NISG 2026 course All courses

Lesson 4.5 · 7 min

Access, MFA, encryption, inventory

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

Point (h) requires policies on cryptography and, where appropriate, encryption; point (i) human resources security, access control and asset management; point (j) multi-factor or continuous authentication, secured voice, video and text communications and, where appropriate, secured emergency communications § 32(4)(h) to (j) NISG 2026. The EU catalogue § 2 NISV 2026 spells this out (Implementing Regulation (EU) 2024/2690, Annex points 9 to 13):

Access control (point 11)

Human resources security (point 10)

All staff and, where needed, direct service providers know their security duties; administrators and the management know their roles; qualifications are checked when hiring; background checks, where feasible, for roles that require them; duties that continue after leaving, such as confidentiality, are in the contract; a disciplinary procedure for breaches is known.

Cryptography (point 9)

A policy sets which data, stored and in transit, gets what strength of cryptographic protection, which protocols and algorithms are approved, with crypto-agility where appropriate, and how keys are managed over their whole life: generated, distributed, stored, changed, revoked, recovered, backed up, destroyed. It is reviewed in line with the state of the art.

Assets (point 12) and physical security (point 13)

Checklist

Quiz

What does the EU catalogue require for administrator accounts?

  1. One shared admin account for the whole IT team
  2. Nothing special, as long as the password is long
  3. That administrators may not read email
  4. Separate accounts used only for administration, with strong authentication such as MFA
Show the answer

The answer is D: Separate accounts used only for administration, with strong authentication such as MFA. Implementing Regulation (EU) 2024/2690, Annex point 11.3.2, through § 2 NISV 2026: strong identification and authentication (e.g. MFA) and specific accounts used only for system administration.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.