers and service providers (Article 21(2)(d))
- Basic cyber hygiene practices and cybersecurity training (Article 21(2)(g))
- Policies and procedures to assess the effectiveness of the measures (Article 21(2)(f))
Access Rights and Privileged Accounts (Implementing Regulation (EU) 2024/2690)
- Applies to DNS, cloud, data centre, content delivery, managed service and managed security service providers, online marketplaces, search engines, social networks and trust service providers
- Assign and revoke access rights on the principles of need-to-know, least privilege and separation of duties
- Modify access rights on termination or change of employment and maintain a register of access rights granted
- Review access rights at planned intervals and document the results
- Use dedicated accounts for system administration and strong authentication such as multi-factor authentication for privileged accounts
- Limit third-party access rights in scope and in duration
Identity Lifecycle and Authentication (Implementing Regulation (EU) 2024/2690)
- Manage the full life cycle of identities of network and information systems and their users
- Set up unique identities and link each user identity to a single person; shared identities need explicit approval and documentation
- Review identities regularly and deactivate those no longer needed without delay
- Match authentication strength to the classification of the asset and require separate credentials for privileged or administrative accounts
- Block users after a predefined number of unsuccessful log-in attempts and terminate inactive sessions
Governance and Incident Reporting
- Management bodies approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements (Article 20)
- Members of management bodies are required to follow cybersecurity training (Article 20)
- Early warning within 24 hours of becoming aware of a significant incident (Article 23)
- Incident notification within 72 hours and a final report not later than one month after the notification (Article 23)
Compliance Checklist
Penalties for Non-Compliance
Essential entities: administrative fines of a maximum of at least €10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities: a maximum of at least €7 million or 1.4% of total worldwide annual turnover, whichever is higher (Article 34). Exact amounts are set in national law.
Quick Facts
- Region
- European Union
- Effective Date
- October 18, 2024
- Enforcing Body
- National competent authorities and CSIRTs in each EU Member State; the European Commission monitors transposition