- Also called
- National cybersecurity agencies
- Examples
- BSI, ANSSI, NCSC-NL, NÚKIB, ACN
- Role under NIS2
- Supervision, incident handling, coordination
- How many
- One or more per Member State
- Updated
- June 2026
- Editorial team
- Compliance Compass
What are national cybersecurity authorities?
The National cybersecurity authorities are the institutions that the Member States designate to carry out the roles NIS2 sets out: supervision and enforcement as competent authority, operational incident handling as CSIRT, and cross-border liaison as single point of contact. The directive prescribes the roles, not the organisation chart, so the institutional picture differs from country to country. Well-known examples are the BSI in Germany, ANSSI in France, NCSC-NL in the Netherlands, NÚKIB in Czechia and ACN in Italy.
What do these authorities do?
- Analyse cyber threats and warn about vulnerabilities
- Develop national standards, such as the German IT-Grundschutz
- Run a national CSIRT that supports entities during security incidents
- Supervise, register and receive notifications under national laws such as the NIS2 transposition
How the NIS2 roles are distributed
Many of these authorities wear several hats at once. For the transposition of NIS2 a Member State may name one and the same institution as the competent authority, as the national CSIRT and as the single point of contact, so that an entity meets practically every formal NIS2 duty towards that one body. Other Member States divide the work: supervision goes to sectoral regulators, incident handling to a separate CSIRT, cross-border liaison to a ministry. Whichever model applies, entities register through the national channels shown under Registration portals and they satisfy the registration duty. Deadlines and the exact form are set in national law and differ from country to country. Significant incidents go through the same national channel under the reporting obligations that NIS2 lays down. The staggered reporting chain requires an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. Article 34 sets minimum ceilings for fines: at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities and at least EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.
National authorities and NIS2: tasks plus registration steps
- Supervising. The competent authority checks whether entities in scope actually meet their NIS2 duties – risk management and reporting, for example – and can request evidence or issue binding instructions.
- Receiving notifications. Significant incidents come together at the national reporting point and CSIRT – through the reporting chain of 24 hours, 72 hours and one month.
- Catching up on registration in the national portal. Deadlines are national, and in several Member States the first one has already passed. If you have missed yours, open an account in the portal listed under Registration portals and file your master data – the duty does not lapse.
IT-Grundschutz
The German IT-Grundschutz was developed by the BSI and is a proven methodology for building information security in a structured way. It combines well with an ISMS based on ISO 27001 and it supplies concrete building blocks for the risk management measures NIS2 requires. Other Member States publish comparable frameworks of their own; IT-Grundschutz is named here as a German example, not as a Union-wide requirement.
What contact with your authority looks like
Example: a mid-sized energy supplier concludes that it falls under NIS2 as an essential entity. It first opens an account in the national portal of the Member State where it is established and registers its master data. If a ransomware attack that disrupts grid operations is detected months later, the company files the early warning within 24 hours through the same portal, follows up with the detailed incident notification within 72 hours and closes with the final report within one month – while the national CSIRT can give advice on containment in parallel. Where one institution holds both roles, it is both things at once. It supervises, and it helps.
What you actually have to do
- Check whether your organisation falls under NIS2 as an essential or an important entity.
- Open an account in the portal listed under Registration portals and complete your registration if your national deadline has already passed.
- Define an internal reporting chain that can reliably trigger the 24-hour early warning, the 72-hour notification and the one-month final report.
- Name the people responsible, and their deputies, for communicating with your authority.
- Document your risk management measures verifiably – with a framework such as IT-Grundschutz or an ISMS.
Further reading: European Commission – state of NIS2 transposition
Frequently asked questions
What are the national cybersecurity authorities?
They are the public bodies that the EU Member States have built up for information security and that NIS2 relies on. Well-known examples are the BSI in Germany, ANSSI in France, NCSC-NL in the Netherlands, NÚKIB in Czechia and ACN in Italy. Their tasks typically include analysing cyber threats, warning about vulnerabilities, developing national standards and running a national CSIRT. What they are called, how many there are and how the tasks are divided is decided by each Member State.
What is their role under NIS2?
NIS2 gives every Member State three roles to fill: a competent authority for supervision and enforcement, a CSIRT for operational incident handling, and a single point of contact for cross-border coordination. Some Member States place all three with one national cybersecurity authority, others spread them across several bodies, in some cases sector by sector. Entities in scope register and report through the national channel of the Member State in which they are established.
How do I find the authority responsible for me?
Start from the Member State in which your organisation is established, then look at the sector you operate in, because several Member States assign supervision to sectoral regulators. The European Commission maintains an overview of the state of NIS2 transposition per country, and that is the reliable starting point. The national authority then publishes the registration portal, the reporting channel and the applicable deadlines; those details are national and cannot be read off the directive.