NIS2 · French ReCyF · Accountability
NIS2 and the French ReCyF: control shared accounts without losing accountability
Individual accounts are the normal mechanism because they directly connect an action to a person. Technical or operational constraints can nevertheless require a shared account.
This page details that special case within the NIS2 identity and access use case.
Intended outcome
Limit shared accounts and retain the ability to identify afterwards who used the account.
How to industrialise it
Combine personal identity upstream, temporary assignment, secret rotation, technical traces and suitable organisational procedures.
Reserve sharing for genuine constraints
Sharing weakens accountability. It should remain limited to equipment, long-running sessions or collective activities where individual accounts are not reasonably possible. Where supported, time windows, environments or permitted equipment can constrain use.
Where no technical mechanism is sufficient, a documented organisational measure can complement it by retaining the date, time and identity of the person using the account.
Preserve identity before elevation
For shared privileged access, the administrator’s personal identity can remain known before elevation or use of the common account. PAM may provide a vault, temporary assignment, secret rotation, traces or session control where those functions answer the actual need.
Not every shared account requires a bastion. The mechanism depends on risk, equipment capability and the level of accountability that must be restored.
Evidence to retain
- Inventory and justification of shared accounts
- List and changes of authorised people
- Traces attributing use to a person
- Secret rotation and documented compensating measures
Relevant capabilities and concepts
Privileged access and secrets
Control selected shared or privileged access where justified.
Identity and Active Directory security
Treat emergency and administration accounts in context.
Related controls
Authentication, MFA and secrets
Manage secrets known by several people.
Active Directory and LDAP
Control emergency accounts and delegations.
Sources and guidance
ANSSI — ReCyF in practice — Identity management, version 1.0, September 2026 (French source document)
- ANSSI — Secure administration of information systems (French)
Turn the control into a process
Frame responsibilities, events and evidence before selecting the mechanisms to deploy.