Live webinarMeet Elimity MCP: ask your identity data in Claude, ChatGPT or Copilot21 Oct · 4:00 PM CET21 Oct · 4 PM CETSave your seatSave seat
Blog

IAM evidence for NIS2, DORA and ISO 27001 within 15 seconds

Maarten Decat, CEO and Co-Founder at Elimity · Oct 6, 2026

Compliance🛡

Whether it is NIS2, DORA or ISO 27001, auditors end up asking the same question: who has access to what, and can you prove it?

Answering that has always been painful. Someone exports accounts from Active Directory, someone else pulls the HR leaver list, and a third person spends days matching the two in a spreadsheet. By the time the evidence is ready, it is already out of date.

What auditors actually want to see

Each framework words it differently, but the evidence is largely the same:

  • Accounts that no longer belong to an active employee
  • Privileged and admin accounts, and who owns them
  • Access that was reviewed, and when
  • Proof that the numbers come from the source, not from a manually edited file

NIS2 expects access control policies. DORA expects financial entities to control access to their ICT assets. ISO 27001 covers it in its access control and privileged access requirements. Different regulations, largely the same evidence.

What changes with Elimity on MCP

Elimity is now available through MCP, which means you can ask Claude, ChatGPT or Copilot your audit question in plain language and get the answer from your own identity data.

We tried it on our demo environment.

The question: "How many admin AD accounts are linked to inactive employees?" The answer came back in about 15 seconds: 2,739 accounts. Next to the number, you see the exact query behind it and how terms like "inactive employee" are defined. That is what makes it usable as evidence: an auditor can verify it instead of taking your word for it.

Demo environment, illustrative data.

It is also built to be safe to use. It is read-only, it runs on your own roles and it stays in your own tenant. Find here more info about Elimity on MCP: www.elimity.com/mcp.

What this does not replace

Your governance processes still matter. Access reviews, approvals and offboarding are how you fix findings. What MCP changes is how fast you can see them and prove where you stand, before the auditor asks.

See it live

I will walk through it on October 21st at 4:00 PM CET. Register here.

See Elimity on MCP live, 21 October, 4:00 PM CET