NIS2 · French ReCyF · Access rights

NIS2 and the French ReCyF: govern access rights and organise recertification

A correctly authenticated identity must still hold the right required to perform an action or access a resource. Authentication and authorisation solve different problems.

This page expands rights governance within the NIS2 identity and access use case.

  • Intended outcome

    Rights limited to actual need, aligned with the person’s situation and removed when no longer justified.

  • How to industrialise it

    Combine roles, rules, requests, approvals, provisioning and recertification around an up-to-date theoretical need.

Assign rights at the right level

Rights are often assigned through groups or profiles. A useful model separates business roles understood by accountable owners from technical roles held in applications and directories. Some entitlements follow automatically from context; others require explicit request and approval.

Least privilege is not limited to initial assignment. On a move, rights must be recalculated and obsolete entitlements removed. On departure, access is fully removed where the rules require it.

Organise review and decision

A recertification campaign compares actual rights with an up-to-date theoretical need. It identifies an owner able to decide, retains the rationale and triggers revocation where access is no longer needed.

Where static rights cannot express the decision, fine-grained authorisation can complement IGA with action, resource and runtime context.

Evidence to retain

  • Catalogue of rights, groups, profiles and owners
  • Requests, approvals and assignment rules
  • Scope, decisions and outcomes of review campaigns
  • History of changes and revocations

Relevant capabilities and concepts

Related controls

Sources and guidance

  • ANSSI — ReCyF in practice — Identity management, version 1.0, September 2026 (French source document)

Turn the control into a process

Frame responsibilities, events and evidence before selecting the mechanisms to deploy.