← Guide

What belongs in access control under NIS2?

Measure (i) of the NIS2 duty of care is about personnel, access control and assets. The core in four agreements: staff only get access to what they need for their work, access is withdrawn on the day someone leaves through a fixed checklist, at least once a year you check who can still reach what, and there is a register of issued laptops, phones and access tokens. Old accounts of people who have left are a classic way in.

Access control is rarely exciting and therefore often neglected. Yet a substantial share of incidents comes in through an account that should no longer have existed, belonging to someone who left months ago.

What does need-to-know access mean?

That not everyone has to be able to reach everything. The financial records, the personnel files and the management environment are for the people who work with them, not for the whole company because that shares more easily. Practically: grant access based on roles rather than per person, and clean up rights nobody uses any more.

This does not only limit misuse from within; above all it limits the damage when one account is taken over.

What has to happen when someone leaves?

Everything closed, the same day: email, VPN, cloud applications, management portals and the building pass. The only way that happens reliably is an offboarding checklist tied firmly to your HR process, so it does not depend on anyone's memory.

Do not forget indirect access: shared passwords the departing employee could reach belong on the list too.

Why a yearly access review?

Because access creeps. People change roles and keep their old rights, temporary access is never withdrawn, and after three years half the company can reach something nobody remembers granting. Going through who has access per system at least once a year, cleaning up whatever no longer fits, and recording the outcome: that report is the evidence customer audits ask for.

Do I have to screen staff?

For critical positions that is sensible and increasingly a contract requirement: a certificate of conduct or a reference check for administrators and others with broad access. Record in your hiring process which roles require screening, and the question on a questionnaire can be answered in one sentence.

What do I do about shared accounts?

Shared accounts are the point where access control quietly stops working: if five people use the same account, there is no telling afterwards who did what, and the password walks out of the door when one of them leaves. So the rule is one account per person.

For the cases where that genuinely is not possible, such as an old application with a single licence or a social media channel, the way out is a password vault holding the password and a record of who can reach it. You still have no traceability per action, but you do have it per person, and you can rotate the password in one move when someone leaves.

And my IT provider's access?

Almost everyone forgets that one, while it is the heaviest access in the company: administrative rights on everything, often permanent, and managed by a party outside your walls. Customers ask about this more and more specifically, because an attack on a managed service provider hits all of its customers at once.

What you want to be able to say about it: how many accounts your provider has at your place, that those accounts are personal rather than shared, that MFA is on them, and that access is only active when there is work rather than all year round. Fold this into the agreements you make with your own suppliers anyway.

What does this mean for home working and personal devices?

For home working little changes in substance: the same access, the same MFA, the same rules. What is added is the network around it, and the practical requirement is that access to company systems runs over a managed connection rather than over any public wifi that happens to be there.

Personal devices are the harder half. A private laptop holding company mail sits outside your management: you cannot enforce encryption on it and you cannot wipe it when someone leaves. So pick a line and write it down. Either company devices for company work, or personal devices allowed under conditions, with at minimum a passcode, disk encryption and the agreement that company data may be wiped remotely. Both answers can be defended on a questionnaire; no answer cannot.

See also the ten duty of care measures in context.

Getting started yourself

Take the free scan: 39 questions in plain language, about ten minutes, no account needed. You will know where you stand and what deserves attention first, and you can share the result with your customer as a passport.

Already have a questionnaire on your desk? With Pro (€39 per month, excl. VAT) you upload it and have the answers filled in from your own scan and evidence. You review it and send it back.

Updated on 5 August 2026