NIS2 access reviews for Microsoft 365

NIS2 makes access control a management responsibility. It does not prescribe a tool or a review frequency, but it does expect you to show that access is controlled, reviewed and owned. For most organisations that evidence lives in Microsoft 365.

What NIS2 asks for

Article 21(2)(i) of the NIS2 Directive (EU) 2022/2555 lists "human resources security, access control policies and asset management" among the minimum cybersecurity risk-management measures. Article 20 makes the management body approve those measures and oversee their implementation.

In Germany the directive was transposed by the NIS2 Implementation Act (NIS2UmsuCG), in force since 6 December 2025. The measures are in § 30 of the BSI Act (BSIG), and § 38 BSIG places the duty to approve and monitor them on management, with personal liability.

For certain digital-infrastructure and ICT-service providers, Implementing Regulation (EU) 2024/2690 goes further and spells out access-control requirements, including the management and review of access rights.

What that means in Microsoft 365

An assessor looking at access control in a Microsoft 365 tenant will ask versions of the same questions:

How Ownership Registry produces that evidence

The tool itself is read-only on your tenant, which keeps it out of your own NIS2 risk register as a new privileged system. Details are on the security page.

What it does not cover

NIS2 access control goes beyond Microsoft 365: physical access, privileged access management, MFA (Art. 21(2)(j)) and access inside business applications. Ownership Registry covers the Microsoft 365 objects and service accounts, and custom object types let you register on-premises service accounts and file shares by hand. For the wider tenant configuration, our Microsoft 365 security assessment is the starting point.

NIS2 questions

How often does NIS2 require access reviews?

Neither the directive nor § 30 BSIG sets a fixed interval. It expects appropriate and proportionate measures, which in practice means a documented cadence based on risk, applied consistently, with evidence. Setting the cadence per object, by risk, is how the registry reflects that.

Does management have to be involved?

Yes. Article 20 of the directive and § 38 BSIG require the management body to approve the risk-management measures and oversee their implementation. A coverage dashboard and a complete audit trail are what makes that oversight possible without a quarterly spreadsheet.

Is an access review tool itself a NIS2 risk?

Any tool with write access to your tenant is. Ownership Registry holds read permissions plus Mail.Send and has no code path that modifies or deletes objects, so it adds no new privileged path into Microsoft 365.

See where your tenant stands

A read-only demo shows your current ownership coverage, the first number a NIS2 access-control review will ask for. Book a demo