Firewalls and antivirus software were once the gold standard of cybersecurity. Today, they’re table stakes. The real test lies not in what tools you use, but in how well you can prove-under scrutiny-that your organization governs access, manages risk, and holds leadership accountable. This shift is at the heart of the NIS2 Directive, which doesn’t just demand better security practices; it demands better evidence. Auditors aren’t satisfied with good intentions. They want logs, approvals, and documented controls that stand up to inspection. And the first place they look? Identity and access management.
The Pillars of Identity Governance Under Audit Scrutiny
When auditors begin their assessment, they don’t start with penetration tests or network diagrams. They start with people-and who has access to what. A clear, centralized view of your digital environment is no longer optional. Many IT teams are already refining their internal protocols when preparing for nis2 compliance, particularly around the discovery and governance of SaaS applications. Shadow IT-tools adopted by employees without IT approval-is one of the most common compliance gaps. Without visibility into these platforms, enforcing access policies becomes impossible.
Automated discovery tools can continuously scan your network for active SaaS usage, mapping every application in real time. This isn’t just about inventory; it’s about control. Once identified, each app must be assessed for risk, integrated into your identity framework where possible, and monitored for unauthorized access. The goal is a single, auditable registry of all applications-official and unofficial-used across the organization. This registry becomes a foundational artifact during audits, demonstrating proactive oversight rather than reactive cleanup.
Centralizing SaaS Visibility and Shadow IT Discovery
Think of your SaaS ecosystem as a city. Official IT-approved tools are the planned neighborhoods. Shadow IT? That’s the informal settlements springing up on the outskirts-functional, maybe even useful, but outside the law. Left unchecked, they become blind spots for security and compliance. Automated discovery solutions act as city planners, mapping every building, road, and utility. They detect usage patterns, integration points, and data flows, giving you a complete picture. From there, you can decide which tools to sanction, which to decommission, and how to apply consistent access policies across the board.
Implementing the Principle of Least Privilege
Article 21 of the NIS2 Directive emphasizes risk management through structured access controls. One of its core requirements is the implementation of the principle of least privilege-users should only have the permissions necessary to perform their job functions. This sounds straightforward, but in practice, privilege creep is common. Employees change roles, gain temporary access for projects, or inherit permissions from shared accounts. Over time, this creates excessive entitlements that increase the attack surface.
The solution lies in automated provisioning and deprovisioning workflows. When an employee joins, transfers, or leaves, their access should be granted or revoked automatically based on role definitions. This is especially critical for third-party vendors and non-human accounts (like service accounts or APIs), which often go overlooked. Automated systems ensure that access doesn’t linger after contracts end or projects conclude. It’s not just about efficiency-it’s about auditability. Every change should be logged, timestamped, and tied to an approval process.
Critical Access Controls: A Comparative Audit Requirement Table
Auditors evaluate compliance not by intent, but by evidence. They look for consistency, coverage, and traceability across key control domains. Below is a breakdown of what they expect to see-and how your organization can meet those expectations with verifiable, technical proof.
| 🔐 Control Category | 📋 Auditor Expectation (Evidence) | ⚠️ Compliance Impact |
|---|---|---|
| MFA Enforcement | Proof of 100% MFA coverage on administrative and sensitive interfaces. Reports showing activation status, authentication attempts, and fallback usage. | Failure here is a red flag. Partial coverage or reliance on SMS-based codes may be deemed non-compliant. |
| User Lifecycle Management | Automated logs of access provisioning and deprovisioning. Scheduled access reviews with documented recertification decisions. | Manual processes or delayed revocation increase risk and suggest weak governance-common audit findings. |
| Third-party Access Governance | Inventory of external users, defined permission levels, and monitoring of activity. Contracts outlining security obligations. | Poor vendor oversight can lead to supply chain breaches, triggering mandatory incident reporting and liability. |
This table highlights a key reality: compliance isn’t about ticking boxes. It’s about building systems that generate evidence continuously. A one-time snapshot won’t suffice. Auditors want to see that controls are active, monitored, and repeatable. For example, MFA isn’t compliant just because it exists-it must be enforced universally on high-risk systems, with logs to prove it. Similarly, access reviews must happen on a regular schedule, not just before an audit. Automation transforms these processes from ad hoc tasks into institutionalized practices.
The NIS2 Compliance Checklist for IT Security Teams
While NIS2 spans multiple articles and obligations, IT teams need a focused, actionable roadmap. Here are seven essential components of a practical NIS2 compliance checklist, each tied to specific audit requirements and technical controls:
- ✅ Application Inventory - A complete, up-to-date list of all SaaS and internal applications, including shadow IT discovered through automated scanning.
- ✅ MFA Coverage Report - Evidence showing multi-factor authentication is enforced across all privileged and sensitive accounts, with no exceptions.
- ✅ Access Review Logs - Automated records of periodic access recertification, including approvals, denials, and remediation actions.
- ✅ Incident Response Plan - A documented procedure aligned with Article 23, including timelines for early warning (within 24 hours) and final reporting.
- ✅ Vendor Risk Registry - A centralized database of third-party providers, their access levels, security assessments, and contractual obligations.
- ✅ Training Attendance Records - Proof that staff have completed regular cybersecurity awareness training, covering phishing, data handling, and incident reporting.
- ✅ Management Approval Sign-offs - Formal documentation that senior leadership has reviewed and approved the organization’s risk management strategy, as required under Article 20.
These items aren’t just paperwork-they’re operational safeguards. Each one closes a potential audit gap. For instance, without management sign-offs, even technically sound controls may be dismissed as lacking governance. Likewise, an incident response plan without test logs suggests theoretical readiness, not practical preparedness. The goal is to move from reactive compliance to continuous assurance.
Standard Client Questions
In my experience, manual logs are always messy; how do auditors react to Excel-based tracking?
Auditors tolerate Excel in theory, but in practice, they view it as high-risk. Spreadsheets can be easily edited, lack tamper-proof timestamps, and aren’t centrally controlled. Automated systems that generate immutable, time-stamped logs are far more credible and reduce the likelihood of follow-up requests or findings.
What is the specific technical standard required for MFA under NIS2?
NIS2 doesn’t mandate a single technology but requires “state-of-the-art” authentication methods. This effectively rules out SMS-based codes due to SIM-swapping risks. Instead, organizations should adopt phishing-resistant solutions like FIDO2 security keys, authenticator apps, or certificate-based authentication for high-privilege accounts.
How does NIS2 compliance differ from ISO 27001 when it comes to access reviews?
ISO 27001 provides a framework for access control, but NIS2 is legally binding with strict timelines and penalties. While ISO encourages periodic reviews, NIS2 demands documented, scheduled recertifications with board-level accountability. The stakes are higher, and the evidence bar is significantly raised.
What happens if we have a small subsidiary with only 10 employees within our group?
If the parent organization meets the criteria for being an Essential or Important Entity (50+ employees or €10M+ turnover), its subsidiaries may fall under the same obligations-especially if they handle critical functions or share IT infrastructure. The directive focuses on the overall entity’s impact, not just individual units.
What are the legal implications if our management refuses to sign off on the security strategy?
Under Article 20, senior management is directly liable for compliance. Refusal to approve the risk management strategy creates a critical audit failure. This could lead to administrative fines of up to €10 million or 2% of global turnover, and in severe cases, temporary bans on holding management positions.
Can we rely on our cloud provider’s compliance to meet NIS2 requirements?
No. While cloud providers may offer compliant infrastructure, the responsibility for configuring secure access, managing identities, and maintaining audit logs remains with your organization. Shared responsibility means you can’t outsource accountability-only parts of the implementation.