Network Access Control has not become less important.
The way organisations buy and operate it has simply failed to keep pace with modern networks.
Businesses need to know more than ever what is connected to their networks.
Regulatory tailwinds such as NIS2, cyber-insurance requirements and customer supply-chain assessments are increasing expectations around asset visibility, authentication, access control and audit evidence. These are no longer concerns reserved for large enterprises. They are becoming practical requirements for SMEs as well.
The problem is that traditional enterprise NAC was rarely designed for them.
Traditional NAC Was Built for the Enterprise
Conventional Network Access Control deployments often require multiple appliances or virtual machines, dedicated databases, certificate infrastructure, specialist consultants and complex licensing.
Even after deployment, the organisation remains responsible for upgrades, patches, backups, availability and capacity planning.
That model can work for a large enterprise with a dedicated NAC team. It is much harder to justify for an SME or an MSP managing multiple customer environments.
The result is a gap in the market.
SMEs face many of the same security expectations as larger organisations, but traditional NAC solutions can cost more, take longer to deploy and demand more specialist knowledge than their networks justify.
The Need for Network Access Control Is Growing
The modern network contains far more than corporate laptops.
Printers, cameras, phones, building-management systems, conference equipment, sensors and other headless devices all require connectivity. Organisations must also support employees, contractors, guests and managed mobile devices.
A shared Wi-Fi password or an open switch port cannot provide meaningful control over this environment.
A modern NAC platform should help answer three basic questions:
- What is connecting?
- How do we know it can be trusted?
- What should it be allowed to access?
For managed devices, certificate-based EAP-TLS provides a strong alternative to shared credentials. For equipment that cannot support IEEE 802.1X, MAC Authentication Bypass, or MAB, can provide a controlled fallback when combined with device profiling and restrictive access policies.
The objective is not simply to block devices. It is to make network access visible, predictable and auditable.
Arbiter Removes the Infrastructure Burden
Traditional Network Access Control often requires organisations to deploy and maintain RADIUS servers, policy nodes, databases, certificate infrastructure and high-availability systems.
Arbiter changes that operating model.
The core NAC, RADIUS, policy and PKI services are delivered as a managed cloud platform, while Arbiter Edge provides secure connectivity and local resilience at the customer site.
There are no NAC appliances or policy-server clusters for the customer to size, patch or upgrade.
Authentication and authorisation remain standards-based, using technologies such as:
- RADIUS
- RadSec
- IEEE 802.1X
- EAP-TLS
- Dynamic VLAN and ACL assignment
This allows Arbiter to work across Cisco, Aruba and other RADIUS-capable network infrastructure without requiring a vendor-specific network design.
Organisations can focus on deciding who and what should access the network rather than maintaining the infrastructure required to make those decisions.
Cisco, Aruba and the Network You Already Have
Replacing the network should not be a prerequisite for improving network security.
Arbiter uses established standards supported across major enterprise network vendors, including Cisco switches, Cisco wireless controllers, Aruba switches and Aruba wireless networks.
That matters because most business networks are not built from one vendor or one hardware generation.
An organisation may have Cisco switching at one location, Aruba wireless at another and older infrastructure inherited through growth or acquisition.
A standards-based NAC platform provides a consistent authentication and authorisation layer across these environments without requiring proprietary enforcement mechanisms or a complete hardware refresh.
Cloud Does Not Have to Mean Cloud-Dependent
Authentication sits directly in the path of network access. A WAN outage should not prevent known employees and devices from connecting.
Arbiter Edge is designed to maintain local continuity when connectivity to the cloud is unavailable.
Cached access decisions allow known devices to continue authenticating, while local certificate validation supports continued EAP-TLS authentication for managed endpoints. Unknown devices can remain restricted until connectivity returns.
When the cloud connection is restored, locally recorded authentication events are synchronised back to the platform to preserve the audit trail.
This combines centralised cloud management with local resilience rather than making every network connection dependent on a live internet service.
Start with Asset Discovery, Not Enforcement
Not every organisation is ready to deploy full Network Access Control immediately.
For many SMEs, the first priority is understanding what is connected to the network and creating an accurate asset inventory.
Arbiter's Asset Discovery tier provides a visibility-only entry point. It profiles and inventories devices but does not enforce network access.
Device discovery can be turned into an audit-ready NIS2 asset register, with fields for:
- Ownership
- Criticality
- Business function
- Location
- Device type
- Operating system
- Manufacturer
Asset records can also be enriched automatically using MDM and RADIUS authentication data, reducing the amount of manual record-keeping required.
This allows an organisation to establish network visibility, identify unknown equipment and improve its asset-management evidence before introducing 802.1X authentication or access-control policies.
The Asset Discovery tier includes a 60-day free trial and costs €29 per month afterwards.
When the organisation is ready, it can upgrade to an access-control tier without rebuilding its asset inventory or starting a separate NAC project.
A Practical Starting Point for NIS2
NIS2 does not prescribe a specific Network Access Control product.
It does, however, increase the importance of asset visibility, authentication, access management, risk management and evidence that security controls are operating as intended.
For an SME, this begins with practical questions:
- Do we know which devices are connected?
- Can we distinguish managed equipment from unknown devices?
- Can access be revoked when an employee leaves or a device is lost?
- Are guests and unmanaged systems isolated?
- Can we show how network access decisions are made?
Traditional NAC often made answering these questions expensive and disruptive.
Arbiter supports a gradual adoption path.
An organisation can begin with Asset Discovery, build its NIS2 asset register and identify unknown devices without enforcing any changes.
It can then introduce controls progressively:
- Certificate-based 802.1X for managed devices
- Secure Wi-Fi authentication without shared passwords
- MAB for printers, cameras and IoT equipment
- Dynamic VLAN or ACL assignment
- Guest network isolation
- RADIUS accounting and authentication audit records
This turns NAC into a manageable security programme rather than a large infrastructure project.
NAC Without the Traditional NAC Project
The future of Network Access Control is not another appliance cluster, advanced licence or six-month consulting engagement.
It is a cloud-managed, locally resilient service built on standards the network already supports.
For SMEs, that means better asset visibility, stronger authentication and clearer evidence for NIS2, insurers and customers.
For MSPs, it means delivering repeatable NAC services across Cisco, Aruba and mixed-vendor customer networks without constructing a separate enterprise platform for every tenant.
NAC is not disappearing.
It is becoming simpler, more accessible and better suited to the organisations that now need it most.