TL;DR: NIS2 expands cybersecurity obligations beyond essential services to their suppliers, with senior management accountability, 24-hour reporting, and fines that can reach 2% of worldwide turnover, according to Expel. The directive turns access control, incident handling, and supply chain assurance into board-level governance issues, not optional controls.
NHIMG editorial — based on content published by Expel: NIS2 compliance and third-party obligations for essential services
By the numbers:
- The directive requires an early warning of a significant incident within 24 hours of becoming aware of it.
- Essential entities can face fines of up to €10 million or 2% of total worldwide annual turnover, whichever is higher.
- Important entities can face maximum fines of €7 million or 1.4% of worldwide annual turnover, whichever is higher.
Questions worth separating out
Q: What do security teams get wrong about third-party access under NIS2?
A: They often treat vendor access as a connectivity issue instead of a governance issue.
Q: Why do identity controls matter so much for NIS2 compliance?
A: Because NIS2 compliance depends on proving who had access, what they could do, and how quickly you can respond when something goes wrong.
Q: What do organisations get wrong about NIS2 reporting readiness?
A: They assume alert volume is the main problem, when the real gap is evidence production.
Practitioner guidance
- Inventory third-party access paths Document every supplier, MSP, and contractor identity that can reach production or regulated environments, including remote support channels, API access, and break-glass accounts.
- Extend MFA to privileged and third-party access Verify that MFA is enforced for administrative logins, remote access, vendor connections, and any workflow that can change critical infrastructure settings.
- Test incident reporting against identity telemetry Run tabletop exercises that use real identity logs, privileged session records, and authentication events to prove you can assemble a 24-hour and 72-hour report.
What's in the full article
Expel's full guide covers the operational detail this post intentionally leaves for the source:
- Sector-by-sector explanation of which organisations fall into essential and important entity categories
- The full incident reporting timeline with 24-hour, 72-hour, and one-month reporting obligations
- Practical compliance preparation steps for companies acting as third-party providers to regulated entities
- Additional detail on how managed detection and response services align to NIS2 readiness
👉 Read Expel's guide to NIS2 compliance and third-party obligations →
NIS2 and third-party access: what security teams need to change?
Explore further
NIS2 makes identity governance a compliance control, not just an IAM programme concern. The directive’s emphasis on access control, incident handling, and supplier oversight means identity teams are now supporting regulatory assurance as much as security posture. That shifts the evaluation standard from "is access managed" to "can access management be evidenced under audit and incident pressure". Practitioners should treat identity governance as part of operational resilience.
A question worth separating out:
Q: Who is accountable when supplier access contributes to a NIS2 incident?
A: Accountability sits with the organisation that owns the service, because NIS2 expects supplier risk to be governed inside operational resilience processes. In practice, that means business owners, identity teams, and security leadership must share responsibility for access issuance, review, and revocation, especially when third-party credentials touch critical systems.
👉 Read our full editorial: NIS2 compliance is now a supply chain issue for critical services