Does NIS2 actually make multi-factor authentication mandatory, or does "where appropriate" leave you room to skip it? It makes it mandatory for the accounts that matter. The phrase lets you decide which accounts need MFA and how strong it must be, based on a documented risk assessment. It does not let you decide against MFA altogether.

Multi-factor authentication, or MFA, means a login requires at least two independent proofs from different categories: something you know (a password), something you have (a key or phone), or something you are (a fingerprint). NIS2 is the EU directive that sets minimum security duties for companies in 18 critical sectors. You will meet the MFA clause when a national supervisor asks for evidence of your access controls, and when your board is asked to sign off on the security measures it is now personally accountable for.

What Article 21(2)(j) says, and how "where appropriate" gets read

Article 21(2) lists ten minimum risk-management measures every in-scope entity must put in place. Item (j) is the one that covers authentication. The operative text of Article 21 requires "the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate."

Article 21(1) sets the test for every one of the ten: measures must be "appropriate and proportionate technical, operational and organisational measures," scaled to the entity's size, its risk exposure, and how likely and severe an incident would be. That is where "where appropriate" comes from. It is a scoping rule. A 60-person manufacturer and a national energy operator both need MFA, but not necessarily on the same systems or of the same strength.

In practice, supervisors and guidance converge on a floor. MFA is expected at minimum on remote access, privileged and administrative accounts, cloud administration, and email, according to the Commission's own summary of how ENISA guidance and national laws read the clause, published alongside its July 2026 infringement announcement.

ENISA's technical implementation guidance, published in June 2025, puts the detail in its access control section. It calls for "strong identification, authentication such as multi-factor authentication and authorisation procedures" for privileged and administrative accounts, as quoted by the MFA vendor Rublon. Two caveats matter. The guidance is written for digital infrastructure and ICT service management entities covered by Implementing Regulation (EU) 2024/2690, and it is non-binding. Your national authority decides what it enforces.

On which kind of MFA counts, the evidence points one way but is not yet settled in binding text. NIST SP 800-63B classifies SMS one-time codes as a "restricted" authenticator because of SIM swapping and SS7 interception, and Help Net Security reports that auditors increasingly treat SMS as insufficient for privileged or remote access. The alternatives named are FIDO2/WebAuthn, hardware security keys and certificate-based authentication.

When the obligation starts depends on your country

A directive binds companies only through national law, so the MFA duty applies from the day your member state's transposition takes effect. The EU deadline was 17 October 2024. Most states missed it.

As of September 2026, the ECSO transposition tracker counts 24 of 27 states with a law in place, with France, Ireland and Malta still at draft stage. A few concrete cases:

  • Germany transposed in December 2025. The main registration deadline passed on 6 March 2026, with a late deadline of 31 July 2026 for roughly 29,000 in-scope entities. German trade press reports BSI compliance audits were set to begin in Q3 2026.
  • The Netherlands passed its Cyberbeveiligingswet on 7 July 2026, and it entered into force on 15 August 2026. More than 8,000 public-sector bodies must register with the NCSC.
  • Austria published its law in December 2025 but deferred enforcement to 1 October 2026.

None of our sources confirms a single EU-wide date for a first round of compliance audits. Audit timing is set nationally, so check your own supervisor's calendar rather than a date quoted in vendor material.

What the €10 million figure attaches to

The fine attaches to failing Article 21 as a whole, not to a missing MFA prompt. Missing MFA on admin accounts is one way to fail it.

For essential entities, member states must allow fines of at least €10 million or 2% of global turnover, whichever is higher. For important entities the figure is €7 million or 1.4%. These are ceilings that states may raise but not lower, as Legiscope's enforcement tracker notes; they are not automatic penalties. Germany has raised the essential-entity cap to €20 million and allows fines of up to €500,000 on individual managers.

The personal exposure is the part boards notice. Article 20 requires management to approve the risk-management measures, which includes authentication policy, and Article 32 allows a "temporary prohibition of a natural person from exercising managerial functions."

How hard any of this has landed is still unclear. Legiscope's late-September tracker could not independently confirm a single NIS2 fine against a named company, and says that is a limit of its method, not proof none exist.

Two things it gets confused with

Often read as What it actually is
"Where appropriate" means MFA is optional A requirement to document, per account class, why each account has the MFA it has
The July 2026 court referrals mean companies are being fined The Commission referred four member states (Ireland, Spain, France, the Netherlands) to the EU Court of Justice for late transposition; companies were not the target

What to check before a supervisor asks

First, confirm your country's law is in force and whether you are an essential or important entity. That sets both the date and the ceiling.

Then build the record an auditor will want: a list of account classes (privileged, remote access, vendor, service, break-glass, cloud admin, email, standard users), the risk level of each, the MFA method used, the reason, and a review date. Any class with no MFA needs a written justification that would survive a reasonable reader.

Finally, look at where SMS codes or push approvals still protect admin or remote access. Those are the accounts most likely to draw a finding, and replacing them is the point at which the question stops being whether to deploy MFA and becomes which kind. If you are moving admins to phishing-resistant hardware keys, that choice has its own trade-offs in cost, recovery and rollout order.

Ready to replace phishable MFA?

Our full guide covers choosing hardware security keys, enrolling admins first, and handling lost keys without reopening the door.

Plan the rollout