Brussels — With EU member states completing transposition of the NIS2 Directive and enforcement activity ramping in 2025, organizations across critical and important sectors are increasingly treating third‑party access as a front‑line zero‑trust problem. Security teams and vendors say regulatory pressure is converting long‑standing best practices into measurable controls: just‑in‑time privileged access, continuous device attestation, granular session brokering, and microsegmentation of supply‑chain connections.
Regulatory trigger, practical consequences
The NIS2 Directive, formally adopted by the EU in 2022 and transposed into national law by member states in 2024, tightens incident reporting, governance and security requirements for dozens of sectors ranging from energy and transport to digital infrastructure and health. While NIS2’s text focuses broadly on governance and cyber risk management, regulators and supervisors have emphasized third‑party risk as a frequent root cause of major incidents—pushing organizations to adopt zero‑trust access principles for vendors, contractors and managed service providers.
“NIS2 moved third‑party access from an operational headache to a compliance obligation,” said an EU‑based CISO at a mid‑size utility who requested anonymity. “We now have to show not just policies but technical evidence: who accessed what, from which device, under what policy, and whether that posture was evaluated continuously.”
What organizations are changing
- Privileged access goes just‑in‑time (JIT). Where long‑standing vendor VPN accounts or always‑on bastions were common, security teams are rapidly implementing JIT workflows that provision ephemeral credentials for a narrowly scoped window and specific resource.
- Continuous device and session attestation. Static allow‑lists are being replaced by continuous evaluation of device posture: OS integrity, patch status, endpoint protection telemetry and cryptographic device identifiers.
- Brokered and isolated sessions. Firms are moving away from broad network access toward session brokering models that mediate vendor sessions at the application layer—ensuring recordings, file controls and explicit file‑transfer policies.
- Microsegmentation and explicit data flows. Engineering teams are defining and enforcing minimal east‑west access for third parties, isolating critical control networks and limiting what vendors can reach even when authenticated.
Vendor and market response
Vendors in the zero‑trust and identity ecosystems report a surge in demand for bundled solutions that map directly to regulatory evidence requirements. Managed security providers are packaging compliance‑focused services that pair identity controls (MFA, conditional access) with session recording, just‑in‑time privilege elevation and attestation attestation services.
Security product managers say customers increasingly request built‑in audit trails that match NIS2 reporting expectations: time‑stamped session metadata, device posture history, and exportable attestations for auditors. The market is also seeing more pre‑built playbooks geared toward sectoral needs—OT/ICS suppliers, for example, want brokered access with strictly enforced operational command sets and immutable audit logs.
Integration pain points
Transitioning to robust zero‑trust third‑party access, however, is not straightforward. Technical teams cite several recurring challenges:
- Legacy systems and OT constraints. Many industrial control systems cannot tolerate agents or frequent credential rotation, complicating device posture assessment.
- Vendor willingness and capability. Not all third parties have modern identity stacks or the ability to integrate client certificates and attestation flows—contract negotiation becomes part of implementation.
- Operational friction. Security teams must balance tighter controls with the need for rapid vendor response during outages; overly rigid JIT and attestation policies can slow critical maintenance.
How organisations are bridging the gaps
Security leaders describe a mix of technical mitigations and governance changes that have become common in pilot and production deployments:
- Risk‑based scoping. Firms prioritize zero‑trust for vendors with access to sensitive systems or data, while using lighter controls for lower‑impact suppliers.
- Contractual and onboarding upgrades. Procurement templates now require minimum identity and logging standards, periodic attestation of vendor security posture and rights to audit.
- Brokered OT gateways. For legacy OT, organizations deploy isolated access gateways that mediate vendor commands without exposing the control network—offering session recording, command filtering and read‑only modes when needed.
- Cross‑team playbooks. Incident response and vendor liaison teams conduct tabletop drills to ensure access revocation and emergency maintenance procedures work under tighter zero‑trust controls.
What auditors and supervisors are watching
Supervisory bodies implementing NIS2 emphasize demonstrable controls over theoretical frameworks. That means auditors expect evidence: access logs, attestation records, least‑privilege policies applied to third‑party identities, and contractual proof that vendors meet minimum security baselines. Those seeking to show compliance are focusing on the measurability of their zero‑trust controls as much as their existence.
“Supervisors want to see traceability from policy to enforcement to evidence,” said a compliance lead at a pan‑European bank. “Zero trust gives you the policy model; the challenge is operationalising it without blocking essential third‑party work.”
What this means for Zero Trust practitioners
For zero‑trust networking enthusiasts and practitioners, the NIS2‑driven acceleration offers both opportunity and pressure. Opportunity, because clearer regulatory expectations create a stronger business case for investments in ZTNA, microsegmentation and device attestation. Pressure, because organizations must now stitch heterogeneous systems, vendors and legacy infrastructure into auditable zero‑trust flows within fixed compliance timelines.
Expect the next 12–18 months to bring more sector‑specific templates, managed‑service offerings tuned to NIS2 evidence needs, and an uptick in product features that simplify device attestation and session brokering. For teams implementing zero‑trust for third‑party access, the practical advice is familiar but urgent: start with high‑risk vendor relationships, build measurable controls, and align procurement and legal teams early.