Here is an overview of the supervisory powers granted to national competent authorities under the NIS2 Directive.
NIS2 Directive: Supervision by national authorities
The NIS2 Directive grants national competent authorities a set of supervisory powers to ensure that essential and important entities comply with cybersecurity risk management and incident reporting requirements. These powers are designed to facilitate effective oversight and promote a consistent level of cybersecurity across the EU. For organizations falling within the scope of the directive, understanding these mechanisms is the first step in structuring an appropriate NIS2 compliance path.
Main supervisory powers under the NIS2 Directive
- Preventive supervisory measures for essential entities: The Directive provides for a stricter supervisory regime for essential entities, requiring competent authorities to actively monitor their compliance with cybersecurity requirements.
- Regular and targeted audits: Competent authorities may conduct regular audits to assess the overall level of cybersecurity of essential entities. They may carry out targeted audits on specific areas of concern.
- On-site and off-site inspections: To verify compliance and collect evidence, competent authorities may conduct on-site inspections at the entity’s premises and perform off-site inspections by requesting documentation or access to systems.
- Ex-post supervisory measures for important entities: For important entities, the Directive adopts a more reactive approach. It focuses on ex-post supervisory measures triggered by evidence or indications of non-compliance.
- Investigations: If an important entity may not be complying with NIS2, authorities may initiate investigations to verify non-compliance.
- Targeted Security Audits: Authorities may request audits conducted by independent experts to assess security measures and identify vulnerabilities.
- Security Scans: Authorities may perform scans on the entity’s systems, using objective and transparent assessment criteria, in collaboration with the entity to minimize operational impact.
Powers to request information and access
- Requests for information: Competent authorities may require essential and important entities to provide information necessary to assess their practices, including:
- Documented cybersecurity policies.
- Evidence of compliance with incident reporting obligations.
- Results of security audits performed by qualified auditors.
- Access to data, documents, and systems: To conduct their supervisory activities, competent authorities have the power to request access to data, documents, and other information relevant to their assessment. This includes:
- Security logs and incident reports.
- Vulnerability assessments and penetration test results.
- Evidence of cybersecurity training programs.
Differentiation of supervisory regimes under the NIS2 Directive
- Essential entities: The Directive establishes a broader and more proactive supervisory regime for essential entities.
- Important entities: The supervisory regime for important entities is more focused and reactive, relying primarily on ex-post measures triggered by evidence or indications of non-compliance.
Collaboration and information sharing
- Cooperation with data protection authorities: If a security incident involves personal data, competent authorities must cooperate with data protection authorities for a coordinated response.
- Information sharing: The Directive encourages the exchange of data between national and cross-border authorities regarding incidents, threats, and cybersecurity best practices.
Overall, the NIS2 Directive provides national competent authorities with a comprehensive set of supervisory powers to oversee the implementation of cybersecurity requirements by essential and important entities. To delve deeper into the reference regulatory framework, the official NIS2 Directive document is available. With these powers, competent authorities can contribute to a higher level of cybersecurity across the EU.
Frequently Asked Questions about NIS2 supervisory powers
- What is the practical difference between the supervision of essential entities and that of important entities?
- For essential entities, the regime is proactive: authorities conduct regular audits and inspections even in the absence of signs of non-compliance. For important entities, the approach is reactive: checks are triggered primarily when evidence or indications of a breach of NIS2 requirements emerge.
- What can a competent authority request during a NIS2 inspection?
- Authorities may request documented security policies, system logs, incident reports, audit and penetration test results, as well as evidence of staff training programs. They may also conduct physical on-site inspections or access systems remotely.
- How can an organization prepare for NIS2 audits?
- It is useful to maintain up-to-date documentation on security measures adopted, keep logs of incidents and vulnerability assessment results, and verify that internal policies are aligned with the directive’s requirements. An analysis of one’s compliance level, conducted before an inspection arrives, significantly reduces the risk of penalties.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
