The European Union is constantly raising the bar in the field of cybersecurity, presenting member states and organizations with increasingly demanding standards. One of the key tools in this strategy is the NIS2 directive, which redefines the approach to securing information systems in the EU. How does it affect companies, and why can a password manager play a key role in adapting to these regulations?
NIS2 - Europe's digital security
NIS2 is an evolution of the earlier NIS directive from 2016, which established basic requirements for network and system security in the EU. The new version, announced in 2020 and entering into force in January 2023, aims to strengthen the capacity of key economic sectors to respond to cybersecurity incidents. Since October 17, 2024, all member states must comply with its requirements.
The directive imposes an obligation to implement appropriate measures to increase security and comply with legal obligations on operators of so-called essential and important services. An additional objective of NIS2 is to cover a wider scope of organizations, expanding the regulations from 7 to 15 sectors.
List of entities covered by the NIS2 directive:
Energy
Healthcare
Transport
Finance
Water supply
Digital infrastructure
Public administration
Digital service providers
Postal services
Waste management
Space
Food sector
Industrial manufacturing
Chemicals
Scientific research
The directive introduces stricter rules for incident reporting, harsher penalties for non-compliance, and obliges the use of advanced cybersecurity measures. For companies, this means the need to adapt to more detailed and demanding regulations, which requires investments in technologies, processes, and human resources.
Why are the new regulations needed?
The COVID-19 pandemic and the massive shift to remote work revealed serious gaps in the previous version of the NIS directive. A lack of effectiveness, low awareness of cyber threats, and insufficient coordination of activities were just some of the problems that became clearer, especially during the armed conflict in Ukraine. The geopolitical situation and technological development caused part of the warfare to be shifted to the network. As a result of these experiences, NIS2 emphasizes security consistency and faster response to constantly evolving threats across the EU.
Requirements of the NIS2 directive
The directive is based on four main pillars:
Risk management
Corporate responsibility
Reporting obligations
Business continuity
NIS2 requires organizations to implement basic security measures, such as:
policies on risk analysis and information system security
incident handling
business continuity and crisis management
supply chain security
security in the acquisition, development, and maintenance of systems
policies to assess the effectiveness of security measures
basic cyber hygiene practices and training
cryptography and encryption
human resources security, access control policies, and asset management
the use of multi-factor authentication and secure communication
secure communication
source: Enisa
How can a password manager help meet NIS2 requirements?
Although a password manager may seem like an additional tool, it plays a crucial role in strengthening cyber resilience. It enables organizations to manage authentication data effectively, minimizing the risk of unauthorized access.
For business leaders, choosing the right tool such as perc.pass can be a strategic step toward NIS2 compliance. Enterprise grade solutions offer end-to-end encryption and zero-knowledge architecture, ensuring the highest level of data protection.
An enterprise-grade password manager allows you to:
- Control data access and restrict it to only necessary resources for specific individuals within the organization (Zero Trust strategy).
- Monitor and report user activity to prevent threats and take proactive measures.
- Enhance security with built-in two-factor authentication (2FA), ensuring that even if a password is leaked, the data remains protected.
- Promote cybersecurity hygiene by reducing unintentional employee actions that could lead to threats like phishing.
- Securely share passwords within teams, significantly improving efficiency in a dynamic organizational environment.
Read more here.
How does perc.pass support security standards compliance?
While specific guidelines are lacking, cybersecurity industry standards such as ISO 27001 provide recognized best practices and solutions for securing organizational data. The perc.pass password manager significantly facilitates the implementation of this standard by establishing a strong foundation for compliance.
This is particularly relevant to organizational control areas, supported by key perc.pass functionalities:
- Password Generator – Users can create unique, fully random passwords in seconds, resistant to brute force attacks and other intrusions.
- Policy Management – Security administrators can enforce password complexity requirements, ensuring a uniform and secure standard across the enterprise.
- Monitoring Dashboard – Administrators receive system reports on password policy violations, breaches, password strength, and account statuses, enabling quick responses to threats.
- Leak Monitoring – Users can check if their passwords have been exposed in breaches and set up periodic monitoring for ongoing protection.
- User Management – The system allows assigning roles and permissions, ensuring that employees access only the areas essential for their work (Zero Trust strategy).
- Two-Factor Authentication (2FA) – An additional security layer ensures that access to the system requires a second authentication factor (e.g., email code, FIDO2 hardware key, OTP, or mobile app).
- Activity Logs – User actions are tracked and recorded, providing full visibility into password manager usage. Administrators can generate detailed activity reports at any time.
- Security Assurance – perc.pass utilizes strong symmetric and asymmetric cryptography and has successfully undergone independent penetration testing, confirming its resilience against attacks.
Complying with NIS2 directive is not just about meeting legal requirements—it’s about building a competitive advantage. Companies that invest in advanced tools and cybersecurity policies gain greater trust from partners and customers. Implementing an organizational password manager sends a clear message that cybersecurity is a top priority.