Not legal advice
This page is an editorial cross-mapping intended to help practitioners translate NIS2 obligations into NHI controls. It is not legal advice and does not substitute for qualified counsel in your jurisdiction. Transposition into national law varies across Member States; always verify against the national transposing act that applies to your entity.
NIS2 in 60 seconds
NIS2 (Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union) is the EU's updated cybersecurity directive, replacing the original NIS Directive of 2016. Transposition deadline was 17 October 2024 for Member States; national enforcement regimes are now active with wide variation in readiness and guidance.
The core structure:
- Identifies "essential" and "important" entities across 18 sectors (energy, transport, banking, health, digital infrastructure, ICT service management, public administration, and more).
- Imposes risk-management obligations under Article 21.
- Imposes incident-reporting obligations under Articles 23 and 24.
- Imposes management-body accountability under Article 20.
- Authorises significant fines and supervisory actions.
Who it applies to
NIS2 scope is much broader than NIS1. Generally, medium-sized and large entities in the listed sectors are in scope (with some exceptions for specific sub-sectors where all-sizes apply). Determining scope for a specific entity requires careful reading of Annexes I and II of the directive and the national transposing act. Qualified counsel is the right arbiter.
Article 21, the cybersecurity risk-management measures
Article 21(2) enumerates ten categories of measures that in-scope entities must take. The directly-NHI-relevant ones:
- (a) policies on risk analysis and information system security
- (d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers
- (e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure
- (h) policies and procedures regarding the use of cryptography and, where appropriate, encryption
- (i) human resources security, access control policies and asset management
- (j) the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications, and secured emergency communication systems within the entity, where appropriate
Mapping Article 21 to NHI controls
| Article 21 measure | NHI control interpretation |
|---|---|
| (a) Risk-analysis policies | NHI risk taxonomy (e.g. OWASP NHI Top 10) embedded in enterprise risk register. Regular NHI-risk assessment as part of information-security governance. |
| (d) Supply-chain security | OAuth integration governance. Third-party NHI inventory. Supplier-credential lifecycle. Post-Salesloft/Drift, this is central: your direct suppliers' NHIs in your environment are in-scope. |
| (e) System acquisition, development, maintenance | Secrets management in CI/CD. Secret scanning. Secure SDLC practices including NHI provisioning patterns. Vulnerability handling for leaked NHI credentials. |
| (h) Cryptography and encryption | Certificate lifecycle management. PKI governance. Key management. Machine identity hygiene. Post-quantum algorithm readiness inventory. |
| (i) Access control and asset management | NHI inventory. Ownership records. Least-privilege enforcement. Periodic access review. This is arguably the single most-central NIS2 requirement for NHI. |
| (j) Multi-factor/continuous authentication | Workload identity federation. Short-lived credentials. MFA for human-proxy NHIs (e.g. personal access tokens). Continuous authentication (behavioural anomaly detection on NHIs). |
Incident reporting
Articles 23 and 24 impose a layered incident-reporting timeline for significant incidents: early warning within 24 hours, incident notification within 72 hours, intermediate and final reports thereafter. "Significant incident" is defined in Article 23(3) and in national transposing acts.
Operational implication for NHI: a compromise traced to an NHI (leaked credential, abused OAuth refresh token, over-privileged service account) that produces significant impact will trigger reporting obligations. Incident-response playbooks should include NHI-specific forensic steps, credential rotation, token revocation, session-termination, audit-log preservation.
Management body accountability
Article 20 makes the management body (boards, executive committees) explicitly accountable for approving risk-management measures and overseeing implementation. Training obligations for management bodies are included. This is a significant shift from NIS1's more operational framing.
Operational implication for NHI: NHI risk and controls should be presented to the management body at the same cadence as other information-security risks, with quantifiable indicators (inventory coverage, orphan rate, credential age). NHI-programme maturity should be a standing item in board-level risk reporting.
Penalties
NIS2 authorises substantial administrative fines, up to €10M or 2% of worldwide annual turnover for essential entities, up to €7M or 1.4% for important entities (higher of the two in each case). Penalties vary by national transposition. Supervisory authorities also have powers to suspend authorisations and, in some regimes, to hold responsible managers personally liable.
The practical implication for NHI programmes: document the risk-based rationale for control choices, keep evidence of continuous improvement, and ensure the programme's coverage of the NHI estate is demonstrable.
Primary sources
- The directive: eur-lex.europa.eu/eli/dir/2022/2555/oj
- The relevant national transposing act for your jurisdiction
- Guidance from your national competent authority (e.g. ENISA at EU level; ANSSI in France; BSI in Germany; NCSC in Ireland)