NIS2 has reached the hospital: the access control evidence a supervisor will ask for
On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify full transposition of the NIS2 Directive. The deadline had passed on 17 October 2024. Five weeks after the referral, on 15 August 2026, the Dutch Cyberbeveiligingswet entered into force.
For hospital boards the message is simple. In most of the EU, NIS2 is no longer a draft. It is national law with a supervisor attached.
Health is one of the 18 sectors the directive covers, and the reason is plain. Member States reported 309 significant cybersecurity incidents affecting healthcare in 2023, more than in any other critical sector. ENISA's NIS360 report places health among six sectors in its "risk zone", where maturity lags behind criticality.
What the directive says about access
Very little, in words. Article 21 asks for "appropriate and proportionate" measures and lists ten minimum areas. Two concern access: "human resources security, access control policies and asset management", and "the use of multi-factor authentication or continuous authentication solutions", the second "where appropriate".
The detail comes from national law and from each supervisor. The fullest EU-level reading is Implementing Regulation 2024/2690, with ENISA's technical implementation guidance. Both are written for digital infrastructure, ICT service management and digital providers, such as cloud and data centre operators, not hospitals. They are still a useful map, because they show how regulators divide the subject: access control policy, management of access rights, privileged accounts, administration systems, identification, authentication and multi-factor authentication.
A policy is not evidence
Under Article 32, authorities supervising essential entities may carry out on-site inspections and random checks. They may also request "evidence of implementation of cybersecurity policies". Larger hospitals will typically be classed as essential, so this can happen before any incident.
That moves the question from "do we have a policy?" to "can we show it working?".
Six things to be able to show
An approved access policy. Article 20 requires the management body to approve the risk measures and oversee them. A signed, dated policy with a review cycle is the starting point.
A named person behind every login. Shared ward accounts are the hard case in hospitals. If a whole shift uses one login, the audit trail identifies nobody.
Joiners, movers and leavers. Show how quickly access is removed when a locum, student or agency nurse leaves, and when rights were last reviewed.
Separate privileged accounts. Administrators should hold dedicated accounts with stronger authentication, used only for administration.
A reasoned position on MFA. "Where appropriate" is a risk decision, so write it down. Remote access, administrator access and supplier access are the obvious first candidates. Article 21 lists supply chain security as well.
Emergency access that leaves a trace. Break-glass access to a patient record is legitimate. It should be logged, time-limited and reviewed afterwards.
What is at stake
For essential entities, Article 34 sets maximum fines of at least €10 million or 2% of worldwide annual turnover, whichever is higher. For important entities the figures are €7 million or 1.4%. Article 20 also allows management bodies to be held liable for infringements of Article 21.
One thing still moving
In January 2026 the Commission proposed targeted amendments to NIS2. They remain a proposal and must still pass Parliament and Council. The obligations already in national law apply today.
A practical test
Pick one patient record that was opened at 03:00 last Tuesday. Can you show who opened it, and how you know it was them? If the answer takes a meeting instead of a report, that is the gap to close first.