Join our Newsletter — 33% off our NHI Course

How should security teams prove who accessed critical systems under NIS2 audits?

Security teams should combine privileged access governance, real time session monitoring, and immutable audit evidence. The practical goal is to show who approved access, who used it, what they did, and whether the activity was recorded. Without traceability across approval, monitoring, and retention, compliance claims stay weak under audit pressure, especially when third party and OT access are involved.

What auditors need to see in access evidence

Under NIS2, the question is not just whether access existed, but whether you can prove the access decision path end to end. Auditors usually want a coherent record that links approval, identity, session activity, and retention, so the evidence shows who was allowed in, who actually used the access, and what was done during the session.

That means the strongest evidence is not a single export from a PAM tool or SIEM. It is a joined trail that can survive challenge across the EU NIS2 Directive and the operational controls behind it.

How to prove accountability across approval, use, and action

Start by separating three questions that often get mixed together: who approved the access, who authenticated into the system, and what the session did. If those are stored in different tools, the audit package must still correlate them through timestamps, user or account IDs, ticket references, and immutable logs.

For privileged and third-party access, the evidence should show the requested scope, the approver, the time window, the actual session start and end, and the commands or transactions that were performed. That is the difference between saying access was controlled and showing that control was actually exercised.

For teams building the evidence trail, NHIMG’s Identity Security Regulatory Map is useful because it ties access governance concepts to NIS2 and related compliance obligations.

Why session monitoring and retention matter more than point-in-time approvals

A clean approval record is not enough if the activity itself is not observable. Auditors will expect session monitoring, alertable event logging, and retention rules that preserve evidence long enough to support investigation, review, and external assurance. In practice, the gap is usually not that logs do not exist, but that they are fragmented, overwritable, or impossible to reconstruct quickly.

Critical systems often involve OT, vendor support, emergency break-glass accounts, or shared administrative pathways. Those are exactly the cases where session traceability becomes the control that separates legitimate maintenance from unexplained privileged use. If a team cannot show the session record, the approval trail loses much of its value.

The most direct internal reference for this kind of audit evidence chain is Ultimate Guide to NHIs, Regulatory and Audit Perspectives, which covers audit trails, governance obligations, and access review themes that mirror the evidence pattern auditors look for.

How to make the audit pack defensible under pressure

Build the audit pack so it can answer a challenge in minutes, not days. The best structure is a single case file per privileged event or access path, containing the approval record, the authentication event, the session transcript or equivalent activity log, the asset targeted, the duration, and the retention location. If third parties are involved, include their contract or access sponsor mapping as well.

Teams should also be ready to explain exception handling. Emergency access, shared admin accounts, or delayed log forwarding can all be defensible, but only if the process shows why the exception existed, how long it lasted, and how it was reviewed afterward. Without that context, auditors may treat exceptions as uncontrolled exposure rather than managed risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AU-2 — Event Logging Access proof under audit depends on recorded privileged activity and session evidence.
AU-6 — Audit Review, Analysis, and Reporting Audits require reviewable evidence that privileged actions were monitored and analyzed.
AC-6 — Least Privilege NIS2 access evidence is stronger when approvals and sessions reflect limited, justified privilege.
Recommendation — Log privileged access events with enough detail to reconstruct who did what and when. Review privileged logs and preserve reports that show access was monitored and investigated. Restrict privileged access to the minimum needed and document the approved scope.
ISO/IEC 27001:2022 A.5.15 — Access control Access governance and traceability are core to proving controlled access under audit.
A.8.15 — Logging Immutable audit evidence requires reliable logging for privileged and critical-system activity.
Recommendation — Define and enforce access rules that tie approval, use, and review together. Enable logging for critical access paths and retain records for audit reconstruction.

Practitioner Guidance

What to verify: Before an audit, verify that every critical access event can be traced from request to approval to actual session activity to retention, without manual reconstruction across disconnected tools. If any one of those links is missing, the control story is weaker than the technical control itself.

Common mistake: Do not rely on approval workflows alone as proof of control. Approval without session evidence proves intent, not accountable use, and auditors usually care about both.

What good looks like: A reviewer can select a privileged session, identify the approver, confirm the actor, see the actions taken, and retrieve the record from immutable storage with minimal ambiguity.

Practitioner takeaway: The audit objective is traceability, not paperwork, so the evidence chain must show who authorised access, who used it, what they did, and whether that record is trustworthy and durable.