August 27, 2026

NIS2: Compliance as an opportunity

NIS-2 mandates effective IAM: Why identity management, MFA, and auditability are critical to compliance success.

Elmar Eperiesi-Beck is a cybersecurity expert with over 20 years of experience and the CEO of Bare.ID.

NIS2: Compliance as an opportunity

The time for hesitation is over. The second EU Directive on Security of Network and Information Systems (NIS-2) is in effect, and those responsible are personally liable for violations. This makes the significant gaps in NIS-2 implementation all the more alarming. Executive leadership, in particular, often lacks an understanding of the necessary measures. The central role of Identity and Access Management (IAM) is frequently and severely neglected.

The foundation: Identity and Access Management

To achieve NIS-2 compliance and avoid heavy penalties, a modern IAM system is essential as a foundation. It serves as the strategic framework upon which nearly all risk management measures under Article 21 of the NIS-2 directive are built. IAM is the central point for controlling the most critical variable in any company's security ecosystem: identities. Almost every security risk—whether it involves the manipulation of critical infrastructure, the theft of sensitive data, acts of sabotage, or the spread of malware—begins with an identity gaining or abusing access. Article 21 of the NIS-2 directive requires a comprehensive analysis and management of risks that could threaten network and information systems. However, this risk analysis operates in a vacuum if those responsible do not know which identities are accessing which systems, under what conditions that access is granted, and how that access is subsequently monitored and validated.

By implementing a modern IAM solution, organizations can create a complete inventory of all digital identities—from human users and service accounts to IoT devices and AI agents—and document their access rights to all critical systems and data. This transparency is the prerequisite for the required risk assessment. Without this clarity, organizations cannot evaluate which risks actually exist, which employees or external partners have access to critical infrastructure, and how these access points impact the overall security posture.

A classic problem with IAM systems can be their complexity. If an IAM system is too complex, a faulty implementation can create more security problems than it solves. Therefore, a modern IAM system should feature not only powerful functionality but also an intuitive user interface that makes it easy for administrators to manage users, groups, and permissions.

Multi-Factor Authentication:

You cannot talk about IAM without talking about MFA. NIS-2 agrees. While IAM, figuratively speaking, defines the identity of a building's residents and visitors and controls their permissions, Multi-Factor Authentication (MFA) handles access control. In Article 21, Paragraph 2, NIS-2 explicitly names MFA as one of the minimum measures for cybersecurity risk management. This applies particularly to privileged accounts, such as those held by administrators and identities with access to critical systems. Companies are also required to use risk analysis to determine where forgoing MFA would pose an unacceptable risk (e.g., for remote access or cloud services).

MFA provides a decisive security advantage because knowing a password alone becomes worthless to an attacker; successful access requires the physical possession of a device, a one-time code, a biometric feature, or similar proof from the legitimate user. By combining different categories such as knowledge and possession, the risk from phishing, brute-force attacks, or stolen credentials is massively reduced. Furthermore, modern MFA methods act like a digital alarm system, as users are notified in real-time via push notifications about unauthorized login attempts and can actively block them.

Don't forget Single Sign-On

The downside of MFA can be the increased inconvenience for users. Requiring at least two factors for authentication—especially if different factors are needed for every single application—can lead to decreased productivity and attempts to bypass these perceived burdensome login procedures by using unauthorized apps. Therefore, combining MFA with Single Sign-On (SSO) is highly recommended. If an SSO solution is deeply integrated into the IAM and MFA infrastructure, users only need to authenticate centrally once with their two factors to gain access to all relevant apps—but only those they truly need, as the principle of "least privilege access" should be a given in modern IT security infrastructures. Modern SSO solutions also support a wide range of MFA factors, from app-based one-time passwords (OTP) and SMS to modern standards like passkeys for a passwordless experience. The latter further enhances user-friendliness alongside SSO. SSO and passkeys are the user-side counterpart to the user-friendly interface of the IAM system.

Provable security

However, implementing these measures alone is not enough to achieve NIS-2 compliance. A key innovation in version 2 of the directive is the requirement for accountability. According to the aforementioned Article 21, it is no longer sufficient to simply implement security measures; companies must be able to prove that these measures are effective and continuously monitored. This is why a modern IAM system must be audit-ready. The core of this is the centralized logging of all identity-related events:

  • Who logged in?
  • When and from where (IP address, device) did the access occur?
  • Which MFA method was used?
  • Failed attempts (important, among other things, because this allows attacks to be detected early, and NIS-2 also mandates a 24-hour reporting requirement for security breaches).

Centralized rights management in the IAM should serve as the "single source of truth": If all permissions are managed via the central IAM, it must be possible to generate a report at the push of a button showing which user has access to which (critical) applications. This should also apply to historical data, so that it is possible to trace who granted or revoked a specific right for a user and when.

Employee lifecycle management should also be part of the audit capabilities, as the handling of departed employees is a critical point in audits. Therefore, the IAM must not only block or adjust access immediately when an employee leaves the company or changes departments, but it must also document that this has taken place.

In a nutshell: The IAM system must be able to provide a complete audit trail.

Digital sovereignty as a form of compliance

Even before current geopolitical shifts pushed digital sovereignty to the top of the agenda, NIS-2 defined various requirements that oblige companies to strive for digital independence. For instance, NIS-2 demands supply chain security. The directive requires companies to evaluate the cybersecurity practices of their suppliers and service providers and to factor these into their purchasing decisions. Furthermore, NIS-2 aims to strengthen the European cybersecurity industry with the goal of ensuring that "Made in Europe" solutions are available.

Sovereignty spans three levels – legal, infrastructure, and technology:

  • Legal: A European provider is not subject to the US Cloud Act. This means that US authorities cannot compel access to identity data – a decisive advantage over many IAM providers on the market.
  • Infrastructure: When an IAM solution runs in European data centers, sovereignty over the critical identity management infrastructure remains within the borders of the European legal framework. Unless the provider is foreign—in which case, as with US-based providers, specific laws may still allow for access from abroad. Infrastructure located in Germany and provided by a German company strengthens resilience by reducing the risk of becoming a casualty of geopolitical tensions or trade conflicts that could disrupt access to global cloud services.
  • Technology (1): Sovereignty also means avoiding being trapped in a technical dead end, or "vendor lock-in." This is why using open-source technology is advantageous. Not only is the source code transparent and subject to critical review by many independent parties, but open source also enables vendor independence. Should a company decide to switch providers, migration is significantly easier than with proprietary, closed systems. Customers retain control over their identity solution.
  • ·Technology (2): Support for open protocols also strengthens independence. When an IAM provider consistently implements relevant standards such as OpenID Connect (OIDC) and Security Assertion Markup Language (SAML), customers can shape their IT landscape according to their own requirements rather than being dependent on the ecosystem of a single major vendor.

NIS-2 as an Opportunity

The aforementioned, still incomplete implementation of NIS-2 is partly due to the fact that companies primarily view compliance as a cost factor. As outlined above, NIS-2 compliance also offers a range of tangible benefits:

  • Savings through increased cybersecurity: Consistent implementation of NIS-2 can significantly improve cybersecurity. This is not only reassuring and helps avoid the reputational damage associated with a security breach, but it also provides tangible financial benefits: after all, the Cost of a Data Breach Report by IBM estimates the average cost of a data breach for a German company at 3.87 million euros.
  • Savings on insurance: Consistent implementation of NIS-2 measures serves as proof for insurers, who are applying increasingly strict standards to cyber policies. NIS-2 compliance can lead to better terms and lower premiums.
  • Savings on operating costs: Introducing a centralized IAM system reduces manual effort in IT administration. Automated onboarding and offboarding processes save working hours and reduce costly human errors in access management.
  •  Savings on fines: NIS-2 violations can result in fines of up to 10 million euros or 2% of total global annual turnover. In addition, there is the risk of personal liability for management. Investing in compliance is often the much more cost-effective option compared to these potential losses.

In summary: Companies should not only avoid delaying NIS-2 implementation, but they also have no reason to do so. On the contrary, everything points to the benefits of a swift and complete implementation. NIS-2 is far more than just a regulatory obligation. Companies that consistently manage their identities not only strengthen their compliance but also increase their cyber resilience, reduce operational risks, and create the foundation for a future-proof security architecture.

Contact the Press Team

Download Resources

Icon - Elements Webflow Library - BRIX Templates

Icon - Elements Webflow Library - BRIX Templates
Icon - Elements Webflow Library - BRIX Templates

More Blog Articles

No items found.