By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
VerifiedLast reviewed 5 August 2026 by the HumanAudit Inc. editorial team.Corrections logEditorial policy
On this page
  1. NIS2 overview
  2. Who it applies to
  3. Article 21 measures
  4. NHI control mapping
  5. Incident reporting
  6. Management accountability
  7. Penalties
  8. FAQ

Not legal advice

This page is an editorial cross-mapping intended to help practitioners translate NIS2 obligations into NHI controls. It is not legal advice and does not substitute for qualified counsel in your jurisdiction. Transposition into national law varies across Member States; always verify against the national transposing act that applies to your entity.

NIS2 in 60 seconds

NIS2 (Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union) is the EU's updated cybersecurity directive, replacing the original NIS Directive of 2016. Transposition deadline was 17 October 2024 for Member States; national enforcement regimes are now active with wide variation in readiness and guidance.

The core structure:

  • Identifies "essential" and "important" entities across 18 sectors (energy, transport, banking, health, digital infrastructure, ICT service management, public administration, and more).
  • Imposes risk-management obligations under Article 21.
  • Imposes incident-reporting obligations under Articles 23 and 24.
  • Imposes management-body accountability under Article 20.
  • Authorises significant fines and supervisory actions.

Who it applies to

NIS2 scope is much broader than NIS1. Generally, medium-sized and large entities in the listed sectors are in scope (with some exceptions for specific sub-sectors where all-sizes apply). Determining scope for a specific entity requires careful reading of Annexes I and II of the directive and the national transposing act. Qualified counsel is the right arbiter.

Article 21, the cybersecurity risk-management measures

Article 21(2) enumerates ten categories of measures that in-scope entities must take. The directly-NHI-relevant ones:

  • (a) policies on risk analysis and information system security
  • (d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers
  • (e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure
  • (h) policies and procedures regarding the use of cryptography and, where appropriate, encryption
  • (i) human resources security, access control policies and asset management
  • (j) the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications, and secured emergency communication systems within the entity, where appropriate

Mapping Article 21 to NHI controls

Article 21 measureNHI control interpretation
(a) Risk-analysis policiesNHI risk taxonomy (e.g. OWASP NHI Top 10) embedded in enterprise risk register. Regular NHI-risk assessment as part of information-security governance.
(d) Supply-chain securityOAuth integration governance. Third-party NHI inventory. Supplier-credential lifecycle. Post-Salesloft/Drift, this is central: your direct suppliers' NHIs in your environment are in-scope.
(e) System acquisition, development, maintenanceSecrets management in CI/CD. Secret scanning. Secure SDLC practices including NHI provisioning patterns. Vulnerability handling for leaked NHI credentials.
(h) Cryptography and encryptionCertificate lifecycle management. PKI governance. Key management. Machine identity hygiene. Post-quantum algorithm readiness inventory.
(i) Access control and asset managementNHI inventory. Ownership records. Least-privilege enforcement. Periodic access review. This is arguably the single most-central NIS2 requirement for NHI.
(j) Multi-factor/continuous authenticationWorkload identity federation. Short-lived credentials. MFA for human-proxy NHIs (e.g. personal access tokens). Continuous authentication (behavioural anomaly detection on NHIs).

Incident reporting

Articles 23 and 24 impose a layered incident-reporting timeline for significant incidents: early warning within 24 hours, incident notification within 72 hours, intermediate and final reports thereafter. "Significant incident" is defined in Article 23(3) and in national transposing acts.

Operational implication for NHI: a compromise traced to an NHI (leaked credential, abused OAuth refresh token, over-privileged service account) that produces significant impact will trigger reporting obligations. Incident-response playbooks should include NHI-specific forensic steps, credential rotation, token revocation, session-termination, audit-log preservation.

Management body accountability

Article 20 makes the management body (boards, executive committees) explicitly accountable for approving risk-management measures and overseeing implementation. Training obligations for management bodies are included. This is a significant shift from NIS1's more operational framing.

Operational implication for NHI: NHI risk and controls should be presented to the management body at the same cadence as other information-security risks, with quantifiable indicators (inventory coverage, orphan rate, credential age). NHI-programme maturity should be a standing item in board-level risk reporting.

Penalties

NIS2 authorises substantial administrative fines, up to €10M or 2% of worldwide annual turnover for essential entities, up to €7M or 1.4% for important entities (higher of the two in each case). Penalties vary by national transposition. Supervisory authorities also have powers to suspend authorisations and, in some regimes, to hold responsible managers personally liable.

The practical implication for NHI programmes: document the risk-based rationale for control choices, keep evidence of continuous improvement, and ensure the programme's coverage of the NHI estate is demonstrable.

Primary sources

  • The directive: eur-lex.europa.eu/eli/dir/2022/2555/oj
  • The relevant national transposing act for your jurisdiction
  • Guidance from your national competent authority (e.g. ENISA at EU level; ANSSI in France; BSI in Germany; NCSC in Ireland)

Frequently asked questions

Does NIS2 mention non-human identities?

No. NIS2 does not use the term. Its obligations on access control policies, asset management, supply-chain security and incident handling apply to machine credentials in substance, because a service account or API key with production reach is both an access-control matter and a supply-chain matter. The mapping is derived rather than stated.

What does NIS2 require for identity security?

In substance: policies on access control and asset management, multi-factor or continuous authentication where appropriate, supply-chain risk management covering direct suppliers, and incident reporting within defined timeframes. For non-human identities the practical translation is an inventory, scoped and rotated credentials, review of third-party integrations, and the ability to attribute an incident to a specific credential quickly enough to meet reporting deadlines.

Is NIS2 in force?

The directive is in force at EU level and obligations apply through national transposition, which has progressed at different rates across member states. Check the transposing law in each jurisdiction where you operate rather than relying on the directive text alone, because scope determinations and penalties are set nationally.

Need this mapped to an audit you actually face?

Frameworks tell you what good looks like. Evidence is what an auditor asks for. HumanAudit runs ISO/IEC 42001 and NHI readiness reviews that test whether your evidence would hold, including agent delegation-chain testing.