Because NIS2 expects operators to manage cyber risk in a way they can demonstrate. If third-party access is not approved, time-limited and auditable, the organisation cannot easily show that it controlled supply-chain and access-risk exposure in a defensible way.
Why remote vendor access draws NIS2 scrutiny in manufacturing
Remote vendor access is not just a convenience issue in manufacturing, it is a controllable route into operational systems, maintenance tooling and the wider supplier chain. Under NIS2, the pressure comes from demonstrable governance: organisations must be able to show who accessed what, when, under whose approval, and with what limits.
What makes vendor access a compliance problem, not just an IT problem
Manufacturing environments often depend on contractors, equipment suppliers and integrators for support, patching and troubleshooting. That makes access governance part of operational resilience, because a vendor session can reach production assets, engineering workstations or remote support platforms. If access is shared, persistent or loosely supervised, the organisation cannot easily prove that it controlled exposure in a defensible way.
That is why EU NIS2 Directive matters here: the directive pushes entities toward evidence-based cyber risk management, and vendor access is one of the clearest places where controls must be visible rather than assumed. In practice, the business question becomes whether the manufacturer can demonstrate approval, scope, timing and traceability for every external session.
Which control failures create the most pressure
The compliance pressure rises fastest when vendor access is not time-boxed, not tied to a named sponsor, and not recorded at session level. Shared remote support accounts, standing VPN access, unmanaged break-glass pathways and unclear offboarding all make audit evidence weak. In manufacturing, those weaknesses are more serious because they can reach OT-adjacent systems where uptime, safety and change control matter together.
That is also why remote access often becomes a third-party risk issue rather than a pure network issue. The organisation is responsible not only for connectivity, but for access governance, authentication strength, session oversight and revocation discipline across suppliers and maintenance partners.
- Third-Party, B2B and Contractor Access Guide is the most direct internal reference for sponsorship, least privilege, time limits and third-party access reviews.
- Remote Access Identity Guide supports the operational side of secure remote entry, including MFA, device posture and retiring dormant VPN accounts.
- OT and ICS Identity and Access Guide is useful where vendor access reaches industrial systems, shared accounts or segmentation-dependent environments.
Risk and Threat Considerations
Remote vendor access concentrates trust in a small number of pathways, so a single weak credential, stale account or overbroad remote-support tool can create outsized exposure. In manufacturing, that exposure can extend from IT admin surfaces into plant-side systems, which makes the risk both operational and regulatory.
Failure mechanism: External access is left standing, insufficiently scoped or poorly logged, so the organisation cannot prove that the session was approved, time-limited and attributable. That creates both an attack path and an audit gap, especially if credentials or remote support tooling are reused across sites.
Impact: A compromised vendor path can enable unauthorised changes, lateral movement or production disruption, while also leaving the manufacturer unable to demonstrate the access controls NIS2 expects. The result is not only higher breach risk, but a weaker compliance position during supervisory review or incident investigation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the technical controls, while NIS2 and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIS2 | GV.RM-01 — Risk Management Strategy | NIS2 risk governance drives demonstrable control over third-party access exposure. |
| Recommendation — Document and enforce a risk-based approval model for external remote access. | ||
| NIST SP 800-53 Rev 5 | AC-20 — Use of External Systems | Remote vendor access is controlled use of external parties and systems. |
| AU-2 — Event Logging | Auditability of vendor sessions depends on recorded access and activity evidence. | |
| Recommendation — Restrict external use conditions and require explicit authorization for vendor access. Log vendor logins, approvals and privileged actions for later review. | ||
| ISO/IEC 27001:2022 | A.5.19 — Information security in supplier relationships | Vendor access is a supplier relationship control problem with compliance impact. |
| Recommendation — Define supplier access requirements, ownership and review obligations in contracts. | ||
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | Cloud and remote vendor access need identity governance, approval and revocation controls. |
| Recommendation — Apply IAM controls to external identities, session limits and access revocation. | ||
Practitioner Guidance
What to verify: Confirm that every vendor session is tied to a named third party, a named internal sponsor, a documented purpose and a defined expiry. If any of those four items is missing, treat the access path as an exception, not as normal operations.
What good looks like: Vendors use unique identities, MFA, time-bound approval and session recording, and access is removed when support ends or the contract changes. The evidence trail should let an auditor reconstruct the approval chain and the exact session history without relying on informal tickets or email.
Practitioner takeaway: For NIS2, the real test is not whether remote vendor access exists, but whether the manufacturer can prove it was intentionally granted, narrowly bounded and fully traceable throughout its lifecycle.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org