Skip to main content
Home > Solutions > Solutions by Standard > NIS2 Compliance NIS2 Ready

NIS2 authentication, done right

NIS2 Article 21 requires essential and important entities to put strong authentication and access control at the heart of their cyber-risk management. MyIDxc2xae delivers phishing-resistant MFA and high-assurance credentials, with the documented, exportable audit evidence regulators expect.

NIS2 Compliance NIS2 Ready
The requirement

What NIS2 actually requires for authentication

NIS2 (Directive (EU) 2022/2555) requires essential and important entities across the EU to take appropriate technical and organisational measures to manage cybersecurity risk. Those measures are set out in Article 21(2), and Article 21(2)(j) specifically calls for multi-factor authentication or continuous authentication, alongside access control (21(2)(i)) and incident handling (21(2)(b)). The transposition deadline passed on 17 October 2024; member states are now bringing their national laws into force. The practical question is which authentication approach gets you compliant without ripping out existing infrastructure.
NIS2 at a glance

The essentials

21(2)(j)
Article 21 names multi-factor or continuous authentication as a required measure
Oct 2024
Transposition deadline passed; national enforcement now rolling out
2%max
Of global annual turnover, the maximum fine for essential entities (Article 34)
Article 21 coverage

How MyID maps to NIS2 Article 21(2)

NIS2 sets out its security measures in Article 21(2); here is where MyID fits. (Annexes I and II of NIS2 list the in-scope sectors: they identify who must comply, not the security measures themselves.)
Regulation / StandardRequirementStatus with MyID
Article 21(2)(j) Multi-factor or continuous authentication MyID MFA: phishing-resistant MFA across in-scope systems
Article 21(2)(i) Access control and cryptography MyID CMS: high-assurance PKI credentials for privileged access
Article 21(2)(b) Incident handling Authentication events logged and exported to your SIEM
Article 21(2)(g) Basic cyber hygiene MyID PSM: breached and weak password screening
How it works

A phased NIS2 rollout

1

Scope assessment

Map your critical and important systems and identify which require strong authentication under NIS2.

2

Deploy phishing-resistant MFA

Roll out MyID MFA across in-scope systems: FIDO2 passkeys, push or one-time codes by criticality. Add MyID CMS PKI credentials for privileged users.

3

Configure the audit trail

Authentication events (user, method and result) are logged to the Windows event log and exported as JSON or CSV to your SIEM.

4

Assemble the evidence pack

Produce your authentication policy, assurance-level mapping and audit-log samples for national-authority inspection.

FAQ

Common questions

Yes. Article 21(2)(j) explicitly names "the use of multi-factor authentication or continuous authentication solutions" as a required risk-management measure for essential and important entities. The sector lists in Annexes I and II define who is in scope; they do not set out the security measures.

The directive had to be transposed into national law by 17 October 2024. Obligations take effect as each member state's implementing law comes into force, so exact timelines vary by country.

Under Article 34, essential entities can face fines of up to xe2x82xac10 million or 2% of total worldwide annual turnover, whichever is higher; important entities up to xe2x82xac7 million or 1.4%.

NIS2 does not mandate a specific technology, but phishing-resistant methods such as FIDO2 passkeys and PKI smart cards are the strongest way to satisfy the multi-factor authentication and access-control measures. MyID issues and manages both.

MyID MFA logs authentication events (including user, method and result) to the Windows event log, and reports export as JSON or CSV for your SIEM, giving inspectors a documented authentication trail.

EU Regulatory Compliance

NIS2 is in force. Let's get you compliant.

Our team can run a gap analysis against your current authentication position and help you assemble the evidence your national authority expects.