Orphaned Account Checker

NIS2: what it asks of an account list

NIS2 Article 21(2)(i) asks an essential or important entity for human resources security, access control policies and asset management, and 21(2)(j) for multi-factor or continuous authentication. These are broad obligations on the entity's measures, not a rule for each account: the findings cite them where leavers, access and authentication are concerned. The Directive sets no number of days; national law and your own policy do.

When to tick it: tick it only when the company is an essential or important entity under NIS2 in an EU member state.

Findings that cite it

FindingClause
1. A leaver's own account is still enabledNIS2 Art. 21(2)(i) (every account type)
2. Owner has left, or owner not recognisedNIS2 Art. 21(2)(i) (every account type)
6. Password or key not changed within the period, or neverNIS2 Art. 21(2)(j) (user accounts whose MFA does not read yes)
10. Not reviewed within the intervalNIS2 Art. 21(2)(i) (every account type)

NIS2: every clause cited

2 of the 28 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

NIS2 Art. 21(2)(i)Human resources security, access control policies and asset management

Three linked disciplines sit in one point because they fail together. Human resources security covers screening proportionate to the role, security terms in employment, and the leaver process. Access control policy covers how identities are created, what rights they carry, how privileged access is granted and reviewed, and how rights change when a person moves internally. Asset management covers knowing what the entity has, who owns it, how it is classified and what happens at disposal. The join between them is where evidence is usually thin: a leaver process that reclaims the laptop but not the cloud account, or an access review run against a directory that does not include the systems that matter. Internal movers are a sharper test than leavers, because accumulated rights are rarely removed.

What an auditor asks to see: Screening policy and records proportionate to role sensitivity; Joiner, mover and leaver procedure with timed evidence of access removal; Access control policy plus periodic access review results, including privileged accounts; Asset inventory with ownership and classification, reconciled against a discovery source; Secure disposal and media sanitisation records
Where account lists usually fall short: Leaver process that covers directory accounts but not federated or cloud services; Internal movers accumulating rights because only leavers trigger review; Asset inventory maintained manually and drifting away from what is actually connected; Access reviews signed off in bulk by managers with no basis for the approval
Source: NIS2 Directive (EU) 2022/2555, Article 21
NIS2 Art. 21(2)(j)Multi-factor or continuous authentication, secured communications and secured emergency communications

This point pulls together the authentication and communications controls the Directive names explicitly. Multi-factor authentication, or continuous authentication solutions in its place, is expected where appropriate, and the interesting question is always coverage: remote access, administrative access, and access to the systems behind the essential service are where absence matters most. Secured voice, video and text communications within the entity is the second limb. The third, secured emergency communication systems, is the one most often absent, and it is the one that decides whether the entity can coordinate during an incident in which its normal collaboration and directory services are unavailable or untrusted. A crisis plan that runs on the corporate messaging platform does not satisfy this if that platform is what has been compromised.

What an auditor asks to see: Coverage report for multi-factor or continuous authentication across remote, privileged and essential-service access; The reasoning and compensating controls for any access path left without it; Configuration evidence for secured voice, video and text communications within the entity; The out-of-band emergency communications capability, its contact data and how the data is kept current; Exercise evidence showing the emergency channel worked when the primary was assumed unavailable
Where account lists usually fall short: Multi-factor authentication on the corporate portal but not on administrative or machine access paths; Exemptions granted to executives or to legacy protocols and never revisited; Emergency communications limited to a contact list stored inside the systems that would be down; No test of the out-of-band channel, so it is first used during a real crisis
Source: NIS2 Directive (EU) 2022/2555, Article 21