Abstract network of glowing blue nodes representing NIS2 competent authorities, CSIRTs and single points of contact

NIS2 Competent Authority vs CSIRT vs Single Point of Contact: Which One Can Fine You

Three separate national bodies sit behind NIS2, and only one of them can impose a fine on you. The competent authority supervises and enforces. The CSIRT handles incidents and, most of the time, helps. The single point of contact is a liaison desk that routes information across borders and rarely deals with you at all. Member States are allowed to merge all three into a single agency, and the Directive is drafted on the assumption that many will — which is why one email address can carry three very different legal meanings depending on which hat the sender is wearing.

Working out which body is writing to you is not an academic exercise. A CSIRT scanning your perimeter is offering assistance. A competent authority scanning your perimeter is exercising a supervisory power under Article 32 or 33, and what it finds can end up in an enforcement file.

This article provides general information only and does not constitute legal advice. NIS2 implementation varies by member state and sector — always verify requirements against your national transposition law and applicable authority guidance.

The three bodies every Member State has to designate

Article 8(1) requires each Member State to designate or establish “one or more competent authorities responsible for cybersecurity and for the supervisory tasks referred to in Chapter VII”. Article 8(3) requires a single point of contact. Article 10(1) requires one or more CSIRTs — and adds, in the same sentence, that CSIRTs “may be designated or established within a competent authority”.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Body Legal basis Core job Can it act against you?
Competent authority Art. 8(1), 8(2) Monitors implementation of the Directive at national level; holds all supervisory and enforcement powers Yes — Articles 32, 33 and 34
CSIRT Art. 10, 11 Incident handling, early warnings, forensic analysis, assistance to entities No supervisory or enforcement power in the Directive
Single point of contact (SPOC) Art. 8(3), 8(4) Liaison function for cross-border and cross-sectoral cooperation No

Article 8(3) settles the most common structural question outright: where a Member State designates only one competent authority, that authority “shall also be the single point of contact”. Article 13(1) is drafted the same way — it obliges the three bodies to cooperate “where they are separate”, conceding that in many countries they will not be.

Both models are live. Ireland has split the role: its National Cyber Security Centre states that “National Competent Authorities (NCAs) are sectoral regulators”, with the NCSC covering every remaining in-scope entity and acting as Lead Competent Authority. Any Member State that designates only one competent authority arrives at the merged model automatically, by operation of Article 8(3). Our Ireland and Germany guides map the specific national structures — the pattern varies enough that you cannot infer your regulator from a neighbouring country’s.

For a compliance officer, the practical output of this section is a two-line register: the named competent authority for your sector, and the named CSIRT that receives your incident reports. For a CISO, it is a contact-routing rule in the incident runbook, because the two are reached through different channels on different clocks.

Only the competent authority holds powers over you

The CSIRT task list in Article 11(3) runs to eight items — threat monitoring and analysis, early warnings, incident response and assistance, forensic data and situational awareness, scanning on request, CSIRTs network participation, coordinated vulnerability disclosure coordination, and secure information-sharing tools, two of which start only when an entity asks for them. None is a supervisory or enforcement power. The single point of contact fares the same: Article 8(4) gives it a “liaison function”, nothing more.

The sharpest illustration is that the same technical act appears in both regimes with opposite legal character. Article 11(3)(e) lets a CSIRT provide “upon the request of an essential or important entity, a proactive scanning of the network and information systems of the entity concerned” — you ask for it. Article 32(2)(d) and Article 33(2)(c) give the competent authority “security scans based on objective, non-discriminatory, fair and transparent risk assessment criteria, where necessary with the cooperation of the entity concerned” — a supervisory power, drafted so that cooperation is a practicality rather than a precondition.

One qualification: Article 11(3) also permits CSIRTs to carry out “proactive non-intrusive scanning of publicly accessible network and information systems” without any request, to detect vulnerable or insecurely configured systems and inform the entities concerned — scanning that “shall not have any negative impact on the functioning of the entities’ services”. An unsolicited CSIRT notification is therefore normal, and it is a warning rather than a finding.

Filing with one body does not mean the other has seen it

Article 13(2) leaves the routing choice to Member States: “their CSIRTs or, where applicable, their competent authorities” receive significant-incident notifications under Article 23. Article 23(1) then creates a forwarding duty in exactly one direction — where an entity notifies the competent authority, the Member State must ensure “that competent authority forwards the notification to the CSIRT upon receipt”.

There is no article-level equivalent running the other way. Searching the operative text of all 46 articles, the CSIRT’s outward duties run to the single point of contact (Article 13(3)), to other affected Member States and ENISA (Article 23(6)), and to authorities under the Critical Entities Resilience Directive (Article 23(10)) — not to the supervisor. Article 13(1) still requires the separate bodies to cooperate generally, and national transposition commonly closes the loop, so treat this as a gap in the Directive rather than a guarantee about your own country.

Two consequences follow, and they point in opposite directions. Filing with a CSIRT is not a way to keep an incident away from your regulator — Article 32(2)(e) and (f), and their Article 33(2)(d) and (e) counterparts, let the competent authority demand the information and the underlying documents directly. But having filed does not mean your supervisor has read it, so “the authority already knows” is an unsafe assumption. Article 23(1) does add one protection: “the mere act of notification shall not subject the notifying entity to increased liability”. Where personal data is involved, Article 31(3) obliges the competent authority to work “in close cooperation” with the GDPR supervisory authority, so one incident can put two regulators on the file. Our incident reporting guide and the country-by-country CSIRT portal list cover the filing mechanics.

What the authority can do before it has any evidence

The split that matters most is not what the powers are but when they can be used. Supervision of essential entities can be proactive: nothing needs to have gone wrong first. Supervision of important entities is gated by the Article 33(1) chapeau, which engages only “when provided with evidence, indication or information” of alleged non-compliance, and then “through ex post supervisory measures”. Ireland’s NCSC guidance sets the two regimes out in the same terms: “Ex Ante & Ex Post Supervision” for essential entities, “Ex Post Supervision” for important ones.

Supervisory power Essential — Art. 32(2) Important — Art. 33(2)
On-site inspections Yes, expressly including “random checks” — (a) Yes — (a), but only once the Art. 33(1) trigger is met
Off-site supervision Yes — (a) Yes, expressly “ex post” — (a)
Regular security audits Yes — (b) Not listed
Targeted security audits Yes — (b) Yes — (b)
Ad hoc audits Yes — (c) Not listed
Security scans Yes — (d) Yes — (c)
Requests for information Yes — (e) Yes, assessed “ex post” — (d)
Access to data and documents Yes — (f) Yes — (e)
Evidence of implementation Yes — (g) Yes — (f)

Two details in this section are budget items rather than legal trivia. First, an identical sub-paragraph in both Article 32(2) and Article 33(2) provides that the costs of a targeted security audit carried out by an independent body “shall be paid by the audited entity, except in duly substantiated cases when the competent authority decides otherwise” — an ordered audit is your invoice, not the regulator’s. Our third-party audit guide covers who qualifies to carry one out. Second, Article 31(2) lets Member States allow their authorities to prioritise supervisory tasks on a risk-based approach. Being in scope and never being inspected is a legitimate outcome of that discretion, not evidence that the rules do not apply to you.

Note: inspection practice, published methodologies and any additional national evidence-submission duties vary by member state and sector. Confirm with your national competent authority.

The enforcement ladder, and where it stops

Article 32(4) gives nine enforcement powers against essential entities; Article 33(4) gives eight against important entities. The overlap is large and the differences are precise.

Enforcement tool Essential Important
Warning about an infringement 32(4)(a) 33(4)(a)
Binding instructions or order to remedy deficiencies 32(4)(b), expressly covering measures to prevent or remedy an incident, with time limits and implementation reporting 33(4)(b), without that added wording
Order to cease and not repeat the conduct 32(4)(c) 33(4)(c)
Order to bring Article 21 or Article 23 compliance into line 32(4)(d) 33(4)(d)
Order to inform affected customers of a significant cyber threat 32(4)(e) 33(4)(e)
Order to implement audit recommendations 32(4)(f) 33(4)(f)
Designate a monitoring officer to oversee Article 21 and 23 compliance 32(4)(g) No counterpart
Order public disclosure of the infringement 32(4)(h) 33(4)(g)
Administrative fine 32(4)(i) 33(4)(h)
Temporary suspension of a certification or authorisation 32(5)(a) Not available
Temporary ban on a CEO or legal representative exercising managerial functions 32(5)(b) Not available
Fine ceiling for Article 21 or 23 infringements Maximum of at least EUR 10 000 000 or 2% of total worldwide annual turnover, whichever is higher — Art. 34(4) Maximum of at least EUR 7 000 000 or 1.4%, whichever is higher — Art. 34(5)

The last two escalation rows rest on a single drafting choice that is easy to miss. Article 33(5) imports “Article 32(6), (7) and (8) … mutatis mutandis” into the important-entity regime. Article 32(5) is not on that list, so the certification suspension and the temporary management ban are unavailable against important entities. They are also conditional against essential ones: Article 32(5) engages only where the measures in points (a) to (d) and (f) of Article 32(4) have proved ineffective and a remediation deadline has passed unmet.

Fines are cumulative rather than alternative: Article 34(2) states they “shall be imposed in addition to” the other measures listed, so a fine does not close out a binding instruction. Article 34(6) lets Member States add periodic penalty payments, and Article 34(8) covers legal systems without administrative fines — there the competent authority initiates and a national court imposes. For public-sector readers the position differs twice over: the Article 32(5) escalation measures expressly “shall not be applicable to public administration entities”, and Article 34(7) leaves each Member State to decide “whether and to what extent” fines apply to them at all. Our penalties guide covers how national laws have set those ceilings.

What the authority owes you procedurally

Article 32(8) is the paragraph to read before an enforcement meeting, not after. Competent authorities “shall set out a detailed reasoning for their enforcement measures”, must notify the entity of their preliminary findings before adopting a measure, and must allow “a reasonable time” for the entity to submit observations. The exception is narrow and specific: cases where immediate action to prevent or respond to incidents would otherwise be impeded. Because Article 33(5) imports Article 32(8), important entities have exactly the same procedural entitlement.

Article 32(7), also imported into the important-entity regime, lists what the authority must weigh: seriousness, duration, previous infringements, damage caused, intent or negligence, mitigation measures taken, adherence to approved codes of conduct or certification mechanisms, and the entity’s level of cooperation. Several are within your control during an inspection, and one runs the other way — Article 32(7)(a)(iv) makes “the obstruction of audits or monitoring activities ordered by the competent authority following the finding of an infringement” a serious infringement in any event.

For the mechanics of an inspection itself — what evidence is requested, how compliance notices work, and how the escalation sequence plays out — see our detailed walkthrough of NIS2 supervisory measures.

Frequently asked questions

Can the same organisation be my competent authority, my CSIRT and my single point of contact?

Yes. Article 8(3) makes a sole competent authority the single point of contact by operation of law, and Article 10(1) permits a CSIRT to be established within a competent authority. Article 13(1) imposes a cooperation duty only “where they are separate”. Both models are in use across the EU, so confirm the structure in your own Member State rather than assuming.

Does reporting an incident to the CSIRT put it in front of my supervisor?

The Directive does not say so. Article 23(1) requires a competent authority that receives a notification to forward it to the CSIRT, but creates no reverse duty; the CSIRT’s stated onward duties run to the single point of contact, other Member States and ENISA. National law often adds the missing link, so check your transposition. Either way, the authority can request the information directly under Article 32(2)(e) or Article 33(2)(d).

Can a competent authority audit an important entity that has never had an incident?

Article 33(1) engages the important-entity regime only when the authority is “provided with evidence, indication or information” of alleged non-compliance. An incident is one possible trigger, not the only one — a complaint, a supervisory finding elsewhere, or information from another regulator can serve. What Article 33 does not contain is the random-check, regular-audit and ad hoc-audit wording that appears in Article 32.

Can my CEO really be banned from managing the company?

The power exists in Article 32(5)(b), but it is narrow. It applies to essential entities only, not to important entities and not to public administration entities; it requires that the enforcement measures in Article 32(4), points (a) to (d) and (f), have already proved ineffective and that a remediation deadline has passed; and it is temporary, lasting only until the entity remedies the deficiencies. Member-state law sets the procedure, so the practical threshold varies.

Sources

  1. Directive (EU) 2022/2555 (NIS2) — full text — EUR-Lex
  2. NIS 2 Directive, Article 8: Competent authorities and single points of contact — nis-2-directive.com (primary text)
  3. NIS 2 Directive, Article 10: Computer security incident response teams (CSIRTs) — nis-2-directive.com (primary text)
  4. NIS 2 Directive, Article 11: Requirements, technical capabilities and tasks of CSIRTs — nis-2-directive.com (primary text)
  5. NIS 2 Directive, Article 13: Cooperation at national level — nis-2-directive.com (primary text)
  6. NIS 2 Directive, Article 23: Reporting obligations — nis-2-directive.com (primary text)
  7. NIS 2 Directive, Article 31: General aspects concerning supervision and enforcement — nis-2-directive.com (primary text)
  8. NIS 2 Directive, Article 32: Supervisory and enforcement measures in relation to essential entities — nis-2-directive.com (primary text)
  9. NIS 2 Directive, Article 33: Supervisory and enforcement measures in relation to important entities — nis-2-directive.com (primary text)
  10. NIS 2 Directive, Article 34: General conditions for imposing administrative fines — nis-2-directive.com (primary text)
  11. NIS 2 Essential and Important Entities — Supervision (guidance sheet 6) — National Cyber Security Centre, Ireland
  12. NIS2 FAQ — competent authorities and supervision in Ireland — National Cyber Security Centre, Ireland
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: