Organisations should use MFA for workforce access to remote sessions, workstations, and privileged accounts, then verify that the method is phishing resistant wherever practical. NIS2 expects a risk based approach, so the control should fit the exposure level of the system and the user role. Security teams should also test emergency access and recovery paths, because weak fallback flows often become the real compliance gap.
Why This Matters for Security Teams
NIS2 is not satisfied by a checkbox MFA rollout. In critical sectors, the control must reduce real compromise paths across workforce access, privileged sessions, and recovery workflows, especially where remote access expands exposure. The NIS2 Directive - official EU legal text frames security measures as risk based, which means organisations need to align MFA strength to the sensitivity of the account and the business impact of failure.
This matters because attackers rarely target the strongest login path first. They look for fallback channels, help desk resets, emergency bypasses, and stale privileged accounts that still accept weak authentication. NHIMG’s research shows that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, which is a reminder that identity failure is usually broader than one user login. That same pattern appears in workforce environments when access governance is inconsistent across endpoints, VPNs, and admin portals. In practice, many security teams discover their MFA gaps only after an incident forces them to examine recovery paths, not through planned assurance.
How It Works in Practice
A workable NIS2 implementation starts by segmenting workforce access into ordinary user logins, privileged access, and high-risk remote sessions. For standard users, organisations should require MFA at sign-in to the workstation, VPN, or equivalent remote access layer. For privileged users, current guidance suggests phishing-resistant methods wherever practical, especially for admin consoles, cloud control planes, and sensitive operational tooling. The ENISA Threat Landscape is useful context here because the threat profile in critical sectors is driven by credential theft, social engineering, and session hijacking, not just password guessing.
Implementation should be built around policy tiers rather than a single enterprise-wide rule. That means different MFA strength requirements for different roles, with privileged access management for admins, contractors, and break-glass accounts. Security teams should also document how MFA interacts with:
- Emergency access and disaster recovery accounts
- Help desk identity verification and reset procedures
- Shared workstations, kiosk devices, and plant-floor terminals
- VPN, SSO, and privileged session elevation flows
- Device trust and conditional access checks
NIS2 compliance is usually stronger when MFA is paired with audit evidence: policy baselines, exceptions, test results, and recovery drills. NHIMG’s Ultimate Guide to NHIs — Regulatory and Audit Perspectives is relevant here because it reinforces the broader point that governance failures often sit in lifecycle controls and exception handling, not just the primary authentication factor. These controls tend to break down when emergency accounts are excluded from normal review cycles because the bypass path becomes the least governed path.
Common Variations and Edge Cases
Tighter MFA often increases operational friction, so organisations have to balance phishing resistance against uptime, support burden, and field conditions. That tradeoff is especially visible in industrial, healthcare, and transport environments where shared devices, offline operations, or legacy systems limit modern authenticators. Best practice is evolving, and there is no universal standard for every edge case, so the key is to justify compensating controls where a stronger method cannot be deployed immediately.
One common exception is break-glass access. It should exist, but it should be rare, monitored, time limited, and tested under realistic recovery scenarios. Another is legacy protocol access, where MFA may not be technically possible at the protocol layer. In those cases, organisations should wrap the access path with stronger network controls, session monitoring, and privileged access gates instead of treating the exception as acceptable by default. For sector operators, the legal baseline is the EU NIS2 Directive, but the operational test is whether an attacker can still reach the same assets through a weaker route. NHIMG’s Microsoft Midnight Blizzard breach remains a useful reminder that identity controls fail fastest where recovery and privileged workflows are underdesigned.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack surface, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the technical controls, and NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIS2 | Article 21 | Requires risk-based cybersecurity measures, including access control and MFA. |
| NIST CSF 2.0 | PR.AA-1 | Identity proofing and authentication support stronger workforce access controls. |
| NIST Zero Trust (SP 800-207) | IL-2 | Zero Trust requires continuous verification for workforce sessions and privileged access. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Workforce fallback and privileged paths often mirror NHI authentication weaknesses. |
| CSA MAESTRO | GOV-02 | Agent and workload governance principles help separate strong identity controls from weak bypass flows. |
Review shared, emergency, and service access paths for weak authentication and remove standing exceptions.
Related resources from NHI Mgmt Group
- How should financial firms implement phishing-resistant MFA to satisfy NYDFS Part 500 requirements?
- How should organisations think about NIST assurance requirements when linking proofing to credential issuance?
- How should organisations balance export flexibility with identity governance requirements?
- How do organisations balance regional compliance requirements with scalable identity operations?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org