The NIS2 Directive requires that the entire authentication mechanism be proportionate to the level of risk, operationally resilient, and defensible regarding dependencies on third parties. This means that the assessment covers not just the existence of MFA, but also its implementation method and the impact of potential failures on system access.
In this context, local solutions like SMSEagle serve as a risk-reducing element in the MFA process supply chain. By shortening the OTP delivery path, limiting dependence on external services, and maintaining control over logs and authentication data, organizations can increase the resilience of their authentication mechanisms during incident scenarios. Thus, MFA becomes a true component of organizational operational resilience, in line with both the intent and the letter of NIS2