
Organizations working toward NIS2 compliance can make measurable progress on credential security without buying new infrastructure, and the work starts with making access visible, revocable, and reviewable. Credentials appeared among the data compromised in 28% of breaches analyzed in Verizon’s 2026 Data Breach Investigations Report, which makes account controls a natural early target inside any risk-based programme. The steps below rank seven credential controls by effort and cost, and they apply whether or not a final scope determination under the directive is complete.
What does NIS2 ask of credential security?
NIS2 Article 21 connects credential security to five specific measures: basic cyber hygiene practices and training, access-control policies, human resources security, asset management, and procedures that evaluate whether controls actually work. Those five measures leave the choice of specific products and policies to each entity’s own risk assessment. A credential-security programme answers four questions in practice: who has access, why they have it, how access gets removed, and how the organization proves the control works.
Risk varies by account category. Privileged accounts carry the highest impact if compromised, and shared credentials create attribution problems when something goes wrong. Service identities, the non-human accounts used by applications and automation, often go unmanaged because no one treats them as a personal responsibility. An inventory, a named owner, and a review cycle cover this starting work. Broader identity architecture can follow later.
Does NIS2 require MFA and stronger access controls?
Article 21(2)(j) lists multi-factor authentication (MFA) or continuous authentication solutions as a measure to apply where appropriate, leaving each entity to judge where the risk justifies the control. That wording scales MFA to specific systems rather than applying it as a blanket requirement on every account. Externally exposed applications, remote network access, and privileged administration carry the highest risk of credential-based compromise and earn MFA first.
Article 21 also directs entities to weigh implementation cost when judging proportionality, which gives smaller teams a defensible reason to sequence a rollout instead of deploying everywhere at once. The remediation gap between control types supports that sequencing. In Verizon’s 2026 analysis of 7,513 third-party cloud MFA exposure findings, half were resolved within one month; weak-password and permission-misconfiguration findings took nearly eight months to reach the same point.
Who has to comply with NIS2?
NIS2 generally applies to medium-sized and large entities across 18 critical sectors identified by the European Commission. A specific organization’s scope depends on sector, size, and national transposition, and that determination belongs with legal counsel and official guidance. Credential visibility and control deliver the same practical value whether that determination is finished or still in progress, and the seven controls below apply either way.
7 low-cost credential-security steps, ranked by priority
The Credential Security Starter Stack below sequences seven credential controls by effort and cost, and lists the first action and the evidence to retain for each. It offers a prioritized starting point; a full risk assessment and legal review remain the basis for any compliance determination.
Row 1: Inventory privileged accounts
Build a list of every privileged account across directories, cloud consoles, and infrastructure. Assign a named owner to each entry. Evidence to retain: the inventory itself, with owner and last-review date.
Row 2: Disable dormant accounts
Flag any privileged or shared account that has not been used in a defined window and disable it. Evidence to retain: a list of accounts disabled, with the date and the reviewer.
Row 3: Enforce MFA on high-exposure systems
Apply MFA first to externally exposed applications, remote access, and privileged administration, then expand inward as proportionality allows. Evidence to retain: MFA coverage report by system category, with rollout date.
Row 4: Move shared credentials into a managed vault
Shared credentials are a governance problem before they are a technical one. A password dropped into a chat thread or a spreadsheet has no clear owner, no selective revocation path, and no record of who used it or when. When a contractor engagement ends, removing their individual account does nothing to a shared admin password they knew, which stays valid outside the organization until someone rotates it. Deprovisioning must pair with rotation of every secret that a person could access. Evidence to retain: vault entries with named users, rotation log, and a permission-history record.
Row 5: Build an access matrix by role
Map each role to the systems and permissions it needs, and remove standing access that falls outside that mapping. Evidence to retain: the role-to-permission matrix and the exception list, with reviewers and dates.
Row 6: Run credential-hygiene training
Cover credential strength matched to system risk, rotation after exposure or a role change, and removal of default vendor passwords before deployment. Evidence to retain: training completion log and the policy version taught.
Row 7: Isolate and rotate service-account secrets
A CI/CD pipeline token left in a configuration file or pipeline variable is readable by anyone who can edit that configuration, and it commonly outlives the employee who generated it. Isolate it in its own vault entry, owned by the platform team rather than an individual, and rotate it on a schedule. Evidence to retain: vault entries for service credentials, rotation timestamps, and named ownership.
What evidence do auditors actually look for?
Most teams skip proving these controls work: a policy with no log, no review date, and no exception record will not satisfy an auditor. Building that evidence trail as each control goes live, rather than reconstructing it before an audit, keeps the work proportional to the size of the team doing it. For most constrained teams, credentials are the fastest place to produce visible, defensible progress: start with the inventory, disable what is dormant, enforce MFA where exposure is highest, and get shared secrets out of chat and spreadsheets.
FAQ
Does NIS2 require MFA on every account?
Article 21(2)(j) lists multi-factor authentication or continuous authentication solutions as a measure to apply where appropriate, leaving each entity to judge where the risk justifies the control. Most organizations apply MFA first to externally exposed applications, remote access, and privileged administration.
Who has to comply with NIS2?
NIS2 generally applies to medium-sized and large entities across 18 critical sectors identified by the European Commission. A specific organization’s scope depends on sector, size, and national transposition, and a final determination should come from legal counsel and official guidance.
Where should a constrained team start on NIS2 credential security?
Start with an inventory of privileged accounts, disable dormant entries, enforce MFA on high-exposure systems, and move shared credentials out of chat and spreadsheets into a managed vault with named owners and rotation logs.
This article summarizes reporting from helpnetsecurity.com.
