- Meaning
- Multi-factor authentication
- Principle
- Several independent factors: knowledge + possession (+ biometrics)
- Benefit
- Protection even when the password is stolen
- Relation to NIS2
- Named expressly in Article 21(2)(j)
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is MFA?
MFA requires at least two independent proofs from different categories when you sign in – typically something you know (a password or a PIN), and something you have (a one-time code from an authenticator app or a hardware token to the FIDO2 standard). Some methods add a third factor, something you are – biometrics such as a fingerprint or face recognition. What matters is that the factors really are independent of one another: if two codes travel over the same compromised channel, the protection is only apparent.
Why MFA is so effective
Most successful attacks begin with stolen credentials – through phishing, data leaks or password reuse. With MFA in place, a captured password alone is no longer enough to sign in, because the second factor is missing. That puts MFA among the most effective and at the same time cheapest technical Controls an organisation can introduce. It does not replace strong passwords, but it catches exactly the cases in which a password ends up in the wrong hands all the same.
Where MFA matters most
The first things to secure are remote access (VPN, webmail, remote desktop), administrative and privileged accounts and business-critical cloud services. Administrator accounts in particular are a favourite target, because they concentrate far-reaching rights, and they should be protected with MFA without exception. On the choice of method: hardware tokens and app-based procedures are markedly safer than SMS codes, which can be intercepted or diverted by SIM swapping.
MFA and NIS2
Article 21(2)(j) of NIS2 names multi-factor authentication or continuous authentication solutions expressly among the risk management measures. For entities in scope it is in practice part of the state of the art. Combined with good Cyber hygiene and regular Security awareness training, it lowers the risk of attack considerably.
For example: A mid-sized machinery manufacturer discovers that an employee entered a Microsoft 365 password on a fake login page. Because MFA with an authenticator app is switched on for every account, the attackers fail at the missing second factor – a potential significant incident carrying a duty to report turns into a harmless phishing attempt, documented internally.
Further reading: ENISA – the EU Agency for Cybersecurity
Frequently asked questions
What is MFA?
MFA stands for multi-factor authentication and requires at least two independent factors from different categories when you sign in: something you know (a password or a PIN), something you have (a code from an app or a hardware token to the FIDO2 standard) and, optionally, something you are (biometrics such as a fingerprint). What matters is that the factors really are independent of one another and do not travel over the same compromised channel.
Why does MFA matter so much?
MFA matters because a stolen password on its own is no longer enough to sign in: without the second factor the attempt fails. Multi-factor authentication therefore blocks a large share of the usual attacks such as phishing and credential stuffing, where most break-ins begin with captured credentials. It is among the most effective and at the same time cheapest technical safeguards, though it does not replace strong passwords.
Is MFA required under NIS2?
Article 21(2)(j) of the directive names multi-factor authentication or continuous authentication solutions expressly among the risk management measures, and it matters most for remote access and administrative accounts. For entities in scope, MFA is in practice part of the state of the art. Leaving it out is the kind of omission Article 34 attaches minimum fine ceilings to: at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities, with Member States free to set higher amounts.