NIS2 Directive – Access Control and Cybersecurity Requirements 2025
The NIS2 law introduces enhanced requirements for cybersecurity and access control for businesses in critical infrastructure. Learn about the new requirements and how to achieve compliance.

The NIS2 Directive introduces enhanced requirements for cybersecurity and access control for businesses within critical infrastructure. Approximately thousands of companies across 11 sectors are covered and must register and comply with the new requirements.
NIS2 primarily focuses on cybersecurity, but also includes requirements for integration of physical and digital security – making modern access control systems like SnapKey a central part of compliance.
What is the NIS2 Directive?
NIS2 (Network and Information Security Directive 2) is the EU's updated directive on network and information security. It replaces the original NIS directive from 2016 with:
- Extended sectors – more industries are now covered
- Stricter requirements – higher security standards and documentation
- Larger fines – up to 10 million EUR or 2% of global turnover
- Personal liability – management can be held personally responsible
Which Sectors are Covered?
NIS2 covers the following 11 sectors:
Transport
Airports, ports, railways, metro, buses
Healthcare
Hospitals, clinics, health authorities
Drinking Water & Wastewater
Water utilities, treatment plants, supply networks
Waste
Waste management and recycling
Digital Infrastructure
Data centers, internet providers, DNS services
ICT Service Management (B2B)
Managed service providers, cloud services
Digital Service Providers
Online marketplaces, search engines, social networks
Post & Parcels
Postal and courier services
Chemical Products
Production and distribution of chemicals
Food
Production, processing, distribution
Manufacturing & Production
Pharmaceuticals, electronics, machinery, vehicles
NIS2 Access Control Requirements
NIS2 sets specific requirements for how businesses administer and document access:
Access Management
Restricted access to critical systems and physical areas based on roles and needs.
Traceability & Logging
All access attempts must be logged with timestamps, user identity, and purpose.
Multi-factor Authentication
Two-factor or multi-factor authentication for access to critical resources.
Time-limited Access
Temporary access for external suppliers and consultants must expire automatically.
Incident Management
Security incidents in access control must be correlated with IT security incidents.
Documentation & Audit
Audit-ready reports and compliance documentation must be available.
Integration
Physical security must be integrated with SIEM, SOC, and other cybersecurity systems.
Role-based Access
Principle of least privilege – users only get access to what's strictly necessary.
Integration of Physical and Digital Security
A central part of NIS2 is the requirement to correlate physical and digital security:
- Access attempts to server rooms must be logged together with network activity
- Alarms from door sensors must trigger IT security protocols
- Physical presence must be validated against digital login events
- Access control systems must integrate with SIEM platforms
SnapKey supports this through API and webhook integrations that send access events in real-time to the company's cybersecurity systems.
How SnapKey Meets NIS2 Requirements
| NIS2 Requirement | SnapKey Solution |
|---|---|
| Access management & role-based access | Centralized administration with user roles and permissions |
| Multi-factor authentication | QR code + PIN, biometrics, eID integration |
| Complete logging & traceability | Encrypted log of all access attempts with timestamps |
| Time-limited access | Automatic key expiration based on time windows |
| Integration with IT security | REST API, webhooks, MQTT for SIEM/SOC systems |
| Documentation & compliance | Automatic audit reports ready for inspection |
| Incident management | Real-time alerts for suspicious activity |
| Secure key management | AES-256 encryption, no possibility of copying |
Consequences of Non-compliance
Companies that don't comply with NIS2 risk:
Fines
- Up to 10 million EUR
- Or 2% of annual global turnover (whichever is higher)
Personal Liability
- Management can be held personally responsible
- Directors and board members are liable
Operational Disruptions
- Orders to shut down systems
- Loss of contracts and business
- Reputational damage
7 Steps to NIS2 Compliance with Access Control
-
Identify covered systems and areas Map all critical IT systems and physical locations
-
Implement role-based access Define user roles and assign permissions based on need
-
Enable multi-factor authentication Implement 2FA/MFA for all critical access points
-
Establish central logging Ensure all access events are logged and stored
-
Integrate with cybersecurity systems Connect access control with SIEM, SOC, and incident management
-
Automate compliance reporting Set up automatic generation of audit reports
-
Train staff and management Ensure understanding of procedures and responsibilities
FAQ
Is my company covered by NIS2?
If your company operates within one of the 11 covered sectors (transport, healthcare, water, digital infrastructure, food, etc.) and meets size criteria (typically medium to large companies with 50+ employees or 10M+ EUR turnover), you are likely covered.
Can SnapKey help with both physical and digital security?
Yes, SnapKey combines physical access control with digital security through API integrations to SIEM systems, meeting NIS2's requirement for correlation between physical and digital security events.
How do I document compliance for authorities?
SnapKey automatically generates audit-ready reports with complete access history, user roles, timestamps, and security events – ready for inspection.
What's the difference between NIS2 and CER?
NIS2 primarily focuses on cybersecurity and IT systems, while the CER directive covers physical resilience and contingency planning. Many companies are covered by both.
Contact Us Today
Is your company ready for NIS2? SnapKey helps you implement modern access control that meets all compliance requirements.
Related articles
Energy Legislation and Access Control – Requirements for Critical Infrastructure
Understand energy legislation requirements for physical security and access control. Learn how SnapKey helps energy companies achieve compliance.
CER Directive – Complete Guide to Critical Infrastructure Compliance
Understand the CER Directive (EU 2022/2557) and learn how SnapKey helps secure your critical infrastructure with advanced access control and compliance.
Access Control for District Heating – Secure Access to Substations and Cabinets
Digital access control for district heating companies. Replace lockboxes with traceable access to heat substations, exchanger stations, and technical rooms.