Glossary · Term

Competent authority explained

The competent authority supervises NIS2 compliance and receives notifications. Every Member State designates its own, sometimes one per sector.

At a glance
Meaning
National supervisory and reporting body
Designated by
Each Member State (Article 8)
Task
Supervision, notifications, enforcement
Related
National authorities, SPOC
Updated
June 2026
Editorial team
Compliance Compass

What is a competent authority?

The competent authority supervises compliance with NIS2 and receives notifications. Depending on the country and the sector this can be a different body – NIS2 requires every Member State to designate one or more competent authorities. The term therefore describes a legal function, namely supervision and enforcement. The institutions that carry out that function in the individual Member States are listed under National cybersecurity authorities.

Who holds the role in your country

The directive creates no EU-level authority. Each Member State designates its own, and it is that authority which supervises entities and takes in registrations and notifications through the national channels described under Registration portals and works together with the SPOC and with ENISA in the wider European network. The roles are deliberately distinct: the competent authority is the supervisory and enforcement function, the single point of contact is the cross-border coordination role, and the CSIRT handles incidents operationally. In some Member States all of these roles sit with one institution, in others they are spread across several bodies.

What powers it has

What this means for organisations

The competent authority is your point of contact and your supervisor at the same time. Once NIS2 applies to your organisation, you have to observe the reporting chain – an early warning within 24 hours, a notification within 72 hours and a final report within one month. Clean documentation of your own measures is the best way to face an inspection calmly.

A typical case

After a data breach at a water utility, the competent authority asks the operator to produce its risk analysis and the technical measures it has taken. Because the company has documented those measures continuously, it can supply the files within a few days. The review ends with conditions rather than a fine – an example of how solid evidence takes the sting out of the procedure.

Further reading: European Commission – NIS2 Directive

Frequently asked questions

What is the competent authority under NIS2?

The competent authority is the national supervisory and reporting body that monitors compliance with NIS2 and receives notifications. NIS2 requires every EU Member State to designate one or more competent authorities. Which body is responsible depends on the country and, in some Member States, on the sector. The directive has applied since 18 October 2024; from the moment your Member State has transposed it, entities in scope must work with that authority and observe the reporting chain.

Who is the competent authority in my country?

That depends on where your organisation is established. Some Member States have designated a single cross-sector authority, others split supervision between sectoral regulators such as financial, energy or health supervisors. Whichever model applies, the competent authority carries out supervision, oversees the national registration and reporting channels, can issue binding instructions and can impose fines. Because the designation is made in national law, the official list for your country is the reliable source.

What powers does the competent authority have?

The competent authority receives registrations and notifications, carries out inspections and audits, can issue binding instructions and can impose substantial fines. Article 34 of the directive sets minimum ceilings: at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and at least EUR 7 million or 1.4 % for important entities, whichever is higher. Member States may set higher amounts. The authority is also the contact point for the reporting chain of a 24-hour early warning, a 72-hour incident notification and a final report within one month.

Supervision

Ready for any inspection

Compliance Compass documents your measures in audit-proof form – so that you can face your competent authority with solid evidence.