The NIS2 Directive, which EU member states were required to transpose into national law by October 2024, is now reshaping how organisations approach cybersecurity from the inside out. While much of the public conversation has focused on incident reporting and supply chain risks, a quieter but equally significant shift is happening around access management within business-critical applications.
For technology teams and compliance officers, the directive’s requirements around access control policies represent a tangible change in day-to-day operations. Organisations that rely on enterprise resource planning systems like Microsoft Dynamics 365 Business Central are discovering that generic user permissions no longer pass regulatory scrutiny. The bar has been raised, and the adjustments needed go deeper than many initially expected.
Specialist tooling has become a practical necessity for many mid-sized and larger organisations navigating these new requirements. Providers such as www.2-controlware.com, based in Breda, have spent over 17 years developing authorisation management solutions specifically for Microsoft Dynamics environments. The timing of demand for such granular access control capabilities has accelerated noticeably since transposition deadlines passed across Europe.
What the directive actually demands on access management
Article 21 of the NIS2 Directive, formally known as Directive (EU) 2022/2555, lists access control policies as one of the minimum cybersecurity risk-management measures that essential and important entities must implement. Unlike its predecessor from 2016, NIS2 covers a far broader range of sectors and applies to many more organisations, including those in manufacturing, food production, and digital infrastructure.
The directive does not prescribe specific technical solutions. It does, however, require that access controls are proportionate to the risks an organisation faces. For companies handling financial data, personal records, or supply chain logistics inside an ERP system, that proportionality test often points toward role-based access, segregation of duties, and continuous monitoring of user permissions.
Proving these measures to a regulator is a very different exercise from simply having them in place informally. Documentation, audit trails, and the ability to demonstrate who had access to what and when are now expected as standard.
Why ERP authorisations sit at the centre of the problem
Enterprise resource planning systems are often the single largest repository of sensitive operational data in an organisation. Purchase orders, employee records, bank details, and customer contracts all live inside these platforms. When user permissions are too broad, the risk of unauthorised data access or fraudulent transactions increases substantially.
In Microsoft Dynamics environments, the built-in permission system offers flexibility but also considerable complexity. Business Central contains several thousand permission sets, and many organisations have accumulated custom configurations over years of use. Auditors assessing NIS2 compliance increasingly want to see documented evidence that permissions follow the principle of least privilege rather than a legacy setup that nobody has reviewed since initial implementation.
Segregation of duties is another area where ERP authorisation controls matter significantly. A user who can both create a vendor record and approve a payment to that vendor represents a classic conflict of interest. Detecting and resolving such conflicts manually across a large permission structure is time-consuming and prone to oversight, which is precisely why dedicated authorisation software has gained traction.
The gap between written policy and technical reality
Many organisations already have written access control policies on file. The challenge lies in translating those policies into enforceable technical configurations inside the systems people actually use every working day. A policy stating that finance staff should not access HR data means little if the underlying permission sets do not reflect that boundary.
The European Commission’s overview of NIS2 emphasises that measures should cover the security of network and information systems, including the handling of incidents. For most organisations, that security starts with knowing precisely who can do what inside their core applications. Automated tools that map, manage, and monitor authorisations provide the kind of auditable trail that regulators expect, far beyond what a spreadsheet-based review can deliver.
What this means for technology teams in 2026
The practical reality for IT managers and application administrators is that authorisation management can no longer be a background task handled reactively. NIS2 has moved it firmly to the foreground. Organisations working with Business Central are finding that dedicated authorisation tooling, rather than periodic manual reviews, offers the most reliable path to demonstrable compliance.
The wider regulatory landscape reinforces this shift. The Digital Operational Resilience Act, known as DORA, applies similar logic to financial entities across the EU. Combined with ongoing obligations under the GDPR, the regulatory expectation is consistent: access to sensitive systems must be controlled, documented, and reviewable at any point. For teams managing complex ERP environments with dozens or hundreds of users, the operational cost of not having proper access governance tooling in place now outweighs the investment required to implement it.