The time for hesitation is over. The second EU Directive on Security of Network and Information Systems (NIS-2) is in effect, and those responsible are personally liable for violations. This makes the significant gaps in NIS-2 implementation all the more alarming. Executive leadership, in particular, often lacks an understanding of the necessary measures. The central role of Identity and Access Management (IAM) is frequently and severely neglected.
The foundation: Identity and Access Management
To achieve NIS-2 compliance and avoid heavy penalties, a modern IAM system is essential as a foundation. It serves as the strategic framework upon which nearly all risk management measures under Article 21 of the NIS-2 directive are built. IAM is the central point for controlling the most critical variable in any company's security ecosystem: identities. Almost every security risk—whether it involves the manipulation of critical infrastructure, the theft of sensitive data, acts of sabotage, or the spread of malware—begins with an identity gaining or abusing access. Article 21 of the NIS-2 directive requires a comprehensive analysis and management of risks that could threaten network and information systems. However, this risk analysis operates in a vacuum if those responsible do not know which identities are accessing which systems, under what conditions that access is granted, and how that access is subsequently monitored and validated.
By implementing a modern IAM solution, organizations can create a complete inventory of all digital identities—from human users and service accounts to IoT devices and AI agents—and document their access rights to all critical systems and data. This transparency is the prerequisite for the required risk assessment. Without this clarity, organizations cannot evaluate which risks actually exist, which employees or external partners have access to critical infrastructure, and how these access points impact the overall security posture.
A classic problem with IAM systems can be their complexity. If an IAM system is too complex, a faulty implementation can create more security problems than it solves. Therefore, a modern IAM system should feature not only powerful functionality but also an intuitive user interface that makes it easy for administrators to manage users, groups, and permissions.
Multi-Factor Authentication:
You cannot talk about IAM without talking about MFA. NIS-2 agrees. While IAM, figuratively speaking, defines the identity of a building's residents and visitors and controls their permissions, Multi-Factor Authentication (MFA) handles access control. In Article 21, Paragraph 2, NIS-2 explicitly names MFA as one of the minimum measures for cybersecurity risk management. This applies particularly to privileged accounts, such as those held by administrators and identities with access to critical systems. Companies are also required to use risk analysis to determine where forgoing MFA would pose an unacceptable risk (e.g., for remote access or cloud services).
MFA provides a decisive security advantage because knowing a password alone becomes worthless to an attacker; successful access requires the physical possession of a device, a one-time code, a biometric feature, or similar proof from the legitimate user. By combining different categories such as knowledge and possession, the risk from phishing, brute-force attacks, or stolen credentials is massively reduced. Furthermore, modern MFA methods act like a digital alarm system, as users are notified in real-time via push notifications about unauthorized login attempts and can actively block them.
Don't forget Single Sign-On
The downside of MFA can be the increased inconvenience for users. Requiring at least two factors for authentication—especially if different factors are needed for every single application—can lead to decreased productivity and attempts to bypass these perceived burdensome login procedures by using unauthorized apps. Therefore, combining MFA with Single Sign-On (SSO) is highly recommended. If an SSO solution is deeply integrated into the IAM and MFA infrastructure, users only need to authenticate centrally once with their two factors to gain access to all relevant apps—but only those they truly need, as the principle of "least privilege access" should be a given in modern IT security infrastructures. Modern SSO solutions also support a wide range of MFA factors, from app-based one-time passwords (OTP) and SMS to modern standards like passkeys for a passwordless experience. The latter further enhances user-friendliness alongside SSO. SSO and passkeys are the user-side counterpart to the user-friendly interface of the IAM system.
Provable security
However, implementing these measures alone is not enough to achieve NIS-2 compliance. A key innovation in version 2 of the directive is the requirement for accountability. According to the aforementioned Article 21, it is no longer sufficient to simply implement security measures; companies must be able to prove that these measures are effective and continuously monitored. This is why a modern IAM system must be audit-ready. The core of this is the centralized logging of all identity-related events:
Centralized rights management in the IAM should serve as the "single source of truth": If all permissions are managed via the central IAM, it must be possible to generate a report at the push of a button showing which user has access to which (critical) applications. This should also apply to historical data, so that it is possible to trace who granted or revoked a specific right for a user and when.
Employee lifecycle management should also be part of the audit capabilities, as the handling of departed employees is a critical point in audits. Therefore, the IAM must not only block or adjust access immediately when an employee leaves the company or changes departments, but it must also document that this has taken place.
In a nutshell: The IAM system must be able to provide a complete audit trail.
Digital sovereignty as a form of compliance
Even before current geopolitical shifts pushed digital sovereignty to the top of the agenda, NIS-2 defined various requirements that oblige companies to strive for digital independence. For instance, NIS-2 demands supply chain security. The directive requires companies to evaluate the cybersecurity practices of their suppliers and service providers and to factor these into their purchasing decisions. Furthermore, NIS-2 aims to strengthen the European cybersecurity industry with the goal of ensuring that "Made in Europe" solutions are available.
Sovereignty spans three levels – legal, infrastructure, and technology:
NIS-2 as an Opportunity
The aforementioned, still incomplete implementation of NIS-2 is partly due to the fact that companies primarily view compliance as a cost factor. As outlined above, NIS-2 compliance also offers a range of tangible benefits:
In summary: Companies should not only avoid delaying NIS-2 implementation, but they also have no reason to do so. On the contrary, everything points to the benefits of a swift and complete implementation. NIS-2 is far more than just a regulatory obligation. Companies that consistently manage their identities not only strengthen their compliance but also increase their cyber resilience, reduce operational risks, and create the foundation for a future-proof security architecture.
