Glossary · Term

National cybersecurity authorities explained

There is no EU cybersecurity authority for NIS2. Every Member State designates its own bodies for supervision, incident handling and cross-border coordination – which is why the practical answer to almost every NIS2 question starts with the country you operate in.

At a glance
Also called
National cybersecurity agencies
Examples
BSI, ANSSI, NCSC-NL, NÚKIB, ACN
Role under NIS2
Supervision, incident handling, coordination
How many
One or more per Member State
Updated
June 2026
Editorial team
Compliance Compass

What are national cybersecurity authorities?

The National cybersecurity authorities are the institutions that the Member States designate to carry out the roles NIS2 sets out: supervision and enforcement as competent authority, operational incident handling as CSIRT, and cross-border liaison as single point of contact. The directive prescribes the roles, not the organisation chart, so the institutional picture differs from country to country. Well-known examples are the BSI in Germany, ANSSI in France, NCSC-NL in the Netherlands, NÚKIB in Czechia and ACN in Italy.

What do these authorities do?

How the NIS2 roles are distributed

Many of these authorities wear several hats at once. For the transposition of NIS2 a Member State may name one and the same institution as the competent authority, as the national CSIRT and as the single point of contact, so that an entity meets practically every formal NIS2 duty towards that one body. Other Member States divide the work: supervision goes to sectoral regulators, incident handling to a separate CSIRT, cross-border liaison to a ministry. Whichever model applies, entities register through the national channels shown under Registration portals and they satisfy the registration duty. Deadlines and the exact form are set in national law and differ from country to country. Significant incidents go through the same national channel under the reporting obligations that NIS2 lays down. The staggered reporting chain requires an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. Article 34 sets minimum ceilings for fines: at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities and at least EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.

National authorities and NIS2: tasks plus registration steps

  1. Supervising. The competent authority checks whether entities in scope actually meet their NIS2 duties – risk management and reporting, for example – and can request evidence or issue binding instructions.
  2. Receiving notifications. Significant incidents come together at the national reporting point and CSIRT – through the reporting chain of 24 hours, 72 hours and one month.
  3. Catching up on registration in the national portal. Deadlines are national, and in several Member States the first one has already passed. If you have missed yours, open an account in the portal listed under Registration portals and file your master data – the duty does not lapse.

IT-Grundschutz

The German IT-Grundschutz was developed by the BSI and is a proven methodology for building information security in a structured way. It combines well with an ISMS based on ISO 27001 and it supplies concrete building blocks for the risk management measures NIS2 requires. Other Member States publish comparable frameworks of their own; IT-Grundschutz is named here as a German example, not as a Union-wide requirement.

What contact with your authority looks like

Example: a mid-sized energy supplier concludes that it falls under NIS2 as an essential entity. It first opens an account in the national portal of the Member State where it is established and registers its master data. If a ransomware attack that disrupts grid operations is detected months later, the company files the early warning within 24 hours through the same portal, follows up with the detailed incident notification within 72 hours and closes with the final report within one month – while the national CSIRT can give advice on containment in parallel. Where one institution holds both roles, it is both things at once. It supervises, and it helps.

What you actually have to do

Further reading: European Commission – state of NIS2 transposition

Frequently asked questions

What are the national cybersecurity authorities?

They are the public bodies that the EU Member States have built up for information security and that NIS2 relies on. Well-known examples are the BSI in Germany, ANSSI in France, NCSC-NL in the Netherlands, NÚKIB in Czechia and ACN in Italy. Their tasks typically include analysing cyber threats, warning about vulnerabilities, developing national standards and running a national CSIRT. What they are called, how many there are and how the tasks are divided is decided by each Member State.

What is their role under NIS2?

NIS2 gives every Member State three roles to fill: a competent authority for supervision and enforcement, a CSIRT for operational incident handling, and a single point of contact for cross-border coordination. Some Member States place all three with one national cybersecurity authority, others spread them across several bodies, in some cases sector by sector. Entities in scope register and report through the national channel of the Member State in which they are established.

How do I find the authority responsible for me?

Start from the Member State in which your organisation is established, then look at the sector you operate in, because several Member States assign supervision to sectoral regulators. The European Commission maintains an overview of the state of NIS2 transposition per country, and that is the reliable starting point. The national authority then publishes the registration portal, the reporting channel and the applicable deadlines; those details are national and cannot be read off the directive.

NIS2 compliance

One platform for all your NIS2 duties

From the account in your national portal to the 24-hour notification: Compliance Compass guides you step by step through registration, evidence and incident reports to your authority.