Abstract network of glowing nodes representing distributed remote access under NIS2

NIS2 and Remote Work: Which Article 21 Measures Follow Your Staff Home

Search the full text of the NIS2 Directive for telework, teleworking or remote work and you get nothing. Not one occurrence. The phrase working from home appears exactly once, in Recital 56, and it is about small businesses needing help from national cybersecurity strategies — not an obligation on anybody.

That absence is why remote-work compliance advice is so unreliable. With no provision to quote, vendors assert that NIS2 "mandates" VPNs, MFA and endpoint agents for remote staff, and readers have no way to check. The obligations are real, but they arrive through five ordinary provisions that were never written with a kitchen table in mind — and each carries a different level of legal force. This guide names all five, quotes the operative words, and separates what is binding from what is merely recommended.

What the Directive Actually Says About Working From Home

In plain terms: NIS2 regulates your network and information systems. It does not regulate locations. A laptop on a sofa in Lisbon is the same regulated asset as the desktop it replaced, so the same measures attach to it — no more, no less.

Article 21(1) requires "appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services". Proportionality is then defined by the entity’s exposure to risk, its size, and the likelihood and severity of incidents. Nothing in that test turns on where an employee sits.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

The three occurrences of remote access in the Directive all sit inside the definition of a cloud computing service — Article 6(30) uses "broad remote access" to describe a service model, not an employee connection. So if you are looking for the sentence that governs your hybrid workforce, it does not exist. What exists instead is a set of general measures under Article 21(2), and a much more specific Implementing Regulation that turns several of them into named controls.

The Five Provisions That Follow Your Staff Home

Commission Implementing Regulation (EU) 2024/2690 converts Article 21(2) into 13 Annex titles of auditable requirements. Each title states in its heading which Article 21(2) point it derives from. Five of those requirements are where remote work actually lands.

CIR Annex point Article 21(2) hook What it says about working away from the office
6.7.2(d) — network security (e) Entities shall "determine and apply controls for remote access to network and information systems, including access by service providers"
6.7.2(g) — network security (e) "Where appropriate, exclusively allow access … by devices authorised by those entities" — the corporate-device rule
11.7.1 — multi-factor authentication (i) and (j) Users authenticated by multiple factors "where appropriate, in accordance with the classification of the asset to be accessed"
12.2 — handling of assets (i) An asset-handling policy covering the whole lifecycle, communicated to everyone who uses the assets
13.3 — perimeter and physical access control (i) Prevent and monitor unauthorised physical access to network and information systems

One scope caveat that changes everything. The Implementing Regulation binds only eleven categories of digital entity — DNS providers, TLD registries, cloud providers, data centres, CDNs, managed service and managed security service providers, online marketplaces, search engines, social platforms and trust service providers. If you are a hospital, a utility or a manufacturer, the Annex is not law for you. It remains the most detailed articulation of Article 21(2) the Commission has published, which makes it the sensible benchmark to design against — but cite it as an interpretive reference, never as a requirement that binds you. Our guide to CIR 2024/2690 sets out the scope test in full.

Binding, Qualified, or Merely Suggested

In plain terms: three different levels of legal force are routinely presented to buyers as one. Knowing which is which is the difference between a defensible control set and an over-engineered one.

Start with the claim you will see most often: that NIS2 makes VPN and MFA mandatory for remote access. Article 21(2)(j) — the multi-factor authentication measure — reads in full: "the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate." It does not mention VPNs at all. The word VPN enters the EU stack only at Recital 18 of the Implementing Regulation, which lists "the use of virtual private networks for remote access" among typical network security solutions. Recitals explain intent; they do not create obligations.

So the honest hierarchy looks like this.

Level Example How to treat it
Binding, unqualified CIR 6.7.2(d): determine and apply controls for remote access You must have documented remote-access controls. Their design is yours to choose.
Binding, qualified CIR 6.7.2(g) and 11.7.1: both open with "where appropriate" Your risk assessment and asset classification decide. A documented decision is the compliance artefact.
Interpretive CIR Recital 18 (VPNs); Directive Recital 56 Cite as intent, never as a requirement. Do not write that the law requires a VPN.
Non-binding guidance ENISA guidance and tips blocks; national frameworks Strong evidence of expected practice. Persuasive at audit, not enforceable on its own.

That last row still matters commercially. ENISA’s Technical Implementation Guidance v1.0 (June 2025) advises entities to "enforce MFA on internet-facing systems, such as email, remote desktop and VPNs", and to "consider MFA, in particular when accessing systems from a remote location". ENISA states plainly that its guidance is recommendation, not law. But once an EU agency has written down what good looks like, an entity that skips MFA on remote desktop is arguing against the grain. In practice, most organisations will find that "where appropriate" is satisfied for remote access almost every time — the point is that you have to reach that conclusion and record it, rather than inherit it from a vendor slide. The specifics of that decision are covered in our MFA requirements guide.

Corporate Device or BYOD: The Provision That Decides It

In plain terms: there is no NIS2 ban on personal devices. There is one clause that makes allowing them a documented risk decision rather than a default.

CIR Annex 6.7.2(g) is the clause: "where appropriate, exclusively allow access to the relevant entities’ network and information systems by devices authorised by those entities". Read it carefully. The default posture it describes is exclusivity — only devices the entity has authorised. BYOD is not prohibited; it is the position you land in when you decide that exclusivity is not appropriate, and that decision now needs a reason on file.

The asset-handling requirement at Annex 12.2 pulls in the same direction from a different angle. It obliges a policy covering the entire lifecycle of assets — acquisition, use, storage, transportation and disposal — communicated to "anyone who uses or handles assets". ENISA’s guidance on that point tells entities to "consider mobile devices, such as smartphones and tablets, and determine a strategy for mobile device management, including Bring-Your-Own-Device".

Germany’s competent authority is blunter about why this is hard. In its recommendation on secure mobile working, the BSI notes that where staff have to fall back on private laptops at home, many of the standard protective measures "can only be implemented by the users themselves", and recommends a risk assessment plus additional awareness-raising as the compensating response. That is the practical core of the BYOD problem stated by a national regulator: on an unmanaged device you are not enforcing a control, you are hoping for one. The IT-Grundschutz building block INF.9 goes further and imposes a MUSS-level requirement that the organisation regulate whether and how staff may work on IT systems that are not its own, and ensure temporary data created during such use is deleted.

If you are moving toward device-conditional access rather than device ownership as the test, our zero trust implementation guide covers the architecture. ENISA itself points that way, listing zero trust network access alongside VPNs as secure connectivity for remote models.

The Home Office Is a Physical Security Problem You Cannot Inspect

In plain terms: physical security is not its own Article 21 measure. It is derived from three of them at once, and it does not stop at your reception desk.

Annex title 13, Environmental and physical security, is headed "Article 21(2), points (c), (e) and (i)" — business continuity, systems maintenance, and access control respectively. Its third subsection, 13.3.1, requires entities to prevent and monitor unauthorised physical access, damage and interference to their network and information systems. Nothing in that sentence is limited to premises the entity owns.

ENISA’s guidance addresses the consequence directly, in the only EU-level text found on the subject. Where an organisation runs a fully remote model with no central offices, it says, badge systems and on-site security "may not be applicable", so the focus shifts to logical controls — MFA, endpoint compliance checks and secure connectivity. And then: "For personnel working from home organizations should provide guidance on securing home workspaces — such as restricting unauthorized physical access to work devices and using locked rooms or cabinets when necessary."

The BSI reaches the same place from a national standpoint, observing that a home workstation cannot be assumed to have the infrastructural security of an office because it is frequently accessible to visitors and family members, and calling for lockable storage — a lockable desk, pedestal or cabinet — plus a clear-desk rule that applies at home. Notably, the BSI splits this territory into three separate building blocks: mobile workplaces, the domestic workspace, and the telework arrangement itself. The EU text has no vocabulary for any of them.

What an Auditor Can Actually Ask You For

Article 21(2)(f) requires policies and procedures to assess whether your measures work, which means remote-work controls have to be evidenceable, not just deployed. The evidence examples in ENISA’s guidance are unusually concrete: VPN and remote access logs showing access attempts, successful connections and anomalies; documented correct usage of mobile devices communicated to personnel; and access control policy documents showing which MFA methods are assigned to which roles.

Different roles own different halves of that. The table below is our reading of how the workload splits, not a provision of the Directive.

Role Owns First evidence to produce
CISO / IT security manager CIR 6.7 remote-access controls, 11.7 MFA configuration Remote access and MFA logs; device authorisation rules
Compliance officer The "where appropriate" decisions behind 6.7.2(g) and 11.7.1 Risk assessment output and asset classification that justify the chosen posture
HR / people lead Annex 12.2 asset handling and 12.5 return on termination Signed acknowledgements of the remote-working and BYOD policies
SME owner or board member Proportionality under Article 21(1) A dated record of what you decided not to do, and why

For a small entity the last row is the whole exercise. You are not expected to buy an enterprise mobility platform. You are expected to show that you considered remote access, classified your assets, and made a defensible call. A three-page decision record beats an unimplemented forty-page policy at every audit we have seen described.

The training obligation is the cheapest item on the list and the one most often skipped. ENISA’s guidance under the cyber hygiene requirement says that "if the entity has remote workers, training should include guidance to ensure that all users securely configure their home network infrastructure" — which is the closest the EU stack comes to acknowledging that a domestic router is now part of your attack surface. See our NIS2 training requirements guide for what that programme has to contain.

Frequently Asked Questions

Does NIS2 require a VPN for remote workers?
No provision requires a VPN. The only EU-level mention is Recital 18 of Implementing Regulation 2024/2690, which lists VPNs among typical network security solutions. The binding requirement, at Annex 6.7.2(d), is that you determine and apply controls for remote access — a VPN is one way to satisfy it, and zero trust network access is another.

Is MFA mandatory for remote access under NIS2?
Article 21(2)(j) and Annex 11.7.1 both qualify multi-factor authentication with "where appropriate", and 11.7.1 ties the decision to the classification of the asset being accessed. For internet-facing access to business systems it will usually be appropriate, and ENISA’s guidance recommends enforcing it there. But the requirement is conditional on that judgement being made and recorded, not a universal default.

Can we ban BYOD to make this simpler?
Yes, and Annex 6.7.2(g) describes device exclusivity as the reference posture. Banning personal devices is the cleaner compliance position. It is not the only lawful one.

Do these requirements apply to contractors and service providers working remotely?
Annex 6.7.2(d) names service provider access explicitly, and the asset-handling policy at 12.2 must reach "anyone who uses or handles assets". Supply chain security under Article 21(2)(d) sits on top of that for the contractual layer.

Does business continuity cover remote workers?
ENISA’s guidance says employees handling critical operations should have backup internet options such as mobile broadband or tethering, and should take part in regular testing of failover including VPN access and voice communications. If your incident response depends on people at home, their connectivity is a continuity dependency.

Where This Leaves You

Remote work did not create a new NIS2 regime and it did not exempt anyone from the old one. It moved regulated systems into premises you do not control, and the Implementing Regulation responded with three qualified words — where appropriate — that hand the decision back to you along with the burden of justifying it. The organisations that will struggle at audit are not the ones with imperfect controls. They are the ones who cannot say why they chose them.

Start with the two unqualified obligations: documented remote-access controls under Annex 6.7.2(d), and an asset-handling policy under 12.2 that names remote and personal devices. Everything else in this article is a decision you record, not a product you buy.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  • Directive (EU) 2022/2555 (NIS2), Article 21 and Recital 56 — EUR-Lex
  • Commission Implementing Regulation (EU) 2024/2690, Recital 18 and Annex points 6.7, 11.7, 12.2 and 13.3 — EUR-Lex (linked above)
  • ENISA, Technical implementation guidance on cybersecurity risk-management measures, version 1.0, June 2025 — linked above
  • Article 21 verbatim text — nis2resources.eu
  • Bundesamt fuer Sicherheit in der Informationstechnik, Tipps fuer sicheres mobiles Arbeiten (bsi.bund.de)
  • Bundesamt fuer Sicherheit in der Informationstechnik, IT-Grundschutz-Kompendium, INF.9 Mobiler Arbeitsplatz, Edition 2023 (bsi.bund.de)
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: