NIS2

Twenty-four hours to say something true

NIS2 does not ask for an identity platform. It asks for measures that are actually in force, an executive who can vouch for them, and a coherent account of an incident inside deadlines that start counting before anyone understands what happened.

What changed

Wider scope, personal accountability, fixed deadlines

The first NIS Directive asked a few operators of critical infrastructure to take cybersecurity seriously. NIS2 asks eighteen sectors, names the people responsible, and attaches a clock to the reporting.

You are probably in scope, or supplying someone who is

Energy, transport, banking, health, water, digital infrastructure and public administration as essential entities; manufacturing, food, chemicals, postal services, waste and digital providers as important ones. Everyone else meets it through a customer's third-party questionnaire.

The accountability is personal

Management bodies approve the measures and oversee them, and in essential entities inadequate governance can mean temporary suspension from managerial duties. That single provision is why NIS2 conversations happen at board level and not in a security backlog.

It arrives as national law

Each member state transposes it under its own name, with its own authority and its own portal — and some extended the scope. A group operating in six countries is complying six times, which is exactly where centralised controls start paying for themselves.

Reporting obligations

The only part of NIS2 with a stopwatch

Three notifications, three deadlines, one story that has to stay consistent across all of them. Under each stage is the question the identity layer is expected to answer — and it is the same question three times, at increasing precision.

Within 24 hours

Early warning

A first notification to the national authority: something significant is happening, whether it looks malicious, and whether it may have cross-border effects. At this point nobody knows the full story yet, and the deadline does not care.

Which identities and accounts are involved, and what do they have access to right now?

Within 72 hours

Incident notification

An initial assessment: severity, impact, indicators of compromise. The gap between the first and second deadline is where an organisation either has its own account of events or starts reconstructing one from screenshots.

Was that access legitimate, when was it granted, and by whom — and what has been cut since?

Within one month

Final report

The full description: root cause, mitigations applied, cross-border impact. This is the document that gets read again if the authority comes back, and the one that has to agree with the two notifications sent before it.

Can the same history be produced twice, months apart, and match?

Nothing here is answerable by an authentication log alone. The 72-hour assessment needs entitlements and approvals as well as sessions — what the access allowed, not only that it happened.

The four domains

What the directive expects, and what identity can evidence

NIS2 organises itself around four areas. Identity contributes to all four and is sufficient for none of them, which is worth saying before a project is scoped as if it were.

DomainWhat NIS2 expectsWhat the identity layer contributes
01Cyber risk managementTechnical and organisational measures proportionate to risk, including access control policies, asset and supplier management, and the ability to show the measures are actually in force rather than written down.Least privilege that is enforced instead of documented: who has access to which system, granted through which policy, reviewed when. Access reviews and segregation-of-duties rules produce the artefact — a state, and the decisions that led to it.
02Corporate accountabilityManagement bodies approve the measures, oversee them and can be held personally responsible. Senior leadership needs a defensible account of the security posture, not a quarterly reassurance.Privileged access is the part of the posture executives are most exposed on. Who can act unilaterally, who approved that, and what happens when the person changes role are answerable from the governance layer rather than from a spreadsheet.
03Reporting obligationsEarly warning, notification and final report inside fixed windows, to the competent authority of each member state where the entity is in scope.Access history is one of the few sources that is both reliable and immediately available: sessions, authentications, entitlement changes, revocations, with the timestamps and the approvals attached.
04Business continuityBackup management, disaster recovery and crisis management that have been tested, including for the identity systems everything else authenticates against.An access layer is itself critical infrastructure once every application depends on it. Deployment model, failure behaviour and recovery of the identity service belong in the continuity plan, not in an appendix.
How Monokee approaches it

Controls that hold, and a history that survives the deadline

Access that changes in minutes, not at next login

During an incident the useful action is narrowing or ending access while the investigation is still running. Sessions carry a lifetime, a scope and conditions, and can be shortened, elevated or terminated from outside the application.

One account of who had what

Entitlements, approvals, grants and removals with their history intact — including for identities that are no longer active. It is the same artefact an auditor asks for and an authority expects in the final report.

Suppliers and third parties as first-class identities

Supply chain security is explicit in the directive, and most of it arrives as people from other organisations holding access to your systems. External populations get their own domain, their own lifecycle and an expiry that is enforced.

What this does not do

It does not make an organisation compliant. NIS2 is a governance, risk and continuity obligation: it needs a risk register, a tested incident response process, named owners and management signoff. An identity platform supplies controls and evidence for part of it — the part that answers who could do what, and when.

Before you scope a project

Five things worth checking first

  • Eighteen sectors, split between essential and important entities, with size thresholds that put most mid-sized companies in scope for the first time.
  • Fines up to €10 million or 2% of global turnover for essential entities, €7 million or 1.4% for important ones — plus national penalties for failing to notify or to produce proof.
  • Management bodies can be held personally accountable, up to temporary suspension from managerial duties in essential entities.
  • The directive is applied through national law: in Italy it is Decreto Legislativo 138/2024, and several member states extended the scope beyond the minimum.
  • Companies outside the scope are still reached through the supply chain, as suppliers asked to demonstrate alignment by customers who are in it.

This page describes how an identity layer contributes to NIS2 obligations. It is not legal advice, and it is not a certification claim: whether an entity is in scope, and what satisfies its national authority, is a question for counsel and for the authority itself.

Bring us the incident you would struggle to reconstruct

Usually there is one: access nobody can date, an account nobody owns, a session that outlived the contract. That is where the identity part of NIS2 is decided.

Talk to an expert