Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Back to the act

EU regulatory register · NIS2

Article 32Supervisory and enforcement measures in relation to essential entities

CELEX 32022L2555 · Read on 2026-08-18 · Chapter VII

Official text

Read from the EU Publications Office for this CELEX number. The wording stands as published; nothing here is rewritten or summarised.

1. Member States shall ensure that the supervisory or enforcement measures imposed on essential entities in respect of the obligations laid down in this Directive are effective, proportionate and dissuasive, taking into account the circumstances of each individual case.

2. Member States shall ensure that the competent authorities, when exercising their supervisory tasks in relation to essential entities, have the power to subject those entities at least to:

(a)

on-site inspections and off-site supervision, including random checks conducted by trained professionals;

(b)

regular and targeted security audits carried out by an independent body or a competent authority;

(c)

ad hoc audits, including where justified on the ground of a significant incident or an infringement of this Directive by the essential entity;

(d)

security scans based on objective, non-discriminatory, fair and transparent risk assessment criteria, where necessary with the cooperation of the entity concerned;

(e)

requests for information necessary to assess the cybersecurity risk-management measures adopted by the entity concerned, including documented cybersecurity policies, as well as compliance with the obligation to submit information to the competent authorities pursuant to Article 27;

(f)

requests to access data, documents and information necessary to carry out their supervisory tasks;

The article continues in the official text.

Open the article on EUR-Lex

Other articles in this chapter

The text is quoted from the official source and is not legal advice. A national court reads the language version that binds in its jurisdiction.

Verifiable trust signals

  • Six fixed blocks, one source per line
  • No sentence written by a language model
  • Engine version and read date on every answer
  • No customer data, no documents, no advice
  • Model card and audit published under the EU AI Act

Model cardAudit