EU regulatory register · NIS2
Article 33Supervisory and enforcement measures in relation to important entities
CELEX 32022L2555 · Read on 2026-08-18 · Chapter VII
Official text
Read from the EU Publications Office for this CELEX number. The wording stands as published; nothing here is rewritten or summarised.
1. When provided with evidence, indication or information that an important entity allegedly does not comply with this Directive, in particular Articles 21 and 23 thereof, Member States shall ensure that the competent authorities take action, where necessary, through ex post supervisory measures. Member States shall ensure that those measures are effective, proportionate and dissuasive, taking into account the circumstances of each individual case.
2. Member States shall ensure that the competent authorities, when exercising their supervisory tasks in relation to important entities, have the power to subject those entities at least to:
(a)
on-site inspections and off-site ex post supervision conducted by trained professionals;
(b)
targeted security audits carried out by an independent body or a competent authority;
(c)
security scans based on objective, non-discriminatory, fair and transparent risk assessment criteria, where necessary with the cooperation of the entity concerned;
(d)
requests for information necessary to assess, ex post, the cybersecurity risk-management measures adopted by the entity concerned, including documented cybersecurity policies, as well as compliance with the obligation to submit information to the competent authorities pursuant to Article 27;
(e)
requests to access data, documents and information necessary to carry out their supervisory tasks;
(f)
requests for evidence of implementation of cybersecurity policies, such as the results of security audits carried out by a qualified auditor and the respective underlying evidence.
The article continues in the official text.
Other articles in this chapter
The text is quoted from the official source and is not legal advice. A national court reads the language version that binds in its jurisdiction.
Verifiable trust signals
- Six fixed blocks, one source per line
- No sentence written by a language model
- Engine version and read date on every answer
- No customer data, no documents, no advice
- Model card and audit published under the EU AI Act