An article sponsored by Passwork and written by its system analyst Eirik Salmi offers a practical starting point for organizations facing NIS2 compliance with limited budgets. It argues that credential controls are a natural early target because they make access visible, revocable, and reviewable without new infrastructure. The piece cites Verizon's 2026 Data Breach Investigations Report, finding credentials appeared in 28% of breaches.

Under NIS2 Article 21, credential security connects to five measures: basic cyber hygiene, access-control policies, HR security, asset management, and evaluation procedures. The article stresses that MFA is required only "where appropriate," so organizations can prioritize externally exposed applications, remote access, and privileged administration. It also notes a remediation gap: half of third-party cloud MFA exposure findings were resolved within a month, while weak-password and permission-misconfiguration findings took nearly eight months.

Salmi's seven-step "starter stack" begins with privileged and shared access visibility, then moves through dormant-account reviews, MFA, shared credential governance, and service-identity management. Shared credentials are framed as a governance problem: a contractor's departure requires rotating every secret they could access, not just removing their account. Service identities, such as CI/CD pipeline tokens, need vault entries owned by the platform team and scheduled rotation.

Because the article is vendor-sponsored, it closes with how Passwork's on-premise vault covers the stack. Still, the compliance logic and evidence requirements stand independently: policies need logs, review dates, and exception records to satisfy auditors. The author advises building that evidence trail as controls go live rather than reconstructing it before an audit.