ENISA Secure by Design: a measurable IAM for GDPR 25 and NIS 2
ENISA’s Secure by Design and Default Playbook provides checklists and minimal evidence. Here’s how a measurable IAM operationalizes these requirements while meeting GDPR art. 25 and NIS 2.
On 30 July 2026, ENISA released its Secure by Design and Default Playbook. Here is how a measurable IAM program operationalizes these recommendations while meeting GDPR (art. 25) and NIS 2 obligations.
The facts
On 30 July 2026, the EU Agency for Cybersecurity (ENISA) published the Secure by Design and Default Playbook, an evidence‑oriented operational guide to help organizations — especially SMEs — embed security controls by design and by default, with action checklists, release gates, and minimal evidence artefacts to be provided at each software delivery. ENISA highlights this guide in its Product Security section and Latest Publications. Sources: ENISA — Publications (30/07/2026), ENISA — Product Security (Playbook, 30/07/2026), ENISA — Private Sector (Playbook, 30/07/2026).
In Luxembourg, as of the law of 5 May 2026, “essential” and “important” entities are supervised under NIS 2 by the ILR, with the SERIMA portal for incident notifications. References: ILR — NISS (NIS 2, resources and SERIMA), Government of Luxembourg — SERIMA launch (02/05/2025).
The applicable legal framework
- GDPR — Article 25 (privacy by design & by default): requires technical and organizational measures “by design and by default” to limit access to strictly necessary data. IAM is a direct lever to demonstrate minimization and self‑control of access. Text: GDPR, art. 25. For local compliance insights, see our GDPR page.
- NIS 2 — Article 21 (risk management measures): requires “policies and procedures” for access, authentication, identity, and privilege management. Operational expectations are further specified by Implementing Regulation (EU) 2024/2690 for some sectors and guided by ENISA’s technical note. Refs: Directive (EU) 2022/2555, ENISA — NIS2 Technical Implementation Guidance (26/06/2025). For the national context, consult NIS 2 in Luxembourg.
- Luxembourg — ILR supervision: NIS 2 obligations transposed by the law of 5 May 2026; SERIMA notification (rapid alert within 24 h, then 72 h, then final report). Ref: ILR — NISS.
The solution to deploy: a measurable, secure‑by‑design IAM
The ENISA Playbook emphasizes release gates and evidence artefacts. In practice, an IAM program aligning GDPR 25 and NIS 2 21 is built around concrete, verifiable controls:
- Identity and account inventory (human and technical) with HR/IT source of authority and SCIM provisioning: each account has an owner, a purpose, and an expiry date. Evidence: SCIM export, identity dictionary, creation/deprovision logs.
- Role‑ and attribute‑based access (RBAC/ABAC) across key apps (SSO); segregation of duties and least privilege embedded in role design. Evidence: role matrix, access policies, automated negative authorization tests in CI.
- Access lifecycle: justified requests, data owner approval, just‑in‑time for sensitive privileges, automatic revocation at end date. Evidence: approval logs, tickets, elevation and revocation timestamps.
- Strong phishing‑resistant authentication for critical access (e.g., passkeys/WebAuthn) and adaptive session policies. Evidence: IdP/tenant configuration, auth reports, samples of conditional policies.
- Periodic recertifications of access to personal data and essential systems, with completion and lead‑time metrics. Evidence: campaign reports, gaps and remediations.
- Centralized traceability: authentication/authorization logs to a SIEM for abuse detection (you cannot prove art. 25 proportionality without reliable logs). Evidence: log pipeline, correlation rules, retention and chain of custody.
- Secrets and non‑human account governance (apps, integrations, bots), rotation and vaulting, with minimal code footprint. Evidence: secret inventory, rotation policies, vault access logs.
Useful frameworks: ISO/IEC 27001:2022 Annex A (A.5.16 Identity management, A.5.17 Authentication information, A.5.18 Access rights), NIST CSF 2.0 (PR.AA — Identity management, authentication and access control), CIS Controls v8 (C5 Accounts, C6 Access Control Management, C15 Service Provider Management).
How Luxgap delivers this
- Our ISO 27001 governance: we structure the identity/access model (ownership, justification, duration) and release gates inspired by the ENISA Playbook. Concretely: role‑mining workshops, mapping of personal data and essential systems, SoD matrix, maturity indicators and minimal evidence per process.
- Managed SOC 24/7: ingestion of IdP/SSO/PAM/EDR logs into a SIEM, detection of access anomalies (privilege escalation, token abuse, impossible travel), and preparation of evidence extractions for ILR (24 h / 72 h / 1 month sequence if an incident occurs).
- Our externalized DPO and CISO consultants: alignment of GDPR art. 25 (privacy by design/by default) with NIS 2 art. 21: minimum access policy, registers, recertification procedures, and effectiveness evidence (timestamped reports and logs). If you need a mandate, see our certified DPO service.
Concrete case in Luxembourg or the EU
A NIS 2‑subject fiduciary centralized identities under a single IdP and enabled SSO across 18 critical apps. In 6 weeks: role‑mining on 5 key functions, just‑in‑time admin, quarterly recertification of client‑file access, and integration of authentication logs into a SOC‑operated SIEM. Result: 62% reduction in standing privileges, deprovisioning time cut from 5 days to < 4 hours, audit‑ready evidence pack (matrices, campaigns, IdP exports) and ability to document an ILR notification in case of incident (timestamps, affected accounts, corrective measures).
First concrete steps
- Build the identity and account inventory (human, technical, third‑party) and link each account to an owner and end date. Export and version it.
- Pick one critical application and enable SSO + phishing‑resistant MFA with restrictive session rules. Document the policy and keep the IdP report.
- Run a targeted recertification for access to sensitive personal data (payroll, HR, client files); record decisions and fix deviations.
- Implement a minimal IAM release gate (checklist + evidence) in your releases: no go‑live if owner/justification/expiry are missing.
- Stream your IAM logs into the SIEM (authentication, authorization, role changes) and define three priority detections. Test and archive results.
Official sources
- ENISA — Publications (Secure by Design and Default Playbook, 30/07/2026)
- ENISA — Product Security (Playbook highlight)
- ENISA — NIS2 Technical Implementation Guidance (26/06/2025)
- EUR‑Lex — GDPR (art. 25)
- EUR‑Lex — Directive (EU) 2022/2555 (NIS 2, art. 21)
- ILR — NISS (NIS 2 in Luxembourg, SERIMA)
- Government LU — SERIMA (02/05/2025)
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →