Defines requirements for multi-factor authentication and continuous authentication solutions, aligned with NIS 2 Article 21(2)(j).
A compliant Multi-Factor Authentication Policy for NIS 2 Directive must include the following6 sections. Each section addresses a specific control requirement that auditors will review.
Policy objectives and NIS 2 MFA requirements.
Systems requiring MFA and classification criteria.
Accepted factor types and phishing-resistant methods.
Secured voice, video, and text communication requirements.
Break-glass procedures when MFA is unavailable.
MFA enrollment process and recovery procedures.
This template shows the required structure. PoliWriter generates a fully customized Multi-Factor Authentication Policy that references your actual cloud providers, identity systems, tools, and team practices — ready for auditor review.
Establishes a systematic approach to identifying, analyzing, and treating cybersecurity risks in accordance with NIS 2 Directive Article 21.
Defines procedures for detecting, managing, and reporting significant cybersecurity incidents, including the mandatory 24-hour early warning to the CSIRT under NIS 2 Article 23.
Ensures continuity of essential or important services during and after cybersecurity incidents, aligned with NIS 2 Article 21(2)(c).
Addresses security requirements for direct suppliers and service providers, aligned with NIS 2 Article 21(2)(d).
Establishes security controls for network and information systems acquisition, development, and maintenance, aligned with NIS 2 Article 21(2)(e).
Establishes procedures for vulnerability disclosure and coordinated handling of vulnerabilities, aligned with NIS 2 Article 21(2)(e) and Article 12.
Defines policies and procedures for the use of cryptography and encryption to protect network and information systems, aligned with NIS 2 Article 21(2)(h).
Establishes access control policies and asset management requirements for network and information systems, aligned with NIS 2 Article 21(2)(i).