What could go wrong, organised.
Risk taxonomies give you a shared vocabulary for what can fail. Use them to structure risk registers, audit scope, and control coverage.
OWASP NHI Top 10 (2025)
The most-used NHI risk taxonomy. Published by OWASP's dedicated working group with Astrix co-sponsorship. Ten risks from improper offboarding through human-use-of-NHI. Our walkthrough + self-audit.
Read the walkthrough →CSA State of NHI Security
The Cloud Security Alliance's annual research: enterprise NHI survey data, programme maturity observations, and baseline best-practice guidance.
Read the summary →How to build it right, the open standards.
Architecture frameworks for workload identity. This is where the static-credential-replacement story gets concrete.
SPIFFE & SPIRE
Secure Production Identity Framework For Everyone (SPIFFE) and its reference implementation SPIRE. The open specification for workload-bound identity, SVIDs, SPIFFE IDs, trust domains, underneath much of the industry's zero-trust workload story.
Deep dive →IETF WIMSE
Workload Identity in Multi-System Environments. The IETF working group standardising workload identity at the protocol level. Active drafts on architecture, service-to-service, and workload-to-service patterns. Where the next generation of workload identity is being formalised.
Read the summary →What regulators expect, mapped to NHI.
Three major regulatory regimes with explicit or implicit NHI obligations. We cross-map each to specific NHI controls so compliance leaders can produce evidence.
NIS2 × NHI
EU Directive 2022/2555. Applies to essential and important entities across 18 sectors. Requires ICT risk management, access control, and incident-response capabilities, all of which translate to specific NHI control expectations.
See the mapping →DORA × NHI
Digital Operational Resilience Act (Regulation EU 2022/2554). Applies to financial entities (banks, insurers, investment firms, crypto-asset service providers). ICT security requirements map directly to NHI inventory, rotation, and third-party governance.
See the mapping →EU AI Act × NHI
Regulation EU 2024/1689. High-risk AI systems (Annex III, enforced 2 August 2026) require technical documentation, risk management, and human oversight, all with NHI implications, especially for agentic AI deployments.
See the mapping →Which framework when
A quick decision tree: use OWASP NHI Top 10 to structure risk registers and audit checklists. Use SPIFFE/SPIRE and WIMSE when designing workload-identity architecture. Use CSA as programme-maturity benchmarking. Use NIS2 / DORA / EU AI Act when producing evidence for regulators. None of them are exclusive; mature programmes use several simultaneously.
From our team at HumanAudit
From understanding NHI risk to documented compliance
This hub is free and vendor-neutral. When you need audit-ready documentation, our two commercial sister sites publish the templates compliance and security teams attach to their audit files.