Skip to content
Back to the knowledge base

9

Multi-factor authentication and secured communications

2026-08-10

Cbw art. 21, third paragraph, opening (j) · NIS-2 art. 21(2)(j) · Cbb art. 9 and 15 (elaborated directly by Cbw art. 21)

Opening (j) of the duty of care covers two things often named together: multi-factor authentication and secured communication, even when normal channels fail.

What this means in practice

You introduce multi-factor sign-in for users and for remote access, give extra protection to administrator accounts, secure voice, video and text communication, and arrange secured emergency communication for when normal channels go down.

Why this is in the law

The Cyberbeveiligingsbesluit doesn't elaborate this opening in its own article; the duty sits directly in article 21 Cbw and touches the articles on access policy and crisis communication.

Measures in this family

  • MC-38 — Multi-factor sign-in for users and remote access
  • MC-39 — Extra protection for administrator accounts
  • MC-40 — Secured voice, video and text communication
  • MC-41 — Secured emergency communication when normal channels fail

Sources

Also worth reading

Not sure yet whether this applies to you? Take the free scope check.

Take the free scope check