What is NIS2?

The NIS2 Directive (Network and Information Security) is the most comprehensive EU-wide legislation on cybersecurity to date. It’s designed to improve the cybersecurity of key entities across Europe. NIS2 explicitly requires affected organisations to implement good physical access control as well.

Get NIS2 Compliance Help

NIS2 compliance: what it means for access control in your organization

NIS2 is not another checkbox exercise. It is a binding regulatory framework that holds organizations to a higher standard on cybersecurity and physical security alike. For those responsible for risk, continuity, and compliance, the directive raises a direct question: can you demonstrate that access to your critical systems and spaces is governed, traceable, and controlled? If that answer is uncertain, this page explains where to start.

What NIS2 requires and why access control is central to it

The NIS2 Directive (Network and Information Security Directive 2) is the updated EU regulation designed to strengthen security across essential and important sectors. It replaces the original NIS Directive and expands both its scope and its enforcement. NIS2 requires organizations to implement technical and organizational measures to manage security risks. This includes protecting networks and information systems, but also managing physical access to facilities and infrastructure.

Historically, physical access governance and cybersecurity evolved as separate disciplines, managed through different teams, systems, and reporting structures. NIS2 increasingly treats both as part of the same operational resilience and risk governance challenge.

Physical access control, meaning the ability to define, manage, and audit who can enter which locations, is a direct compliance requirement under NIS2. Organizations that cannot demonstrate centralized oversight of access rights, timely revocation when roles change, and audit-ready reporting are exposed to both regulatory and operational risk.

For a broader perspective on how access management fits within a larger compliance framework, see our guide on enterprise security compliance.

Key Facts About NIS2 Compliance

NIS2 compliance is crucial for organisations with significant financial stakes, as the NIS2 Directive sets out specific monetary penalties for non-compliance. Namely, a maximum fine of at least €10,000,000 or 2% of the global annual revenue (whichever is higher) for essential entities, and a maximum fine of at least €7,000,000 or 1,4% of the global annual revenue (whichever is higher) for important entities.

160K

Estimated number of entities affected by new rules.

10

Core actions to be taken by essential & important entities.

 

Let’s discuss NIS2 Compliance

€10,000,000

Potential maximum fine for non-compliance.

How do I know if my organization falls under NIS2?

NIS2 applies to organizations operating in sectors classified as essential or important. Essential sectors include energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, and public administration. Important sectors include postal services, waste management, chemicals, food, manufacturing, and digital providers.

Size matters too. Organizations with more than 50 employees or an annual turnover above 10 million euros in these sectors typically fall within scope. Member states may also include smaller organizations if they are deemed critical to national infrastructure. If there is uncertainty about scope, a formal assessment against the NIS2 criteria is the appropriate starting point.

What are the NIS2 requirements for physical security and access control?

NIS2 requires organizations to implement risk-based security measures that protect both digital and physical assets. Key requirements include access control, identity management, incident response, business continuity, supply chain security, and regular security assessments. For physical security, organizations must demonstrate that access to buildings, critical infrastructure, and sensitive areas is controlled, monitored, auditable, and aligned with defined security policies.

Key NIS2 requirements related to physical security

  • Identity management and access control – Physical access rights must be assigned, reviewed, and enforced according to the principles of least privilege and separation of duties.
  • Physical protection of critical assets – Organizations must prevent unauthorized access to facilities, infrastructure, and sensitive information.
  • Auditability and logging – Access events and authorization changes should be recorded and available for monitoring and audits.
  • Risk management and governance – Physical security controls must be part of a broader risk management framework.

What cybersecurity measures does NIS2 require?

NIS2 requires organizations to adopt a risk-based cybersecurity framework. Measures include incident handling procedures, business continuity planning, supply chain security, access control, identity management, multi-factor authentication where appropriate, and regular security assessments. Physical access control forms part of these requirements because unauthorized physical access can directly impact the security and resilience of information systems.

What are the penalties for non-compliance with NIS2?

NIS2 introduces significantly stronger enforcement compared to its predecessor. For essential entities, fines can reach up to 10 million euros or 2% of global annual turnover, whichever is higher. For important entities, the maximum is 7 million euros or 1.4% of global annual turnover.

Beyond financial penalties, NIS2 introduces personal liability for senior management. In cases of negligence or repeated non-compliance, national authorities can hold directors personally accountable. This shifts compliance from an IT or security department responsibility to a board-level governance matter.

How to achieve NIS2 compliance with access control

Achieving NIS2 compliance through access control requires a structured approach. Organizations need centralized visibility across all locations and access points, automated provisioning and de-provisioning tied to HR or identity systems, role-based access policies that reflect actual organizational structure, and audit-ready reporting without manual data collection.

For organizations managing critical infrastructure, the requirements extend further. Access to sensitive areas must be governed with precision, and any deviation must be traceable. See how organizations in regulated sectors approach this in our overview of critical infrastructure regulatory compliance.

Ensure your organisation is compliance-ready for NIS2 with Nedap Access

Nedap Access offers comprehensive high-security solutions, to help your organization achieve seamless NIS2 compliance. Here’s how Nedap Access solutions can help:

  • End-to-End Encryption:  Protect sensitive data with robust encryption protocols, in AEOS and Access AtWork®, ensuring that your information is secure at every level.
  • Two-Factor Authentication: Strengthen your access control with built-in two-factor authentication, aligning with NIS2’s multi-component authentication requirements.
  • 802.1x Network Security:  Leverage AEOS’s support for 802.1x, providing secure authentication to prevent unauthorized access to your network.
  • Transparent Mode: Ensure seamless integration with existing systems while maintaining high levels of security and compliance with AEOS and Access AtWork®.

 

Why you should choose Nedap Access for Your NIS2 compliance

Nedap Access helps you with more than just access control—it’s a unified suite of PIAM, on-premises, cloud, and hybrid security solutions all designed to support your organisation’s entire security infrastructure so you can meet NIS2 requirements with:

  • Comprehensive Security: AEOS covers all aspects of physical and logical access control, making it a complete solution for your security needs.
  • Scalability and Flexibility: Easily adaptable to the specific requirements of different industries and organizational sizes.
  • Future-proofness: Stay ahead of regulatory changes with a platform that evolves alongside new directives and standards.

Frequently Asked Questions

Yes. Physical security is explicitly addressed within the NIS2 framework as part of an organization’s overall cybersecurity and resilience strategy. Organizations must demonstrate that physical risks are identified, managed, and mitigated through appropriate security controls.

NIS2 requires organizations to establish and enforce access control policies based on roles, responsibilities, and business needs. Access rights should be regularly reviewed, monitored, and documented to ensure that only authorized individuals can access critical assets and systems.

Organizations can demonstrate NIS2 compliance by implementing documented security policies, maintaining audit trails, conducting regular risk assessments, and ensuring that access rights are managed according to defined governance processes. Evidence of compliance should be available for audits and regulatory reviews.

Non-compliance can result in financial penalties, regulatory scrutiny, operational disruption, and reputational damage. Organizations may also face increased liability if a security incident occurs and inadequate security controls are found to be a contributing factor.

NIS2 requires organizations to take a structured approach to physical security governance. This includes defining policies, assigning responsibilities, maintaining audit records, and ensuring that physical security controls support the organization’s overall risk management strategy.