TL;DR: NIS-2, the Cyber Resilience Act and eIDAS 2.0 shift European digital security from guidance to enforceable control, with more than 30,000 mid-sized companies in Germany alone newly or explicitly in scope, according to KOBIL. The practical message is that documentation without technical identity and access enforcement will not withstand regulatory scrutiny.
NHIMG editorial — based on content published by KOBIL: NIS-2, the Cyber Resilience Act and eIDAS 2.0 make identity control mandatory
Questions worth separating out
Q: How should organisations implement NIS-2 controls across identity and access management?
A: Start with enforceable identity ownership, least privilege and auditable lifecycle controls for every regulated system.
Q: Why do shared accounts and weak offboarding create compliance risk under NIS-2?
A: Because they break accountability.
Q: What do security teams get wrong about compliance in identity governance?
A: Teams often treat compliance as proof that a control exists, when it is really proof that evidence was collected.
Practitioner guidance
- Define regulated identity ownership Assign a named owner for every privileged, workforce and third-party identity in scope for NIS-2, and record the business basis for access so accountability can be traced during review.
- Remove shared accounts from regulated processes Replace shared credentials with individually attributable identities wherever access can affect regulated systems, approvals or reporting.
- Validate auditability before the next supervisory review Test whether you can reconstruct access approval, use, change and revocation across key systems without manual evidence gathering.
What's in the full article
KOBIL's full article covers the operational detail this post intentionally leaves for the source:
- How KOBIL maps its identity and access architecture to NIS-2, eIDAS 2.0 and the Cyber Resilience Act
- Product-specific traceability and access control details for regulated mobile and workplace workflows
- How the vendor positions its mobile app protection approach against regulatory security requirements
- The article's full list of compliance and implementation claims for mid-sized European organisations
👉 Read KOBIL's analysis of NIS-2, the Cyber Resilience Act and eIDAS 2.0 →
NIS-2 compliance in 2026: what identity teams need to change?
Explore further
Identity has become the compliance substrate, not a supporting control. The article correctly frames NIS-2, the Cyber Resilience Act and eIDAS 2.0 as enforceable regimes, but the real operational shift is that regulators can now test whether identity controls actually exist. Policies, presentations and process descriptions are insufficient if access cannot be enforced and evidenced. For identity programmes, that makes governance architecture the primary compliance surface.
A question worth separating out:
Q: Who is accountable when identity controls fail under NIS2?
A: Accountability sits with the organisation and its management structure, because NIS2 is built around governance, supervision, and demonstrable risk management. Operational teams may run the controls, but leadership remains responsible for ensuring the controls are defined, monitored, and evidenced well enough to withstand regulatory review.
👉 Read our full editorial: NIS-2, CRA and eIDAS 2.0 make identity control mandatory