Glossary · NIS2

Multi-Factor Authentication (MFA)

A login security method requiring more than one form of verification, required under NIS2 Article 21(j).

Explained in depth: The 10 NIS2 security requirements

Multi-factor authentication requires users to prove their identity with at least two independent factors: something they know (a password), something they have (a hardware key or authenticator app), or something they are (biometrics). Article 21(j) requires entities to use MFA or continuous authentication solutions "where appropriate", along with secured voice, video, and text communications and secured emergency communication systems. "Where appropriate" is a risk-based qualifier, not an opt-out. For remote access, administrator accounts, and cloud services, authorities and auditors will expect MFA as a baseline. Phishing-resistant methods (FIDO2/passkeys, hardware tokens) are increasingly regarded as best practice for high-privilege access.

Why it matters

MFA is one of the cheapest and most effective Article 21 measures, and its absence on critical systems is one of the easiest findings for an auditor to make. It is also a common requirement in cyber insurance, so the work usually pays off twice.

Used in

See also

← All glossary terms