Free practical guide

NIS2 and identity management

How to fulfill NIS2 Art. 21 requirements for authentication and access control with a modern identity provider. Includes a 90-day plan and checklist for SMEs.

NIS2-PracticalGuide_Identity 32 pages
Updated: February 2026

What you will learn in this whitepaper

32 pages of practical knowledge tailored to SMEs.

NIS2 duties for IAM: Which Art. 21 controls directly affect your identity management.

MFA duty in detail: Which methods really protect and how passkeys should be used strategically.

Audit-trail requirements: Which logs, retention periods and evidence auditors expect.

EU hosting and data sovereignty: Why IdP location and governance are relevant for compliance.

90-day implementation plan: Step-by-step rollout for teams with limited resources.

Who is this whitepaper for?

Practical knowledge for teams that must implement and prove NIS2 readiness.

CTO / IT leadership

Plan technical NIS2 implementation and prioritize identity infrastructure.

Executive management

Understand liability risk, approve budgets and accelerate decisions.

Compliance

Build audit readiness and robust evidence for external reviews.

A look into the guide

8 chapters from impact analysis to concrete implementation.

1NIS2 overview: what changes for SMEs
2Art. 21: the 10 risk-management controls
3Authentication and access control (lit. i + j)
4MFA duty from TOTP to passkeys
5Audit logs, forensics and evidence capability
6EU hosting as a compliance factor
7Implementation plan: IAM remediation roadmap
8Checklist: authentication under NIS2

Implement directly instead of only reading

Set up MFA, SSO and audit logs directly in your identity flow.

Start for free