NIS2 Directive
Strong authentication is mandatory.
NIS2 (Directive EU 2022/2555) applies to "essential" and "important" entities — including most MSPs, financial services, healthcare, government and education. Article 21 explicitly requires strong authentication on sensitive actions, including password resets and access to confidential systems.
What "strong" means in practice:
- Knowledge factors alone (password, security questions) are insufficient.
- SMS-OTP alone is considered weak (ENISA / NIST guidance).
- Biometric or document-based verification meets the bar.
- Every authentication must be logged and auditable.
GDPR / AVG
Data subject rights, by design.
GDPR (Regulation EU 2016/679) applies whenever you process personal data. For helpdesks, this means: every verification creates personal data (name, phone, verification result) that you must process lawfully, minimise and document.
The core requirements:
- Lawful basis for processing (legitimate interest works for security checks).
- Data minimisation — only what's strictly needed.
- Storage limitation — delete when no longer required.
- Data subject rights — access, rectification, erasure on request.
- Sub-processor disclosure if you use external vendors.