TL;DR: Nearly 66% of businesses operating in Europe have likely not implemented the controls needed for NIS2 compliance, according to Teleport, while the directive’s penalties can reach 10 million euros or 2% of annual revenue for essential entities. The issue is no longer theoretical: identity controls, auditability, and incident response now sit inside a regulatory enforcement frame, not a future policy discussion.
At a glance
What this is: This is an analysis of what NIS2 enforcement means for security and identity programmes, with a focus on access control, logging, and compliance readiness.
Why it matters: It matters because NIS2 turns identity governance, privileged access, and incident evidence into regulatory obligations that affect NHI, human IAM, and operational resilience programmes.
By the numbers:
- 66% of businesses operating in Europe have likely, likely not implemented the necessary compliance controls for NIS2.
- For essential entities, NIS2 administrative fines may reach 10 million euros or 2% of annual revenue, whichever is higher.
- For important entities, NIS2 fines can start at 7 million euros or 1.4% of annual revenue, whichever is higher.
👉 Read Teleport's analysis of NIS2 compliance controls and enforcement
Context
NIS2 is a regulatory compliance issue first, but its operational impact lands directly on identity control, access governance, and audit readiness. The directive requires organisations to prove they can manage access, monitor activity, and respond to incidents across critical systems.
The article’s core argument is that compliance work should not slow while national transposition varies. For identity teams, that means treating access control, logging, and incident handling as part of a single governance plane across human users, service accounts, and other non-human identities.
Key questions
Q: How should security teams prepare identity controls for NIS2 audit scrutiny?
A: Teams should make access lifecycle evidence retrievable by design. That means approval trails, entitlement changes, review outcomes, revocation records, and privileged session logs must be tied to the same identity records. If the organisation cannot prove who had access, why they had it, and when it ended, NIS2 readiness is incomplete.
Q: Why does NIS2 make access logging more important for IAM teams?
A: Because NIS2 treats incident reporting and accountability as core obligations, logs become proof of who accessed what, when, and under which policy. IAM teams need retained, correlated logs for authentication, privileged actions, and changes so compliance teams can reconstruct events and demonstrate control after an incident.
Q: What breaks when organisations rely on ephemeral credentials but ignore governance?
A: Short-lived credentials reduce the window of exposure, but unmanaged issuance, weak policy enforcement, and poor session visibility still leave control gaps. The organisation may have fewer standing secrets yet still lack evidence, ownership, and enforcement. That creates a false sense of compliance and a real risk of audit failure.
Q: Who is accountable when identity controls fail under NIS2?
A: Accountability sits with the organisation and its management structure, because NIS2 is built around governance, supervision, and demonstrable risk management. Operational teams may run the controls, but leadership remains responsible for ensuring the controls are defined, monitored, and evidenced well enough to withstand regulatory review.
Technical breakdown
Access control under NIS2 means provable identity governance
NIS2 does not just ask for access controls in the abstract. It expects organisations to demonstrate that access to network and information systems is proportionate, monitored, and governed across the lifecycle of the identity. That puts least privilege, authentication strength, and entitlement review into the same operational category as resilience and reporting. For identity teams, the technical issue is not whether access exists, but whether access can be justified, limited, and audited when regulators or incident responders ask for evidence.
Practical implication: map privileged and sensitive access paths to named owners, review cycles, and auditable controls before compliance testing begins.
Ephemeral credentials reduce exposure but do not remove governance duty
The article links NIS2 compliance to identity-based access and credential elimination. Ephemeral credentials can reduce standing risk by shortening the usable lifetime of secrets, but they do not replace governance around issuance, scope, session visibility, or offboarding. If a credential is short-lived but unmanaged, the control problem shifts from static exposure to operational blind spots. That matters for SSH access, administrative sessions, and service accounts that need traceability without persistent secrets.
Practical implication: pair short-lived credentials with logging, policy enforcement, and lifecycle ownership instead of treating ephemeral access as a complete control.
Audit logs become compliance evidence, not just telemetry
NIS2 places heavy emphasis on incident reporting and maintaining comprehensive logs of access and system changes. In identity terms, logs are no longer only security telemetry for detection teams. They become the evidence layer that supports accountability, forensic reconstruction, and regulatory response. Without reliable session trails, access logs, and change history, organisations may be able to say they enforced policy but not prove it under scrutiny.
Practical implication: verify that authentication, session, and privileged action logs are retained, correlated, and exportable for incident and compliance review.
Threat narrative
Attacker objective: The objective is to exploit weak identity governance to gain unauthorised access, increase blast radius, or create compliance failure that compounds operational and financial damage.
- Entry occurs through weak or unmanaged access controls, especially where standing credentials or inconsistent authentication still exist across critical systems.
- Escalation follows when access is broader than the task requires, allowing privilege misuse, policy bypass, or unauthorised administrative activity.
- Impact appears as regulatory exposure, audit failure, incident response friction, and potential penalties when the organisation cannot prove control or containment.
Breaches seen in the wild
- Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.
- Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
NIS2 has turned access governance into a regulatory evidence problem, not just a security design problem. The directive’s requirements force organisations to show who had access, why they had it, and how activity was monitored. That shifts IAM, PAM, and logging from operational hygiene to board-visible compliance evidence. Practitioners should treat every critical entitlement as a potential audit artefact.
Identity-based access reduces standing risk, but it does not satisfy NIS2 by itself. Ephemeral credentials and zero standing privilege can narrow the attack window, yet regulators still expect demonstrable control over issuance, scope, monitoring, and response. The lesson is that short-lived access is a control pattern, not a compliance outcome. Security teams need end-to-end lifecycle ownership, not just shorter credential lifetimes.
Auditability is now part of resilience because NIS2 assumes the organisation can reconstruct access events after an incident. If session logs, change records, or privileged actions are incomplete, the control gap becomes visible at the worst possible moment. That makes identity telemetry a governance dependency, not an optional investigation layer. The practical conclusion is simple: if you cannot evidence access, you cannot evidence compliance.
Ultimate Guide to NHIs - Regulatory and Audit Perspectives: NIS2 reinforces a broader pattern across machine identity governance, where access, audit, and accountability must be designed together. The same discipline applies whether the actor is a human admin, a service account, or an automated workload. Identity governance teams should align control ownership across these actor types before enforcement tightens further.
From our research:
- The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to The 2024 ESG Report: Managing Non-Human Identities.
- Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks.
- That pattern reinforces the need to pair Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs with regulatory evidence controls.
What this signals
NIS2 is pushing identity programmes toward a single operating model where access, audit, and incident response are managed together. Teams that still separate IAM, PAM, and compliance reporting will struggle to prove control consistency when the regulator or an incident response team asks for evidence.
Identity evidence debt: this is the gap between having controls in place and being able to prove they operated at the right time. In practice, the risk is not just non-compliance but delayed detection, weak forensic reconstruction, and weak leadership accountability when something goes wrong.
For practitioners
- Map NIS2 obligations to identity controls Translate Article 21 obligations into named controls for access, authentication, logging, incident handling, and privileged access. Assign each control to a business owner and a technical owner so compliance evidence is not scattered across teams.
- Review standing access across critical systems Identify administrative accounts, service accounts, and long-lived tokens that can reach critical systems without task-scoped justification. Replace persistent access where possible and document the approval path where persistence remains necessary.
- Validate audit trails before the regulator asks for them Test whether access logs, session records, and change histories can be retained, correlated, and exported in a form that supports incident reporting and management accountability. Treat missing telemetry as a compliance defect, not only a detection gap.
- Close the gap between policy and enforcement Check whether your access policies are actually enforced across infrastructure, cloud, and privileged sessions. If policy exists only in documentation, NIS2 readiness is still incomplete even when the language looks mature.
- Accelerate compliance work in parallel with transposition changes Track national implementation status, but do not wait for perfect local clarity before hardening identity and logging controls. The control work has to be usable now, because audit and incident expectations will not wait for legal neatness.
Key takeaways
- NIS2 turns identity controls into enforceable evidence, so access governance is now a compliance function as much as a security function.
- The article’s numbers show a wide implementation gap, which means many organisations will face pressure on both controls and proof.
- Practitioners should align access, logging, and incident ownership now, because regulators will expect the organisation to reconstruct events, not just claim readiness.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the technical controls, while NIS2 and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIS2 | Article 21 | The article centres on NIS2 cyber risk measures and compliance obligations. |
| NIST CSF 2.0 | PR.AC-4 | NIS2 compliance in the article depends on managed access permissions. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is central to the article’s access-control discussion. |
| ISO/IEC 27001:2022 | A.5.15 | Access control is a direct match for the article’s governance requirements. |
| NIST Zero Trust (SP 800-207) | 4.2 | The article’s identity-based access approach aligns with zero-trust verification. |
Map access control, logging, incident handling, and policy enforcement to Article 21 requirements.
Key terms
- NIS2 Compliance Evidence: NIS2 compliance evidence is the operational record that proves controls are working, not just written down. It usually includes access logs, incident timestamps, approval history, supplier reviews, and revocation records that show governance was executed consistently across the organisation.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
- Audit-Ready Logging: Audit-ready logging is evidence capture detailed enough to reconstruct what happened in a model interaction after the fact. For LLM environments, that means recording prompts, retrieval steps, guardrail actions, model changes, and administrative activity in a form that supports compliance review and incident investigation.
What's in the full article
Teleport's full blog post covers the operational detail this post intentionally leaves for the source:
- The specific NIS2 control areas Teleport maps to secure infrastructure access, including access control, incident handling, and audit logging.
- The article’s explanation of how identity-based access can reduce standing credentials across engineering workflows.
- The compliance-oriented framing Teleport uses for log retention, session recording, and policy enforcement in regulated environments.
- The broader white-paper context on future NIS2 deadlines and implementation planning.
👉 Teleport's full post covers the access, logging, and policy details behind NIS2 readiness.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org