NIS2 and DORA compliance starts at the service desk

Both regimes require that identity is verified before privileged actions are performed, and that you can prove it afterwards. Most organisations still leave that decision to an agent on a phone call.

01 · THE GAP

The control your framework probably does not cover

You have MFA. You have conditional access. You have a privileged access management tool.

Then a user calls the service desk and says they have lost their phone. In that moment every one of those controls is suspended, and the decision to restore access rests on an agent's judgement about a voice on a line. Social engineering attacks on IT help desks cost MGM Resorts and Clorox more than $480 million between them, and both started with a single phone call.

Under NIS2 and DORA this is no longer only an operational weakness. It is a control gap a supervisor can ask you to evidence.

FastPass Identity Verification Manager(opens in new tab) (IVM) closes it. IVM enforces a policy-driven verification workflow(opens in new tab) inside your existing ITSM platform, decides the outcome by rule rather than by agent discretion, and writes the evidence straight back to the ticket.

02 · THE REQUIREMENT

What the regulations actually say

» EU · NIS2 DIRECTIVE

Directive (EU) 2022/2555

Applies to essential and important entities across energy, transport, banking, health, water, digital infrastructure, public administration and manufacturing.

Requirement Reference At the service desk
Access control policies and human resources securityArt. 21(2)(i)Access restoration must follow a defined policy, not agent habit
Multi-factor or continuous authenticationArt. 21(2)(i)The factor must still hold when the user calls to bypass it
Incident handlingArt. 21(2)(b)A social engineering attempt must be detectable and reportable
Supply chain securityArt. 21(2)(d)An outsourced service desk sits inside your risk management
Management body accountabilityArt. 20Boards approve the measures and can be held personally liable
Reporting deadlinesArt. 23Early warning within 24 hours, notification within 72 hours

Supervisory fines reach EUR 10 million or 2% of global annual turnover for essential entities, and EUR 7 million or 1.4% for important entities.

» EU · DORA

Regulation (EU) 2022/2554

Directly applicable to financial entities across the EU since 17 January 2025. The operational detail sits in the RTS on ICT risk management, Commission Delegated Regulation (EU) 2024/1774.

Requirement Reference At the service desk
Strong authentication mechanismsDORA Art. 9(4)(d)Credential restoration is an authentication event and needs the same rigour
Least privilege and access rights administrationDORA Art. 9(4)(c)Agents should not hold standing rights over the identities they support
Identity managementRTS Art. 20Unique identity, accountable actions, controlled lifecycle
Access control policyRTS Art. 21Need-to-know, account lifecycle, authentication proportionate to risk
LoggingRTS Art. 12Access events recorded, retained and available for reconstruction
ICT third-party riskDORA Art. 28 to 30Contracted service desk providers must meet the same standard

DORA has no fixed fine schedule. Supervisors can require remediation, restrict arrangements with providers, and hold named senior managers responsible.

The shared principle

Neither regime asks whether you have a verification procedure written down. Both ask whether it was applied, every time, and whether you can produce the record.

03 · THE MAPPING

Where FastPass IVM meets the requirement

Verification is enforced by the system, not chosen by the agent
Covers NIS2 Art. 21(2)(i) and (j) · DORA Art. 9(4)(d) · RTS Art. 20, 21

The security team defines the policy. IVM runs it. The agent sees a workflow with a pass or fail outcome and cannot skip a mandatory proofing step or improvise an alternative. Verification is scored, so weak factors alone do not clear the threshold, and the required score differs by user group, request type and risk signal. Factors include Microsoft Entra ID, Okta, Duo, RSA, TOTP, smartcard, SMS, email, manager approval, device confirmation from an enrolled workstation, and encrypted HR keyword data where the agent sees only match or no-match.

The evidence is produced automatically
Covers NIS2 Art. 21(2)(b) and Art. 23 · DORA Art. 9 · RTS Art. 12

Every attempt is logged, including the ones that failed or were abandoned. The record captures the factors presented, the score reached, the outcome, the timestamp, the agent identity and the ticket reference, and it is written back into the ITSM ticket. Audit data sits in SQL Server and can feed Microsoft Sentinel, Splunk or any SIEM through database access or ETL. Two practical consequences. An auditor sampling tickets sees system-generated evidence rather than an agent's free-text note. And a cluster of failed verifications against one identity becomes a signal you can act on inside the 24-hour NIS2 early warning window.

Agents stop holding standing privilege
Covers NIS2 Art. 21(2)(i) · DORA Art. 9(4)(c) · RTS Art. 21

Agents run the full IVM workflow without elevated directory rights. The privileged action, whether an Entra ID password reset, an MFA re-enrolment or an account unlock, is executed by the system only once the verification policy has been satisfied. Between 50% and 60% of FastPass customers have removed agent directory privileges on this basis. That turns a permanent standing-privilege finding into a controlled, evidenced transaction.

Temporary Access Passes are gated
Covers DORA Art. 9(4)(d) · RTS Art. 21 · NIS2 Art. 21(2)(j)

A TAP bypasses MFA by design, which makes it the highest-value item a social engineer can ask for. IVM issues a TAP only after the policy for that user has been met, and logs the issuance against the verified session. As Microsoft moves Entra ID towards passwordless, TAP volume rises and this control moves from useful to load-bearing.

Assurance scales with the risk of the identity
Covers DORA Art. 6 and Art. 9 proportionality · NIS2 Art. 21(1)

A warehouse worker without a smartphone and a domain administrator should not clear the same bar. IVM sets separate policies by group, so routine requests stay fast while privileged accounts, finance staff and executives are pushed through stricter combinations. Proportionality is a stated principle in both regimes, and this is what it looks like in practice.

Both directions of the call are covered
Covers NIS2 Art. 21(2)(g) · DORA Art. 9

Attackers also impersonate the service desk to harvest credentials from employees. IVM supports reverse verification, where the end user confirms the caller is a genuine agent through a desktop or browser flow that only functions while that agent has the user open in IVM, with the agent's name displayed for confirmation.

Outsourced service desks are held to the same policy
Covers NIS2 Art. 21(2)(d) · DORA Art. 28 to 30 · RTS on subcontracting (EU) 2025/532

If a managed service provider runs your first line, DORA treats them as an ICT third-party service provider and NIS2 treats them as supply chain risk. Contractual language alone does not evidence enforcement. FastPass IVM is deployed multi-tenant by MSPs, so the policy you define is the policy their agents execute, and the audit trail lands in your ticket rather than in theirs.

04 · COMPARISON

Legacy service desk against verified service desk

Typical service desk With FastPass IVM
Verification methodKnowledge questions, caller ID, voice recognitionScored combination of MFA, device, HR data and approval
Who decidesThe agent, under time pressureThe policy, enforced by the system
Deepfake and vishing exposureHigh, the control is human perceptionLow, no factor depends on how the caller sounds
Agent privilegeStanding rights over directory objectsNo standing rights required to run verification
Audit evidenceFree-text note reading "ID verified"System record of factors, score, outcome, timestamp, agent, ticket
Failed attemptsUsually not recorded at allLogged and available to SIEM
Policy changeRetraining, memos, hopeConfiguration change, effective on the next call
"Prove it"Sampling tickets and interviewing agentsExport the log

05 · AUDIT READINESS

What an auditor or supervisor will ask for

Bring these five things to the review. IVM produces all of them.

1. The written verification policy, per user population, with the risk rationale.


2. Proof that the policy was technically enforced rather than communicated.


3. A complete record of verification events, successful and failed, for the sample period.


4. Evidence that privileged actions followed successful verification and not the reverse.


5. Evidence that the same standard applied to outsourced and after-hours support.

07 · QUESTIONS

Questions from compliance and security teams

Does FastPass IVM make us NIS2 or DORA compliant?

No product does. Compliance is an organisational obligation covering governance, risk management, continuity, reporting and supply chain, and no single tool discharges it.

What IVM does is close one specific control gap, help desk identity verification(opens in new tab), and produce the evidence that the control operated. We supply a mapping document referencing the relevant articles so your GRC team can drop it into the control framework alongside everything else.

We are a financial entity. Does DORA name the service desk explicitly?
Our NIS2 gap assessment did not flag the help desk. Should it have?
Does verification slow the service desk down?
What about users with no smartphone, or users who are fully locked out?
Can we prove the policy was followed on a specific ticket?
Where is the data held?

FastPassCorp A/S · Frederiksborggade 15.3, 1360 Copenhagen · Listed on Nasdaq First North Copenhagen. This page is provided for information and is not legal advice. Regulatory obligations depend on your sector, size and national transposition.

Close the gap before your supervisor finds it

Most organisations discover this control gap in one of three ways. An auditor asks how a password reset was authorised. A penetration tester calls the service desk and gets in. Or an attacker does.

Scroll to Top