TL;DR: Nearly 66% of businesses operating in Europe have likely not implemented the controls needed for NIS2 compliance, according to Teleport, while the directive’s penalties can reach 10 million euros or 2% of annual revenue for essential entities. The issue is no longer theoretical: identity controls, auditability, and incident response now sit inside a regulatory enforcement frame, not a future policy discussion.
NHIMG editorial — based on content published by Teleport: The NIS2 Directive is Here. What Happens Next?
By the numbers:
- 66% of businesses operating in Europe have likely, likely not implemented the necessary compliance controls for NIS2.
- For essential entities, NIS2 administrative fines may reach 10 million euros or 2% of annual revenue, whichever is higher.
- For important entities, NIS2 fines can start at 7 million euros or 1.4% of annual revenue, whichever is higher.
Questions worth separating out
Q: How should security teams prepare identity controls for NIS2 audit scrutiny?
A: Teams should make access lifecycle evidence retrievable by design.
Q: Why does NIS2 make access logging more important for IAM teams?
A: Because NIS2 treats incident reporting and accountability as core obligations, logs become proof of who accessed what, when, and under which policy.
Q: What breaks when organisations rely on ephemeral credentials but ignore governance?
A: Short-lived credentials reduce the window of exposure, but unmanaged issuance, weak policy enforcement, and poor session visibility still leave control gaps.
Practitioner guidance
- Map NIS2 obligations to identity controls Translate Article 21 obligations into named controls for access, authentication, logging, incident handling, and privileged access.
- Review standing access across critical systems Identify administrative accounts, service accounts, and long-lived tokens that can reach critical systems without task-scoped justification.
- Validate audit trails before the regulator asks for them Test whether access logs, session records, and change histories can be retained, correlated, and exported in a form that supports incident reporting and management accountability.
What's in the full article
Teleport's full blog post covers the operational detail this post intentionally leaves for the source:
- The specific NIS2 control areas Teleport maps to secure infrastructure access, including access control, incident handling, and audit logging.
- The article’s explanation of how identity-based access can reduce standing credentials across engineering workflows.
- The compliance-oriented framing Teleport uses for log retention, session recording, and policy enforcement in regulated environments.
- The broader white-paper context on future NIS2 deadlines and implementation planning.
👉 Read Teleport's analysis of NIS2 compliance controls and enforcement →
NIS2 compliance and access controls: what teams need to fix?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
NIS2 has turned access governance into a regulatory evidence problem, not just a security design problem. The directive’s requirements force organisations to show who had access, why they had it, and how activity was monitored. That shifts IAM, PAM, and logging from operational hygiene to board-visible compliance evidence. Practitioners should treat every critical entitlement as a potential audit artefact.
A few things that frame the scale:
- The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to The 2024 ESG Report: Managing Non-Human Identities.
- Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks.
A question worth separating out:
Q: Who is accountable when identity controls fail under NIS2?
A: Accountability sits with the organisation and its management structure, because NIS2 is built around governance, supervision, and demonstrable risk management. Operational teams may run the controls, but leadership remains responsible for ensuring the controls are defined, monitored, and evidenced well enough to withstand regulatory review.
👉 Read our full editorial: NIS2 compliance gaps expose identity controls and audit weaknesses