๐ŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
All posts

FIDO2 for NIS2 Compliance: What Security Teams Actually Need

September 26, 2026 ยท PlayCISO
TL;DR

NIS2 (the EU Network and Information Security Directive 2) does not name "FIDO2" or "passkeys" explicitly, but its Article 21 risk-management obligations and its emphasis on multi-factor and secure authentication make phishing-resistant MFA the natural way essential and important entities satisfy the access-control expectations. FIDO2/WebAuthn credentials โ€” hardware security keys and passkeys โ€” bind authentication to the origin, so a credential phished on a lookalike domain simply will not work. This guide maps FIDO2 to the relevant NIS2 measures, explains what "phishing-resistant" buys you over app-based OTP, and gives a rollout order that starts with administrators and remote access before general workforce.

NIS2 does not contain the words "FIDO2" or "passkey" anywhere. What it does contain, in Article 21, is a requirement for essential and important entities to put in place appropriate and proportionate technical, operational and organisational measures โ€” explicitly including access-control policies and the use of multi-factor or continuous authentication "where appropriate." For most organisations, the cleanest way to satisfy the strong end of that expectation is phishing-resistant authentication, and in practice that means FIDO2/WebAuthn: hardware security keys and passkeys.

Why phishing-resistant, and why now

The dominant way accounts get taken over is not password guessing โ€” it is phishing and adversary-in-the-middle kits that relay a legitimate login, including the one-time code or push approval, in real time. App-based OTP and push MFA raise the bar but do not remove this path. A FIDO2 credential does, because it is bound to the origin it was registered with. On a lookalike domain the browser will not release it, so there is nothing to relay. That single property is why regulators and frameworks increasingly describe phishing-resistant MFA as the target state, and why it is the most defensible answer to a NIS2 assessor asking how you control access to important systems.

Mapping FIDO2 to NIS2 Article 21

  • Access control & MFA: FIDO2 directly implements the "multi-factor authentication where appropriate" measure, at the strongest tier.
  • Identity of privileged users: device-bound hardware keys give administrators an authenticator that cannot be silently copied off a laptop.
  • Business continuity & resilience: registering two or more authenticators per user is both a lockout-avoidance practice and evidence of the resilience NIS2 expects.
  • Supply chain & remote access: phishing-resistant sign-in for VPN, VDI and third-party portals shrinks the most-exploited entry points.

A rollout order that survives an audit

  1. Administrators and PAM first. Hardware security keys for domain/cloud admins and privileged-access tooling. Highest blast radius, smallest population.
  2. Remote and VPN access. Enforce FIDO2 at the identity provider for anything reachable from outside the network.
  3. General workforce passkeys. Roll out synced passkeys for primary IdP sign-in; this is where adoption and phishing-resistance scale.
  4. Two authenticators per user. A platform passkey plus a roaming key removes lockouts and reads as resilience, not just authentication.
  5. Disable weaker fallbacks. The control only holds if SMS/OTP fallback is removed for the accounts you have hardened โ€” an assessor will check this.

What to measure

Track FIDO2 coverage by population (admins, remote users, all staff), the number of accounts still allowed a phishable fallback, and the number of users with fewer than two authenticators. Those three numbers are the honest picture of how much of your NIS2 access-control obligation FIDO2 actually covers.

For the wider build-vs-buy view and authenticator options, see our FIDO2 & passkeys assessment, and quantify where weak identity controls sit with the free Identity Risk tool โ†’

Frequently asked questions

Does NIS2 require FIDO2 specifically? No โ€” NIS2 is technology-neutral. Article 21 requires multi-factor or continuous authentication where appropriate; FIDO2/WebAuthn is the most common way to meet the phishing-resistant end of that expectation.

Why is FIDO2 phishing-resistant? The credential is bound to the website origin, so it cannot be released on a lookalike domain or relayed by an attacker-in-the-middle.

Where should we deploy it first? Administrators and privileged access, then remote/VPN, then the general workforce โ€” with at least two authenticators per user.

Passkeys or hardware keys? Both are FIDO2. Passkeys for broad adoption; hardware keys for administrators and high-risk roles.

Ready to practise the decisions these articles describe?

Run a free War Room โ†’
FIDO2 for NIS2 Compliance: What Security Teams Actually Need | PlayCISO Blog ยท PlayCISO