Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Which matters more under NIS2, access approval or…
Governance, Ownership & Risk

Which matters more under NIS2, access approval or access evidence?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

Both matter, but evidence is what survives audit and incident scrutiny. If a team cannot show who had access, for how long, and which assets were affected, then approval alone is not enough to demonstrate that the control was operating as intended.

Why access approval is necessary but not sufficient

Approval answers the policy question, who was allowed to have access. Under NIS2, that is only half the control story. What matters in practice is whether the organisation can prove the access existed, was limited, and was removed or changed when it should have been, because operational resilience depends on evidence, not intention.

An approval record is a starting point, but it does not show whether the entitlement was actually provisioned, whether it was overbroad, whether it remained active after the business need ended, or whether a shared or privileged account was involved. That gap is why access approval by itself rarely settles audit, incident, or management scrutiny.

Well-run access governance therefore treats approval as the authorisation to grant access, not as proof that access control worked. The control is only convincing when the approval can be tied to the actual account, role, privilege, resource, and time period in question.

Why access evidence is the stronger proof under NIS2

Evidence shows who had access, when they had it, what they could reach, and whether that access was appropriate for the period under review. That is the material proof auditors, investigators, and incident responders need when they reconstruct a control decision or test whether a security measure was operating as intended.

This is especially important where access is dynamic, temporary, or delegated. If access can be granted, extended, or revoked quickly, the approval trail alone may miss the real state of the environment. Evidence from identity systems, access reviews, logs, and asset records is what closes that gap.

NIS2 is a regulatory framework that expects organisations to demonstrate effective security governance, and that makes contemporaneous records more persuasive than retrospective assurances. The practical test is whether you can reconstruct access history for a person, service, or privileged role without relying on memory or manual reconstruction.

What auditors and responders will ask for first

In an audit or incident, the first question is rarely “was this approved?” It is more often “who actually had access, for how long, and to which assets?” That is why organisations should be able to produce evidence showing account ownership, entitlement scope, date ranges, and the business justification that applied at the time.

For NIS2-facing controls, the strongest evidence usually comes from a combination of access request records, entitlement snapshots, recertification results, and system logs. If those sources disagree, the discrepancy itself becomes the issue, because it suggests the approval process and the live environment are not aligned.

That is also where broader control mapping helps. Ultimate Guide to NHIs, Regulatory and Audit Perspectives is useful for showing how access governance, audit trails, and recertification support a defensible control posture, while the Identity Security Regulatory Map helps teams connect those records to NIS2 and adjacent regulatory expectations.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-2 — Event LoggingAccess evidence depends on auditable records of who accessed what and when.
AC-2 — Account ManagementThe question centers on proving approved access was provisioned and removed correctly.
Recommendation — Retain access logs and review them to reconstruct entitlement use and changes. Track account lifecycle events so approvals map to actual active access.
ISO/IEC 27001:2022A.5.15 — Access controlNIS2 evidence aligns with documenting and enforcing access control decisions.
A.8.15 — LoggingLogs provide the evidence needed to show access history and control operation.
Recommendation — Document and enforce access decisions so they can be demonstrated during audit. Enable logging that preserves access history and supports retrospective review.

Practitioner Guidance

What to verify: Make sure every approved access path can be matched to a live account or entitlement record, a start and end date, and an owner who can explain why it existed. If you cannot reconcile approval to actual access, treat that as a control weakness rather than an administrative nuisance.

What good looks like: The organisation can produce a clean chain from request to approval to provisioning to review to revocation, with evidence retained in a way that survives an incident review. The best signal is not a perfect approval workflow, but a workflow that leaves enough trace to reconstruct access after the fact.

Common mistake: Teams often keep approval emails or ticket states and assume that is sufficient. Under scrutiny, that is weak because it proves a decision was made, not that access was correctly scoped, applied, and removed.

Practitioner takeaway: Under NIS2, approval is necessary governance evidence, but access evidence is what proves the control actually operated. If the live access state cannot be reconstructed from records, the approval record alone will not carry the case.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org