Glossary · Term

MFA explained

MFA, or multi-factor authentication, means signing in with several factors – a password plus an app or a token, for example.

At a glance
Meaning
Multi-factor authentication
Principle
Several independent factors: knowledge + possession (+ biometrics)
Benefit
Protection even when the password is stolen
Relation to NIS2
Named expressly in Article 21(2)(j)
Updated
June 2026
Editorial team
Compliance Compass

What is MFA?

MFA requires at least two independent proofs from different categories when you sign in – typically something you know (a password or a PIN), and something you have (a one-time code from an authenticator app or a hardware token to the FIDO2 standard). Some methods add a third factor, something you are – biometrics such as a fingerprint or face recognition. What matters is that the factors really are independent of one another: if two codes travel over the same compromised channel, the protection is only apparent.

Why MFA is so effective

Most successful attacks begin with stolen credentials – through phishing, data leaks or password reuse. With MFA in place, a captured password alone is no longer enough to sign in, because the second factor is missing. That puts MFA among the most effective and at the same time cheapest technical Controls an organisation can introduce. It does not replace strong passwords, but it catches exactly the cases in which a password ends up in the wrong hands all the same.

Where MFA matters most

The first things to secure are remote access (VPN, webmail, remote desktop), administrative and privileged accounts and business-critical cloud services. Administrator accounts in particular are a favourite target, because they concentrate far-reaching rights, and they should be protected with MFA without exception. On the choice of method: hardware tokens and app-based procedures are markedly safer than SMS codes, which can be intercepted or diverted by SIM swapping.

MFA and NIS2

Article 21(2)(j) of NIS2 names multi-factor authentication or continuous authentication solutions expressly among the risk management measures. For entities in scope it is in practice part of the state of the art. Combined with good Cyber hygiene and regular Security awareness training, it lowers the risk of attack considerably.

For example: A mid-sized machinery manufacturer discovers that an employee entered a Microsoft 365 password on a fake login page. Because MFA with an authenticator app is switched on for every account, the attackers fail at the missing second factor – a potential significant incident carrying a duty to report turns into a harmless phishing attempt, documented internally.

Further reading: ENISA – the EU Agency for Cybersecurity

Frequently asked questions

What is MFA?

MFA stands for multi-factor authentication and requires at least two independent factors from different categories when you sign in: something you know (a password or a PIN), something you have (a code from an app or a hardware token to the FIDO2 standard) and, optionally, something you are (biometrics such as a fingerprint). What matters is that the factors really are independent of one another and do not travel over the same compromised channel.

Why does MFA matter so much?

MFA matters because a stolen password on its own is no longer enough to sign in: without the second factor the attempt fails. Multi-factor authentication therefore blocks a large share of the usual attacks such as phishing and credential stuffing, where most break-ins begin with captured credentials. It is among the most effective and at the same time cheapest technical safeguards, though it does not replace strong passwords.

Is MFA required under NIS2?

Article 21(2)(j) of the directive names multi-factor authentication or continuous authentication solutions expressly among the risk management measures, and it matters most for remote access and administrative accounts. For entities in scope, MFA is in practice part of the state of the art. Leaving it out is the kind of omission Article 34 attaches minimum fine ceilings to: at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities, with Member States free to set higher amounts.

Technical measures

Sign in securely, prove it easily

Compliance Compass documents measures such as MFA as audit-proof evidence for your NIS2 compliance.