Glossary · NIS2
Competent Authority
The national body in an EU member state responsible for supervising NIS2 compliance.
Explained in depth: Who NIS2 applies to
Each member state designates one or more competent authorities to supervise the entities in its jurisdiction. Competent authorities can conduct audits and inspections, request evidence of compliance, issue warnings and binding instructions, and impose administrative fines. For essential entities, supervision is proactive (the authority can act without cause); for important entities it is reactive (triggered by evidence or indication of non-compliance). In many member states, supervision is split by sector, so an energy company and a healthcare provider may answer to different authorities under the same national law. In Sweden, sector-specific supervisory authorities operate under the framework of Cybersäkerhetslagen, with MSB in a coordinating role.
Why it matters
Knowing your competent authority determines where you register, where you report, and who will audit you. Multi-country organisations may face several competent authorities at once.
