IAM as the Control Plane for DORA and NIS2

Identity is usually bought as a security tool and justified as a convenience — single sign-on, fewer passwords, faster onboarding. Under DORA and NIS2, it becomes something else: the control plane regulators inspect to see whether access to critical systems is actually governed. Reframing identity this way changes both the selection criteria and the business case, because the question is no longer “does it log people in” but “can it produce the evidence a supervisor asks for.”

What the regulations actually demand of identity

Neither DORA nor NIS2 contains a chapter called “identity,” but both make access governance load-bearing. DORA’s ICT risk management expects strong authentication, least-privilege access to critical functions, and a reviewable record of who can do what. NIS2 requires access control and multi-factor authentication as baseline measures for essential and important entities, with management personally accountable. In both, the recurring supervisory question is the same: show me who has access to this critical system, why, when it was last reviewed, and prove it. An identity platform that cannot answer that on demand is a security tool, not a control plane.

Choosing tooling for evidence, not just access

The buyers comparing Okta, Microsoft Entra and SailPoint are usually evaluating features. The more useful lens is evidence production:

Free · 4 minutes

Would you survive contact with a determined attacker — or an auditor?

Fourteen questions on access, patching, detection, and recovery — the basics that prevent most real incidents, and the ones most often assumed rather than verified. Banded finding on screen, full sheet by email.

  • Can it prove least privilege? Not just enforce access, but show access reviews, certifications, and the removal of entitlements over time.
  • Does it govern privileged access separately? Administrative and emergency access is where supervisory scrutiny concentrates; generic SSO does not cover it.
  • Can it account for non-human identities? Service accounts, machine credentials and now AI agents hold privileges too, and most programmes never inventoried them.
  • Does it integrate with your critical systems, or just the easy ones? Evidence gaps appear precisely at the legacy and bespoke systems that matter most to a regulator.

The mistake to avoid

The common error is running an identity programme as an IT-efficiency project and only later discovering it has to satisfy two regulators. That sequence produces a platform optimised for login convenience with no access-review trail, which then needs re-engineering under deadline. Treating identity as the compliance control plane from the outset — selecting for evidence, governing privileged and non-human access, and mapping it to DORA and NIS2 obligations explicitly — costs less and stands up to inspection.

Who this is for

This reading is for:

  • CTOs selecting or consolidating identity tooling under regulatory pressure
  • Security leads who own IAM but are asked to prove compliance with it
  • Compliance officers mapping DORA and NIS2 controls to real systems
  • Boards funding an identity programme and wanting to know why

Sixteen Pillars selects and governs identity as a compliance control plane, mapping privileged and non-human access to your DORA and NIS2 obligations. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming