CyberTRIZPEDIA

Multi-Factor Authentication Enforcement

Control
NIS2-A21-002
Regulation
NIS2
Category
technical
Priority
critical
Frequency
quarterly
Type
technical

What this control requires

Deploy and enforce multi-factor authentication for all network access, remote access, privileged access, and access to critical systems. Implement phishing-resistant MFA (FIDO2/hardware tokens) for privileged users. Conduct quarterly MFA coverage audit.

Other NIS2 controls