9
Multi-factor authentication and secured communications
2026-08-10
Cbw art. 21, third paragraph, opening (j) · NIS-2 art. 21(2)(j) · Cbb art. 9 and 15 (elaborated directly by Cbw art. 21)
Opening (j) of the duty of care covers two things often named together: multi-factor authentication and secured communication, even when normal channels fail.
What this means in practice
You introduce multi-factor sign-in for users and for remote access, give extra protection to administrator accounts, secure voice, video and text communication, and arrange secured emergency communication for when normal channels go down.
Why this is in the law
The Cyberbeveiligingsbesluit doesn't elaborate this opening in its own article; the duty sits directly in article 21 Cbw and touches the articles on access policy and crisis communication.
Measures in this family
- MC-38 — Multi-factor sign-in for users and remote access
- MC-39 — Extra protection for administrator accounts
- MC-40 — Secured voice, video and text communication
- MC-41 — Secured emergency communication when normal channels fail
Sources
Also worth reading
Not sure yet whether this applies to you? Take the free scope check.
Take the free scope check