Datawiza
Back to blog
Published July 20, 2026Blog

NIS2 and MFA: What Article 21 Requires, Who Must Comply, and How to Close the Legacy Gap

NIS2 MFA abstract feature image
Table of contents

NIS2 is one of the clearest MFA frameworks because it names the control directly. Article 21(2)(j) includes "the use of multi-factor authentication or continuous authentication solutions" as part of cybersecurity risk-management measures for essential and important entities.

That makes the NIS2 MFA conversation different from SOC 2, ISO 27001, SOX, or GDPR. This is not only an auditor expectation or a post-breach appropriateness argument. It is written into the directive.

What Article 21 Requires

Article 21 requires entities to take appropriate and proportionate technical, operational, and organizational measures to manage cybersecurity risks. The list includes incident handling, business continuity, supply-chain security, vulnerability handling, encryption, access-control policies, asset management, and multi-factor or continuous authentication.

The important part for application teams is scope. NIS2 is not limited to the SaaS apps already behind the IdP. The requirement follows the entity's systems and risk, including legacy and sector-specific web applications.

Who Is in Scope

NIS2 covers essential and important entities across sectors such as energy, transport, health, drinking water, digital infrastructure, public administration, managed ICT services, manufacturing of critical products, food, chemicals, waste management, postal services, and research.

Many manufacturers, suppliers, healthcare operators, and digital-service providers that were not deeply affected by NIS1 are now reviewing whether they are directly in scope or facing customer flow-down requirements.

Penalties and Current Transposition Status

NIS2 sets administrative fine ceilings of at least EUR 10 million or 2% of worldwide annual turnover for essential entities, and at least EUR 7 million or 1.4% for important entities. The European Commission's FAQ also emphasizes management accountability for cybersecurity measures.

The transposition deadline was October 17, 2024. As of July 2026, the Commission had referred Ireland, Spain, France, and the Netherlands to the Court of Justice for failing to notify complete transposition measures. That means the EU-level MFA substance is clear, but national-law mechanics still need country-by-country review.

Where NIS2 MFA Gaps Hide

The predictable gap is not Microsoft 365 or Salesforce. It is the sector-specific application path:

  • ERP and manufacturing portals.
  • Supplier and logistics portals.
  • Plant or operations web applications.
  • Admin dashboards for critical services.
  • Custom applications that touch regulated workflows.

These are exactly the applications that often cannot add native MFA quickly.

How Datawiza Helps with NIS2 MFA

Datawiza Access Proxy enforces MFA at the access layer. Put it in front of the web application, block direct bypass, and require MFA before users reach the system.

Datawiza can use your existing IdP for SSO and MFA, or Datawiza built-in MFA when users are outside the IdP. That helps teams cover legacy and external-facing web applications without rewriting them or waiting for a full identity modernization project.

Sources Reviewed

FAQ

Does NIS2 require MFA?

Yes. Article 21(2)(j) explicitly includes multi-factor authentication or continuous authentication solutions among the cybersecurity risk-management measures for essential and important entities.

Who must comply with NIS2?

Essential and important entities in covered EU sectors must comply through the national law that transposes NIS2. Suppliers may also see requirements through contracts with in-scope customers.

What are the NIS2 penalties?

The directive sets fine ceilings of at least EUR 10 million or 2% of worldwide annual turnover for essential entities, and at least EUR 7 million or 1.4% for important entities.

Do legacy web applications need MFA under NIS2?

If they are part of the entity's risk-relevant system environment, they should be assessed. NIS2 does not exempt applications because they are old or hard to modify.

Datawiza is Easy to Get Started

Sign up to secure your AI agents and critical enterprise apps

Try Datawiza