NIS2 · French ReCyF · Access rights
NIS2 and the French ReCyF: govern access rights and organise recertification
A correctly authenticated identity must still hold the right required to perform an action or access a resource. Authentication and authorisation solve different problems.
This page expands rights governance within the NIS2 identity and access use case.
Intended outcome
Rights limited to actual need, aligned with the person’s situation and removed when no longer justified.
How to industrialise it
Combine roles, rules, requests, approvals, provisioning and recertification around an up-to-date theoretical need.
Assign rights at the right level
Rights are often assigned through groups or profiles. A useful model separates business roles understood by accountable owners from technical roles held in applications and directories. Some entitlements follow automatically from context; others require explicit request and approval.
Least privilege is not limited to initial assignment. On a move, rights must be recalculated and obsolete entitlements removed. On departure, access is fully removed where the rules require it.
Organise review and decision
A recertification campaign compares actual rights with an up-to-date theoretical need. It identifies an owner able to decide, retains the rationale and triggers revocation where access is no longer needed.
Where static rights cannot express the decision, fine-grained authorisation can complement IGA with action, resource and runtime context.
Evidence to retain
- Catalogue of rights, groups, profiles and owners
- Requests, approvals and assignment rules
- Scope, decisions and outcomes of review campaigns
- History of changes and revocations
Relevant capabilities and concepts
Identity governance
Model entitlements and organise their decision lifecycle.
Fine-grained authorisation
Complement static roles where context matters.
Access review
Structure review scope, decision and evidence.
Least privilege
Keep rights limited to actual need over time.
Related controls
Identification and lifecycle
Trigger rights changes from authoritative context.
Authentication, MFA and secrets
Verify identity before making an authorisation decision.
Sources and guidance
ANSSI — ReCyF in practice — Identity management, version 1.0, September 2026 (French source document)
Turn the control into a process
Frame responsibilities, events and evidence before selecting the mechanisms to deploy.