Compliance is not something an organisation can simply “ensure” in five steps. Requirements differ by sector, jurisdiction and risk profile; they also change over time. What organisations can do is build a repeatable way to identify obligations, apply appropriate controls and demonstrate that those controls are working.
That is especially important in complex environments. A multinational organisation may operate under several national implementations of the same directive. Responsibilities for security may be shared across IT, security, facilities, HR and local site teams. And while digital risk often leads the conversation, physical access to critical systems, sensitive areas and operational assets must be governed just as deliberately.
The five steps below are a practical framework for strengthening compliance. They do not replace legal advice or a formal audit. They help organisations establish the governance, evidence and continuous oversight needed to manage regulatory expectations at scale.
Step 1: Map your regulatory obligations and scope
Start by establishing what applies to your organisation. This goes beyond listing regulations such as NIS2 or DORA. You need to understand which legal entities, countries, services, locations, assets and critical processes fall within scope — and which teams own them. For example, a European directive may be implemented differently from one country to another. Sector-specific obligations may overlap with broader security, privacy or resilience requirements. In critical infrastructure, the scope may also include the physical environment around the systems that deliver essential services: control rooms, technical spaces, substations, data centres and visitor areas.
A useful outcome is a regulatory inventory that links each relevant requirement to an owner, affected assets and evidence needed to show it is being addressed. Critical infrastructure compliance deserves particular attention here, because the consequences of access-related failures can extend well beyond a single site.
Questions to answer at this stage:
- Which regulations, standards and contractual obligations apply to us?
- Which countries, entities, services and physical locations are in scope?
- Which assets or areas would have the greatest impact if access were compromised?
- Who is accountable for interpreting and meeting each obligation?
Step 2: Assess current controls and the evidence behind them
Once the scope is clear, compare the current state with the requirements. The purpose is not to declare yourself compliant or non-compliant overnight. It is to identify where controls are absent, inconsistently applied, poorly documented or difficult to evidence.
Look beyond whether a control exists. A policy is not sufficient if local teams apply it differently. An access system is not sufficient if nobody can demonstrate who approved an access right, why it was granted or whether it was reviewed. In complex organisations, these gaps often appear at the handovers between departments and between central policy and local operations.
For physical access, assess both the control and the lifecycle around it: how rights are requested, approved, provisioned, changed, reviewed and revoked. Also examine the quality and availability of access-event logs, exception records and reports.
The result should be a gap assessment with clear supporting evidence, not a generic list of improvements. This makes it possible to distinguish a missing control from a control that simply lacks consistent ownership or proof.
Step 3: Prioritise improvements by risk and impact
Not every gap deserves the same response. Prioritise remediation according to the potential impact on people, critical operations, sensitive information and regulatory obligations — rather than according to what is easiest to implement.
This means considering both likelihood and consequence. A weak access review process for a low-risk storage room is different from ungoverned access to a server room, control centre or restricted production area. Dependencies matter too: a physical-access failure can create disruption or exposure even where digital controls are strong.
This risk-based approach aligns compliance work with wider resilience and security governance. In the context of NIS2 compliance, organisations need to be able to explain how security measures address the risks relevant to their critical systems and operations.
Turn the highest-priority gaps into a realistic remediation plan. For each item, define the control objective, accountable owner, required resources, target date and the evidence that will show the change is effective. Some improvements will take time; what matters is that the plan is governed, measurable and actively followed up.
Step 4: Design access controls for consistent governance and auditability
Controls should work in day-to-day operations and stand up to scrutiny. That requires more than installing technology: organisations need documented policies, clear responsibilities and processes that are consistently applied across locations.
For physical access control, a strong governance model normally includes:
- role- or policy-based access rights;
- documented approval and escalation processes;
- timely updates when someone joins, changes role or leaves;
- periodic reviews of access rights, especially for sensitive areas;
- reliable records of access events and exceptions; and
- clear procedures for incidents, overrides and failed controls.
The exact model will vary by organisation, but the objective is consistent: authorised people should have appropriate access for an appropriate period, and the organisation should be able to evidence how that decision was made.
Nedap Access helps organisations apply and manage physical access policies consistently across locations. Integrations with HR and IT systems can support more reliable joiner, mover and leaver processes, while central visibility helps security teams oversee local access decisions. For a broader perspective, see the ultimate guide to enterprise security compliance.
Step 5: Monitor, review and improve continuously
Compliance is an ongoing management process, not the end point of a remediation project. Controls can weaken as organisations change: people move roles, sites are added, contractors are onboarded, systems are integrated and regulations evolve.
Build regular monitoring and review into the operating model. This should include access events, policy exceptions, overdue access reviews, changes to rights and deviations from expected processes. It should also include a periodic check that the regulatory inventory and risk assessment still reflect the organisation’s current footprint.
Reporting should serve two purposes. First, it should give management a usable view of risk, control performance and outstanding actions. Second, it should make audit preparation easier by keeping relevant evidence organised and available, rather than collecting it only when an audit begins.
This is what makes compliance sustainable: a clear line between obligations, controls, accountable owners and evidence — reviewed continuously as the organisation changes.
Why physical access belongs in the compliance conversation
Physical access is sometimes treated as a separate operational topic. In reality, it is part of how organisations protect the environments in which critical systems, information and assets are located. If an individual can enter a server room, control area or restricted facility without appropriate authorisation, the organisation may not be able to demonstrate effective control of the associated risk.
That does not mean every compliance requirement prescribes a specific access control system. It means physical access should be assessed alongside digital, operational and organisational controls. A mature approach connects access policies to people, roles, locations and risk — and produces reliable evidence that those policies are enforced.
For organisations operating across multiple sites or jurisdictions, this consistency is particularly valuable. It reduces dependence on local workarounds, makes exceptions visible and gives central teams the oversight needed to govern access without losing operational flexibility.
Frequently Asked Questions
No. Compliance depends on the specific laws, supervisory expectations, business activities and risk profile that apply to an organisation. These five steps provide a practical structure for building and maintaining a defensible compliance approach, but they do not replace legal interpretation, assurance work or a formal audit.
Identify the jurisdictions in which you operate, your sector, the services you provide and the assets that support them. Then involve legal, compliance and risk specialists to interpret the relevant obligations. For European directives, assess the applicable national implementation as well as the directive itself.
Retain the policies and procedures that govern access, approval records, access-right reviews, logs of access events and exceptions, incident records, and evidence that joiner, mover and leaver processes are working. The exact evidence should follow your organisation’s obligations and risk assessment.
Review frequency should be based on risk. Access to critical or sensitive areas generally requires more frequent review than low-risk access. Rights should also be reassessed whenever a person changes role, leaves the organisation, a contractor’s assignment ends or the risk profile of a site changes.
Physical access may be relevant where it affects the protection and resilience of systems, facilities or assets within scope. The appropriate controls depend on the organisation’s risk assessment and applicable requirements; access control should be considered as part of the wider security and resilience framework, rather than in isolation.