KeyGuard Password is now KeyCare Pass. Same vault, same account, a new name and address.

Compliance

KeyCare Pass and NIS2

The NIS2 Directive asks essential and important entities in the EU to manage cybersecurity risk. Several of its measures touch how you handle passwords and access.

Get a quote

Prices and options by email

Start business trial

How to get started today

Please read this first

KeyCare Pass is not certified against this framework, and GovPAM does not claim that using it makes an organization compliant. This page describes how KeyCare Pass's features can support your own compliance work. It is not legal or audit advice.

What NIS2 asks for

Directive (EU) 2022/2555, known as NIS2, requires essential and important entities to take appropriate technical, operational and organisational measures to manage cybersecurity risks (Article 21). The measures listed in Article 21(2) include policies on access control, the use of cryptography and encryption, basic cyber hygiene, multi-factor authentication, incident handling and business continuity.

National laws implement the directive, so the exact obligations depend on your country and sector.

Where KeyCare Pass fits

The Article 21(2) measures that a password manager can contribute to.

What is asked forHow KeyCare Pass can helpPlans
Cryptography and encryption (21(2)(h))Vault data is encrypted on each person's device (AES-256 with HMAC-SHA256); keys come from the master password through PBKDF2-SHA256 or Argon2id; traffic uses TLS.All plans
Access control (21(2)(i))Collections with five permission levels, groups and roles; revoke or remove members in one place; the single organization policy.Teams, Enterprise
Multi-factor authentication (21(2)(j))The require two-step login policy; authenticator apps, FIDO2 security keys and passkeys, email codes or Duo.Policy: Enterprise. Two-step login: all plans
Basic cyber hygiene (21(2)(g))Password generator and its policy, master password requirements, and vault health reports for weak, reused and exposed passwords.All plans; policies on Enterprise
Incident handling and effectiveness (21(2)(b), (f))Event logs with times and IP addresses, sign-in activity and alerts, and a public API to collect logs.Teams, Enterprise
Business continuity (21(2)(c))Organization vault export, emergency access, account recovery, and full control of backups when you self-host.All plans; account recovery on Enterprise

What stays with you

A password manager is one control among many. These remain your organization's work:

  • Your risk assessment and the policies built on it
  • Incident reporting to your national authority within the deadlines
  • Supply chain checks, including of GovPAM as a supplier
  • Training staff to use KeyCare Pass and to recognise phishing

Frequently asked questions

Is KeyCare Pass NIS2 compliant?

NIS2 applies to organizations, not products, so there is no product certification to claim. KeyCare Pass can help you implement some of the measures in Article 21.

Where is our data hosted?

Our cloud service runs on servers GovPAM operates in the European Union. You can also host KeyCare Pass yourself.

Need details for your auditor?

Ask us about KeyCare Pass's design, hosting and data handling.