What Is NIS2?
NIS2 (the revised Network and Information Security Directive, EU 2022/2555) is a European Union directive that sets cybersecurity risk-management and incident-reporting obligations for operators of essential and important services — including energy, transport, health, digital infrastructure, and public administration. It expands the scope of the original 2016 NIS Directive to cover more sectors and significantly more organizations, requires board-level accountability for cybersecurity, and mandates incident reporting within strict timeframes (typically 24 hours for initial notification). EU member states transpose NIS2 into national law; in France, ANSSI enforces it partly through the ReCyF framework. Enforcement of NIS2 obligations in France begins October 1, 2026, with ReCyF Objective 13 specifically addressing service accounts and machine credentials.
Why It Matters
NIS2 explicitly extends cybersecurity accountability to the machine layer, not just human users. ANSSI's ReCyF Objective 13 — part of the French implementation of NIS2 — specifically targets service accounts and machine credentials, requiring organizations to inventory, monitor, and control non-human identities the same way they control human access. This matters because NHIs are where the exposure actually concentrates: a typical 100-person company runs 2,000+ non-human identities, often outnumbering human employees 45 to 1, and OWASP's 2025 NHI Top 10 research found that 80% of identity breaches involve a non-human identity. A regulator asking 'can you demonstrate control over your service accounts and API keys' is asking a question most organizations cannot currently answer — because these credentials are typically created ad hoc by developers, never inventoried centrally, and rarely rotated. With enforcement beginning October 1, 2026, organizations in scope have a fixed deadline to close a visibility gap that has existed, unaddressed, for years.
How Cydenti Helps
Cydenti gives organizations the inventory and evidence NIS2 — and ReCyF Objective 13 specifically — expects them to produce: a continuously updated map of every service account, API key, OAuth token, and machine identity, who owns it, what it can access, and whether it's been rotated or reviewed. Instead of scrambling to reconstruct this picture manually before an audit, teams get it as a standing, exportable view they can hand to a regulator or auditor on request. That turns NIS2's machine-identity requirement from a compliance scramble into a maintained, evidence-backed control.
Explore →Frequently Asked Questions
Does NIS2 apply to service accounts and API keys?
Yes, indirectly but explicitly in France. ANSSI's ReCyF framework, which operationalizes NIS2 compliance for French organizations, includes Objective 13, which specifically requires visibility and control over service accounts and machine credentials — not just human user accounts. Organizations in NIS2's scope should expect machine identity governance to be part of an audit.
When does NIS2 enforcement start?
NIS2 enforcement in France begins October 1, 2026, under ANSSI's ReCyF framework. Organizations classified as essential or important entities should use the time before enforcement to build an inventory of their non-human identities and demonstrate control over service accounts, since ReCyF Objective 13 addresses this directly.
Discover the machine identities you didn't know you had
— in 27 minutes, for free.
NIS2 enforcement begins October 1, 2026. The Audit Flash delivers your complete NHI exposure snapshot — service accounts, orphaned credentials, OAuth grants, AI agents — with a first report in 3 hours. No commitment.
No commitment • No credit card • Data hosted in Europe • Response within 24h