Just-in-Time Access Software
an independent guide to JIT access software
Subscribe
Landscape

Regulatory and Compliance Pressure: Where ZSP Stopped Being Optional

For most of the last decade, eliminating standing privileged access was a security best practice that auditors politely recommended and budget cycles politely deferred. That's changed. Across the frameworks that actually carry enforcement weight, least privilege and just-in-time access have moved from recommended controls to named requirements with named consequences for ignoring them.

NIST SP 800-53: the access control backbone

NIST SP 800-53 Revision 5 is the control catalog most U.S. federal systems and their contractors are evaluated against, and its Access Control family is where JIT shows up directly. AC-6 (Least Privilege) and its enhancements require organizations to authorize, restrict, and periodically review privileged accounts; AC-6(7) specifically calls for review of user privileges to confirm continued need. AC-2 (Account Management) goes further: its enhancements address automated temporary and emergency account management and dynamic privilege management, which is essentially a control-catalog description of what a JIT platform does. A standing administrative credential that never gets reviewed isn't a minor finding under this framework. It's a direct AC-6/AC-2 gap.

PCI DSS 4.0.1: least privilege with a deadline that already passed

The grace period on PCI DSS 4.0's future-dated requirements closed March 31, 2025, which means every 2026 assessment is being scored against the full standard, not a transition allowance. Requirement 7.2.4 mandates that human account privileges be reviewed at least every six months, and system or application accounts on a frequency set by a documented targeted risk analysis. Requirement 7.2.5 restricts application and system accounts to least privilege, and accounts with interactive login capability now require documented business justification and credential management, commonly through a vault or equivalent control. The standard doesn't name JIT directly, but the access pattern it's describing, time-bound, justified, reviewed, logged, is the JIT pattern.

DORA and NIS2: continuous, not quarterly

In the EU, the Digital Operational Resilience Act applies to financial entities and the third-party ICT providers that serve them. Its regulatory technical standards on ICT risk management, under Article 21, require that access rights be assigned based on need-to-know and least privilege, including for remote and emergency access, with prompt revocation of unnecessary rights and automated privileged access management deployed where feasible. NIS2, which applies to essential and important entities across 18 sectors EU-wide, carries a parallel access control requirement under Article 21 of its own risk management measures.

What distinguishes both frameworks from older compliance language is the word continuous. DORA's emphasis on ongoing ICT risk monitoring, rather than point-in-time audit snapshots, is difficult to satisfy with a permanent administrative account that sits outside any time-bound review cycle. A standing credential doesn't generate the kind of continuous, attributable access record these frameworks are built around. A JIT-issued, automatically expiring one does.

What this means for the buying decision

None of these frameworks say "buy a JIT platform." None of them have to. They describe an access pattern, time-bound, justified, automatically revoked, reviewed on a defined cadence, that a standing-privilege model cannot produce evidence for without manual reconstruction after the fact. That gap is what's pulling JIT out of the "nice to have" column and into the part of the budget that gets approved without much debate.

Finding

A platform's audit trail and review-cadence reporting matter as much as its access-granting mechanics. A tool that grants time-bound access cleanly but produces a flat activity log is solving half the compliance problem. The frameworks above are asking for evidence, not just enforcement, and the platforms that generate audit-ready reporting natively are doing more of the compliance work for you than the ones that require a SIEM integration to back it out after the fact.

Related: Market direction  ·  Full vendor comparison tool