NIS2 MFA & Secured Communications (Article 21(2)(j)): The Highest-Impact Control
NIS2 Article 21(2)(j) calls for multi-factor authentication and secured communications. MFA is the single most effective control against the account compromise behind most breaches, here's how to get it right.
Article 21(2)(j) asks for “the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications, and secured emergency communication systems.” Of all ten measures, MFA is the one with the clearest, best-evidenced payoff: it stops the large majority of account-takeover attacks that follow stolen or phished passwords.
This is guidance, not legal advice. National transposition varies (Italy applies NIS2 through D.Lgs. 138/2024 under the ACN), so verify your exact obligations with your supervisory authority.
Get MFA right, everywhere it matters
The measure is only as good as its coverage. Priorities:
- Remote access and VPN, the front door for attackers.
- Email and identity provider, compromise here cascades everywhere.
- Administrative and cloud accounts, highest blast radius; these should use the strongest factors (hardware keys / FIDO2 where possible).
- Anything internet-facing that holds or controls sensitive data.
Two common gaps: SMS-only MFA (better than nothing, but phishable, prefer authenticator apps or hardware keys for high-value accounts), and partial coverage where one forgotten legacy system or service account becomes the way in. Aim for “MFA on by default, exceptions documented and minimised.”
Secured communications
The communications part is often overlooked. In practice: use encrypted channels for sensitive conversations (the cryptography measure overlaps here), and have a secured, out-of-band way to communicate during a crisis, because if your primary systems are compromised, you can’t trust them to coordinate the response. A simple pre-agreed fallback channel and contact tree satisfies the intent.
How this connects to the rest
MFA is also your strongest mitigation when a vulnerability can’t be patched immediately: if an exposed system can’t be fixed today, strong authentication and segmentation reduce what an attacker can do with it. Knowing which exposed systems are running actively-exploited vulnerabilities, what SentriKat tracks, tells you exactly where to prioritise both patching and compensating controls like MFA.
Start here
Audit where MFA is and isn’t enforced, turn it on for remote access, email, identity, and admin/cloud accounts first, move high-value accounts to app-based or hardware factors, and agree one out-of-band crisis comms channel. This is among the fastest risk reductions available to you.
Want the full per-domain picture? The free NIS2/DORA readiness check gives you an indicative gap analysis across all ten measures in ~5 minutes.
Ready to automate your vulnerability management?
Deploy SentriKat on-premises in minutes. Track CISA KEV vulnerabilities, generate NIS2 compliance reports, and protect your infrastructure.
Request a Demo