NIS2 organises itself around four areas. Identity contributes to all four and is sufficient for none of them, which is worth saying before a project is scoped as if it were.
DomainWhat NIS2 expectsWhat the identity layer contributes
01Cyber risk managementTechnical and organisational measures proportionate to risk, including access control policies, asset and supplier management, and the ability to show the measures are actually in force rather than written down.Least privilege that is enforced instead of documented: who has access to which system, granted through which policy, reviewed when. Access reviews and segregation-of-duties rules produce the artefact — a state, and the decisions that led to it.
02Corporate accountabilityManagement bodies approve the measures, oversee them and can be held personally responsible. Senior leadership needs a defensible account of the security posture, not a quarterly reassurance.Privileged access is the part of the posture executives are most exposed on. Who can act unilaterally, who approved that, and what happens when the person changes role are answerable from the governance layer rather than from a spreadsheet.
03Reporting obligationsEarly warning, notification and final report inside fixed windows, to the competent authority of each member state where the entity is in scope.Access history is one of the few sources that is both reliable and immediately available: sessions, authentications, entitlement changes, revocations, with the timestamps and the approvals attached.
04Business continuityBackup management, disaster recovery and crisis management that have been tested, including for the identity systems everything else authenticates against.An access layer is itself critical infrastructure once every application depends on it. Deployment model, failure behaviour and recovery of the identity service belong in the continuity plan, not in an appendix.