NIS2: what it asks of an account list
NIS2 Article 21(2)(i) asks an essential or important entity for human resources security, access control policies and asset management, and 21(2)(j) for multi-factor or continuous authentication. These are broad obligations on the entity's measures, not a rule for each account: the findings cite them where leavers, access and authentication are concerned. The Directive sets no number of days; national law and your own policy do.
When to tick it: tick it only when the company is an essential or important entity under NIS2 in an EU member state.
Findings that cite it
| Finding | Clause |
|---|---|
| 1. A leaver's own account is still enabled | NIS2 Art. 21(2)(i) (every account type) |
| 2. Owner has left, or owner not recognised | NIS2 Art. 21(2)(i) (every account type) |
| 6. Password or key not changed within the period, or never | NIS2 Art. 21(2)(j) (user accounts whose MFA does not read yes) |
| 10. Not reviewed within the interval | NIS2 Art. 21(2)(i) (every account type) |
NIS2: every clause cited
2 of the 28 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
NIS2 Art. 21(2)(i)Human resources security, access control policies and asset managementThree linked disciplines sit in one point because they fail together. Human resources security covers screening proportionate to the role, security terms in employment, and the leaver process. Access control policy covers how identities are created, what rights they carry, how privileged access is granted and reviewed, and how rights change when a person moves internally. Asset management covers knowing what the entity has, who owns it, how it is classified and what happens at disposal. The join between them is where evidence is usually thin: a leaver process that reclaims the laptop but not the cloud account, or an access review run against a directory that does not include the systems that matter. Internal movers are a sharper test than leavers, because accumulated rights are rarely removed.
NIS2 Art. 21(2)(j)Multi-factor or continuous authentication, secured communications and secured emergency communicationsThis point pulls together the authentication and communications controls the Directive names explicitly. Multi-factor authentication, or continuous authentication solutions in its place, is expected where appropriate, and the interesting question is always coverage: remote access, administrative access, and access to the systems behind the essential service are where absence matters most. Secured voice, video and text communications within the entity is the second limb. The third, secured emergency communication systems, is the one most often absent, and it is the one that decides whether the entity can coordinate during an incident in which its normal collaboration and directory services are unavailable or untrusted. A crisis plan that runs on the corporate messaging platform does not satisfy this if that platform is what has been compromised.