Revolvertech

Empowering Home Computing, Exploring Technology, Immersing in the Gaming Zone, and Unveiling the Business World

EU Cybersecurity Regulations Are Rewriting Access Management Rules for ERP Users

The regulatory landscape for cybersecurity across the European Union has shifted markedly over the past two years. With the NIS2 Directive fully applicable since October 2024 and the Digital Operational Resilience Act in force from January 2025, organisations across Europe now face stricter requirements around how they manage digital access within their own systems. For companies running enterprise resource planning software, particularly those handling financial data or operating in regulated sectors, the implications are real and pressing.

What sets this wave of regulation apart from earlier frameworks is its explicit focus on access control and identity management. Previous directives left much to interpretation. NIS2 and DORA spell out that organisations must demonstrate who has access to what, why, and how conflicts of interest are prevented, putting ERP systems such as Microsoft Dynamics 365 Business Central squarely in the spotlight.

Keeping pace with these developments is becoming a discipline in itself. For teams managing authorisations in Business Central, following news and inspiration from 2-Controlware provides a practical way to track how compliance requirements translate into day-to-day system configuration. The challenge goes beyond knowing the rules: it lies in applying them inside complex software environments where dozens or hundreds of users each need carefully scoped permissions.

What NIS2 demands from internal systems

The NIS2 Directive (Directive (EU) 2022/2555) requires organisations in essential and important sectors to implement risk-based security measures. Among those measures, access control policies and asset management are named explicitly. Organisations must be able to demonstrate that only authorised personnel can reach sensitive functions and data.

In practice, that means mapping out every user role within an ERP system, identifying which combinations of permissions could create conflicts, and monitoring changes over time. A finance team using Business Central where a single user can both create vendors and approve payments faces exactly the kind of segregation-of-duty risk that regulators now expect to see addressed.

The directive covers a broad range of sectors, from energy and transport to digital infrastructure and public administration. Many mid-sized organisations that previously fell outside the scope of the original NIS Directive now find themselves included, a shift that has caught more than a few IT departments off guard.

DORA adds another layer for financial services

Running in parallel is the Digital Operational Resilience Act (Regulation (EU) 2022/2554), which applies specifically to financial entities and their ICT service providers. DORA became applicable in January 2025 and introduced detailed requirements for ICT risk management, including access rights management and the principle of least privilege.

Organisations in banking, insurance or investment services that rely on Dynamics 365 Business Central for financial operations now face an explicit obligation to control and review user permissions on a regular basis. Setting up roles once during implementation and leaving them untouched no longer meets the standard. Continuous monitoring and periodic reviews of access rights are a regulatory expectation.

Where NIS2 sets a broad baseline, DORA drills into operational specifics. Financial regulators across EU member states have been given enforcement powers that include significant fines. The combination of both frameworks means that authorisation management within ERP systems has moved from an IT housekeeping task to a board-level compliance concern.

The gap between regulation and actual system configuration

Knowing what the regulations require is one thing. Translating those requirements into actual permission structures inside Business Central is a different challenge entirely. Microsoft provides a security and protection framework for Business Central that covers permission sets and user groups, yet the native tooling does not always make it straightforward to detect conflicts between roles or enforce segregation of duties at a granular level.

Specialised authorisation software fills that gap. 2-Controlware, based in Breda, has spent over 17 years building tools specifically for designing, managing and monitoring permissions in Business Central. Their product suite includes conflict detection and continuous monitoring, functions that map directly onto the access control expectations set by NIS2 and DORA.

For many IT managers, spreadsheets and manual permission reviews simply no longer suffice. With user counts growing and role structures becoming more complex, automated tooling for authorisation management is shifting from a convenience to a necessity. Organisations that began preparing in 2024 are now in a stronger position, while those that delayed face a steeper path toward compliance.

What to expect through the rest of 2026

Enforcement of both NIS2 and DORA is expected to intensify throughout 2026 as national supervisory authorities finalise their inspection frameworks. In the Netherlands, the transposition of NIS2 into national law has been a protracted process, but the direction of travel is unambiguous. Organisations that can demonstrate robust access control within their ERP systems will be better positioned when auditors arrive.

For anyone responsible for Business Central environments, the message from these regulations is consistent: know your permissions, separate conflicting duties, and monitor continuously. Regulatory guidance documents published by national authorities over the coming months will likely set even more specific benchmarks for what adequate access management looks like in practice.