
NIS2 Compliance for Privileged Access
Meeting NIS2 requirements for access control, audit logging, and incident response with a PAM solution built for German compliance
Get 25 Endpoint Privilege Management, Secure Remote Access & Web Access Management seats, free.
Fill out the form with your work email and we’ll send your credentials to your inbox.
What NIS2 Means for Privileged Access
The NIS2 Directive establishes unified cybersecurity requirements for essential and important entities across 18 critical sectors in the EU.
For German organisations within NIS2 scope, the requirements around privileged access management are specific: access control, multi-factor authentications, complete audit trails, and the ability to report security incidents within 24 hours.
Fines for non-compliance can reach up to €10 million or 2% of worldwide annual turnover for essential entities. NIS2 compliance has moved from a side compliance task to a board-level responsibility.
See how an Admin Session works.

NIS2 Requirements We Cover
Admin By Request supports the four pillars of NIS2 compliance with capabilities that map directly to the security measures required under Article 21(2) of the Directive.*

Risk Management
Just-in-time privilege elevation, role-based access controls, and automated vulnerability management during parching and maintenance AI-driven risk scoring is backed by a database of over 12 million applications.

Corporate Accountability
Executive dashboards with visibility into privileged activity, comprehensive audit trails demonstrating management oversight, and automated compliance reporting at board level.

Reporting Operations
Real-time incident detection and alerting that supports the 24-hour early warning requirement, tamper-resistant audit logs with up to 5 years of retention, and automated documentation of security events for reporting to national authorities.

Business Continuity
Break Glass emergency access for operations during security incidents, session isolation and monitoring to maintain critical services, and rapid restoration of privileges and systems.
*Admin By Request supports the technical controls required under NIS2; it does not constitute legal certification or guarantee regulatory compliance on its own.
Award Winning Solutions
We provide award-winning SaaS-based solutions to standing admin rights, overloaded helpdesks, outdated remote access infrastructure, malicious downloads, and internet access management.

BSI IT-Grundschutz-Aligned Access Control
The BSI IT-Grundschutz requirements for managing privileged accounts overlap significantly with what NIS2 requires: documented access policies, MFA for privileged access, audit logging, and least-privilege enforcement. Admin By Request supports these requirements with the same capabilities that cover NIS2.
At the endpoint, standing local admin rights are replaced by just-in-time elevation, every elevation is logged with user, application, command, and timestamp, and approval workflows can enforce MFA before any elevation. At the server level, privileged sessions are fully recorded and traceable in the audit log.
How the Compliance Architecture Works
The platform is SaaS-based with a 2MB agent on Windows, macOS, and Linux. Customer data is hosted in EU-based datacentres in Germany, subject to GDPR and EU data protection regulation. The Article 28 GDPR-compliant Data Processing Agreement is available for every customer by default.
For the compliance documentation taht German auditors typically expect to see, we provide SOC 2 Type II and ISO 27001 certifications, penetration test reports, the Data Processing Agreement, and full compliance mapping through the Trust Center.


What You Can Demonstrate in an Audit
Complete access logs
Every elevation and every login is logged with user, endpoint, application, command, and outcome. The audit log filters by user, time range, application, or section and exports as PDF, XLS, or CSV.
Approval workflows on record
Each elevation request shows which admin approved or denied it and when. Mobile app approvals are logged identically to portal approvals.
Session recordings for sensitive work
Privileged sessions can be captured in full as screen recordings, available for incident investigation or audit review.
Settings change history
A full portal settings audit log captures every configuration change with old value, new value, user, and timestamp.
Frequently Asked Questions
NIS2 Article 21(2) requires security measures including access control, identity management, MFA, and audit logging. In practice, this means privileged accounts can’t carry permanent elevated rights, every privileged access must be logged, and audit data has to be available within the 24-hour early warning window if an incident occurs.
NIS2 covers essential and important entities across 18 critical sectors, including energy, transport, banking, healthcare, digital infrastructure, IT services, and public administration. Germany’s implementation is the NIS2-Umsetzungsgesetz, which sets out the specific requirements for German organisations.
Our Trust Center includes SOC 2 Type II, ISO 27001, ISO 27701, the Data Processing Agreement, penetration test reports, and compliance mapping. On request we can also provide detailed reports on NIS2-specific controls.
Yes. Customer data is hosted in EU-based datacentres in Germany, with an Article 28 GDPR-compliant Data Processing Agreement covering every customer.
BSI IT-Grundschutz requirements for privileged accounts overlap significantly with NIS2: documented access policies, MFA, audit logging, and least-privilege enforcement. The same capabilities that cover NIS2 also support BSI IT-Grundschutz-aligned access control.
Yes. Our Free Plan covers 25 endpoints with full feature access, no time limit, and no payment details required.
