NIS2Art. 21(2)(j)voice-validated

NIS2 Art21j: Art. 21(2)(j)

Network and Information Security Directive 2 (EU 2022/2555)

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Essential and important entities must implement the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate. MFA must be applied to privileged accounts and remote access at minimum.

ATT&CK techniques this article tests · 15

TechniqueWhy it mapsConfidence
T10781. Multi-factor authentication (MFA) directly counters the use of compromised valid accounts by requiring an additional verification factor, as mandated by NIS2 Art. 21(2)(j). This significantly reduces the success rate of credential theft attacks.
90%
T11331. MFA for remote access, as specified in NIS2 Art. 21(2)(j), directly mitigates unauthorized access via external remote services. This adds a critical layer of security beyond passwords for external connections.
90%
T10031. Even if credentials are dumped (e.g., via OS Credential Dumping), MFA ensures these stolen credentials alone are insufficient for authentication. This reduces the utility of credential access techniques.
80%
T10561. Input Capture techniques, such as keylogging, may obtain primary credentials. MFA requires a second factor, rendering captured passwords less effective for gaining unauthorized access, as per NIS2 Art. 21(2)(j).
80%
T15521. MFA protects against the use of unsecured credentials found by adversaries. Even if credentials are exposed, the required second factor prevents their direct use, aligning with NIS2 Art. 21(2)(j).
80%
T10211. Applying MFA to remote services, as required for remote access in NIS2 Art. 21(2)(j), restricts an adversary's ability to move laterally or maintain access through compromised remote service credentials.
80%
T10711. Secured voice, video, and text communications, as per NIS2 Art. 21(2)(j), make it harder for adversaries to establish or maintain command and control channels by intercepting or manipulating application layer protocols.
70%
T10401. Secured communications (encryption) prevent network sniffing, directly protecting the confidentiality of data in transit as required by NIS2 Art. 21(2)(j) for internal communications.
80%
T10411. Secured internal communications, as mandated by NIS2 Art. 21(2)(j), hinder exfiltration over C2 channels by encrypting data and making it more difficult for adversaries to establish covert communication paths.
70%
T10981. MFA on privileged accounts, as required by NIS2 Art. 21(2)(j), makes it significantly harder for adversaries to manipulate accounts for persistence or privilege escalation, even if initial credentials are compromised.
80%
T11101. MFA directly counters brute force attacks by requiring a second, typically time-sensitive, factor. This renders repeated password guessing ineffective, as specified in NIS2 Art. 21(2)(j).
90%
T1078.0031. MFA for cloud accounts, especially privileged ones, directly addresses unauthorized access to cloud resources. This aligns with the NIS2 Art. 21(2)(j) requirement for MFA on privileged accounts.
90%
T1078.0041. MFA for local accounts, particularly privileged ones, enhances security against local credential compromise. This supports the NIS2 Art. 21(2)(j) mandate for MFA on privileged accounts.
90%
T1071.0011. Securing application layer protocols, such as web protocols, for internal communications as per NIS2 Art. 21(2)(j), makes it harder for adversaries to intercept or inject into web-based C2 channels.
70%
T1071.0021. Secured file transfer protocols, as part of general secured communications under NIS2 Art. 21(2)(j), prevent adversaries from using unencrypted file transfers for C2 or data exfiltration.
70%

Defending mitigations · 6

MitigationWhat it doesConfidence
M10321. Multi-factor authentication is explicitly required by NIS2 Art. 21(2)(j) for privileged accounts and remote access, directly implementing this mitigation to prevent unauthorized access.
90%
M10301. Implementing secured voice, video, and text communications, as per NIS2 Art. 21(2)(j), directly addresses the need for encryption to protect data in transit and communication integrity.
80%
M10271. MFA for privileged accounts, as mandated by NIS2 Art. 21(2)(j), directly limits the impact of compromised credentials by requiring an additional authentication factor for high-privilege access.
80%
M10351. Continuous authentication solutions, mentioned in NIS2 Art. 21(2)(j), enhance user session management by continuously verifying user identity, reducing the window for unauthorized access post-authentication.
70%
M10431. Secured emergency communication systems, as required by NIS2 Art. 21(2)(j), ensure reliable and protected communication channels during incidents, which is crucial for incident response and recovery.
70%
M10171. MFA for remote access, as specified in NIS2 Art. 21(2)(j), directly restricts network access by ensuring only authenticated users can connect, even if their primary credentials are known.
70%

Underlying weaknesses · 6

CWEWhy it persistsConfidence
CWE-2871. Improper Authentication is directly addressed by the requirement for MFA in NIS2 Art. 21(2)(j). MFA adds layers of verification, preventing unauthorized access from weak or stolen credentials.
90%
CWE-3061. Missing Authentication for Critical Function is mitigated by NIS2 Art. 21(2)(j)'s mandate for MFA on privileged accounts and remote access, ensuring critical functions are adequately protected.
90%
CWE-3191. Cleartext Transmission of Sensitive Information is mitigated by the requirement for secured voice, video, and text communications in NIS2 Art. 21(2)(j), which implies encryption to protect data confidentiality.
80%
CWE-5211. Weak Password Requirements are inherently mitigated by MFA, as mandated by NIS2 Art. 21(2)(j). Even if a password is weak, the second factor prevents easy compromise.
80%
CWE-7981. Use of Hard-coded Credentials is made less impactful by MFA, as required by NIS2 Art. 21(2)(j). While not directly preventing hard-coding, MFA ensures these credentials alone are insufficient for access.
70%
CWE-2881. Authentication Bypass Using an Alternate Path is made more difficult by comprehensive MFA implementation across all access points, as implied by NIS2 Art. 21(2)(j) for remote and privileged access.
70%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0194 compute · voice-rubric self-validated