Abstract illustration of a glowing oversight shield above a data network, representing a NIS2 competent authority audit

NIS2 First Audit: Why Essential and Important Entities Face Different Rules (Article 32 vs. 33)

In July 2026, the European Commission asked the Court of Justice of the EU to fine Ireland, Spain, France, and the Netherlands for still not having finished transposing the NIS2 Directive into national law. In the same month, German entities were partway through a staggered evidence cycle that runs until 2028, and Belgium’s own cybersecurity centre was writing in its 2025 annual report that its first supervisory cycle had focused on “education and support,” not fines. Search for “NIS2 first audit” and most results describe one universal process, the same checklist, the same generic timeline. There isn’t one process. What your first audit looks like, and whether it happens at all this year, depends on two things: which country regulates you, and whether you’re classified as an essential or an important entity.

This article separates what the Directive actually says competent authorities will do from what compliance blogs are guessing they’ll do, using the primary legal text and the current, country-by-country state of enforcement.

Does This Apply to You Right Now?

In plain terms: your first audit can only happen in a country that has finished transposing NIS2 into national law and given its competent authority the legal power to act. As of 10 July 2026, that’s 22 of the EU’s 27 member states.[7]

Situation What it means for your first audit
Your country hasn’t transposed NIS2 yet No competent authority has the domestic legal power to inspect you under NIS2 yet. As of July 2026, Ireland, Spain, France, and the Netherlands were still finalising transposition, and the European Commission referred all four to the Court of Justice of the EU for missing the original 17 October 2024 deadline by more than 20 months, seeking a lump sum plus daily penalties until each notifies full transposition.[8]
Your country transposed NIS2 but supervision is still ramping up Registration and documentation duties apply, but on-site audits may be phased in. Germany’s law (NIS2UmsuCG) took effect 6 December 2025 with registration due 6 March 2026, yet formal evidence audits for many entities aren’t required until as late as 2028.[11]
Your country has an active, dated audit programme Belgium requires essential entities to complete a first compliance verification by 18 April 2026, with full certification due by 18 April 2027.[7] Hungary set a national first-audit deadline of 30 June 2026 for its own in-scope entities.[7] Neither date applies EU-wide, despite how often you’ll see “June 30, 2026” repeated as a universal deadline.

Every published country page on this site tracks the specific competent authority and enforcement status for that jurisdiction; check the scope test first if you’re not certain whether you’re in scope at all, and see your national competent authority page for country-level detail.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Essential vs Important: Two Different Audit Realities

In plain terms: essential entities can be inspected at any time, for no reason at all. Important entities generally can’t be, until the authority already has a reason to look.

NIS2 doesn’t create one supervisory regime. Article 32 governs essential entities under an ex-ante model: competent authorities may act proactively, without waiting for evidence of a problem.[2] Article 33 governs important entities under an ex-post model, triggered only “when provided with evidence, indication or information” that the entity allegedly isn’t complying, particularly with Articles 21 or 23.[3] That single legal distinction, buried in two adjacent articles, is the biggest predictor of whether you’ll see an auditor this year.

Essential entities (Art. 32) Important entities (Art. 33)
Trigger Proactive, ex-ante, random or risk-based selection Reactive, ex-post, only after evidence or an incident
Tools available On-site inspections, off-site supervision incl. random checks, regular and targeted security audits, ad hoc audits after an incident, security scans, information/data requests On-site/off-site ex-post inspections, targeted security audits, security scans, information requests, implementation evidence such as qualified auditor reports
Who performs security audits An independent body or the competent authority itself; the audited entity generally pays for a targeted audit unless the authority decides otherwise Same mechanism, applied only once a case is already open
Cross-regime coordination GDPR supervisory authorities, where an incident is also a personal data breach[1] DORA authorities under Regulation (EU) 2022/2554, for critical ICT third-party providers[3]

Article 31 adds one more variable: competent authorities are explicitly permitted to run a “risk-based approach” to prioritise which entities they examine first.[1] In practice, that means sector risk profile and incident history push some essential entities up the queue well before others, even within the same country and the same random-inspection regime.

What Auditors Actually Check

In plain terms: whatever an auditor asks for, it maps back to one of ten measure categories in Article 21(2), plus your incident-reporting track record under Article 23.

Generic “bring your policies” checklists miss the structure auditors actually use. Article 21(2) lists ten specific measure categories every in-scope entity must implement; an audit is, functionally, a test of whether you can produce evidence for each one.[4]

Article 21(2) measure Evidence an auditor typically asks to see
(a) Risk analysis & information security policy Documented risk methodology, current risk register, approved policy with a review date
(b) Incident handling Incident handling procedure, incident log, evidence it was actually used
(c) Business continuity, backup, disaster recovery, crisis management Backup policy, tested recovery plan, crisis management roles and contact tree
(d) Supply chain security Supplier classification, contractual security clauses with direct suppliers
(e) Secure acquisition, development, maintenance Vulnerability handling and disclosure process, patch records
(f) Effectiveness assessment Internal audit results, KPI tracking, management review minutes
(g) Cyber hygiene and training Training records, awareness campaign evidence, coverage by role
(h) Cryptography and encryption Encryption policy, key management approach
(i) HR security, access control, asset management Access control policy, asset register, joiner/mover/leaver process
(j) MFA and secured communications MFA enforcement evidence, secured channels for emergency communications

Alongside Article 21(2), auditors reviewing an entity’s reporting history are checking against a fixed clock: a 24-hour early warning, a 72-hour incident notification, and a final report no later than one month after that notification, all counted from the moment the entity became aware of a significant incident.[5] A missed or late notification is one of the easiest things for an authority to verify objectively, because it’s a timestamp comparison, not a judgment call, which is part of why incident notification gaps show up disproportionately in early enforcement actions.

What Happens on Inspection Day

In plain terms: expect written notice, a request for specific documentation in advance, and a mix of system walkthroughs and staff conversations on the day, not just a folder review.

Neither Article 32 nor Article 33 specifies exact inspection-day mechanics; that’s left to each competent authority’s own procedure. Compliance advisories tracking early national programmes describe a broadly consistent pattern: written notice of roughly two weeks before an on-site visit, giving the entity time to assemble documentation before auditors arrive.[10] The evidence requested typically spans the same ground as the Article 21(2) table above, incident response and crisis plans, vulnerability and patch records, access control and authentication configuration, asset registers, risk assessments, supply chain security evidence, and encryption and MFA implementation.[10]

On the day itself, reports from early inspections describe entities preparing a short walkthrough of their business and the services they provide, followed by auditors reviewing security systems directly rather than relying solely on submitted documents, and, in some cases, brief interviews with regular staff as well as senior management, specifically to test whether security awareness matches what the policy documents claim.[10] That last point catches organisations that have well-written policies nobody on the floor can actually describe.

If the Audit Finds Gaps: The Enforcement Ladder

In plain terms: a finding doesn’t jump straight to a fine. Both articles describe an escalating sequence, and the harshest tools (suspending certifications, banning managers) sit at the very end of it, reserved for essential entities that don’t fix things after being told to.

Article 32 sets out the enforcement sequence available for essential entities: warnings, binding instructions on how to remedy a problem, orders to stop non-compliant conduct, orders to bring measures into compliance within a set deadline, orders to notify affected users of a threat, orders to implement audit recommendations, appointment of a monitoring officer, mandatory public disclosure of the infringement, and administrative fines. If those measures don’t produce compliance, authorities can escalate further, temporarily suspending a certification or authorisation, or requesting a temporary ban on a named manager holding managerial responsibility for the infringement.[2] Article 33 gives authorities largely the same toolkit for important entities, applied only once the ex-post trigger has been met.[3]

Entity type Maximum administrative fine
Essential EUR 10,000,000 or 2% of total worldwide annual turnover, whichever is higher
Important EUR 7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher

Those ceilings apply to breaches of Article 21 or Article 23.[6] They’re the maximum the law permits, not a number that gets applied automatically the moment an auditor finds a gap, which is precisely where a lot of secondary coverage of “first NIS2 fines” goes wrong. For deeper detail on the personal liability layer that sits alongside these entity-level fines, see the site’s management liability and penalties pages.

Belgium’s First Cycle: A Real Case Study, and a Warning About “First Fines” Lists

In plain terms: the specific fine figures circulating online for 2025-2026 don’t hold up against at least one country’s own official reporting, so treat any list of “confirmed NIS2 fines” with real skepticism unless it links to the regulator itself.

Belgium is one of the few countries with both a dated audit programme and a public account of how its first cycle actually went. The Centre for Cybersecurity Belgium runs proactive, ex-ante audits and mandatory regular conformity assessments for essential entities, using on-site inspections, remote monitoring, and security scans, and requesting documentation such as access logs, configuration files, audit reports, and internal policies.[9] Its own 2025 annual report describes the first supervisory cycle as having focused on education and support rather than punishment, and as of mid-2026 the CCB had not published any individual sanctions.[9]

That matters because several tables of specific “first NIS2 fines” are circulating across compliance marketing content, with precise figures attached to Belgium, Italy, Hungary, and other countries. Cross-checking the Belgian figure against the CCB’s own reporting found no supporting record, which suggests at least some of these numbers are unverified estimates being repeated between sites rather than confirmed enforcement actions. Before citing a specific fine amount for your board or your legal team, trace it back to the competent authority’s own publication, not a compliance blog’s summary table.

The clearest early enforcement signal in Belgium is indirect: reporting on the CCB’s 2025 annual report cites a 70% year-on-year rise in incident reports, which points toward more incident-triggered investigations as that backlog gets worked through, rather than random ex-ante fines being the primary early enforcement path.[9]

Role by Role: What Your CISO, Compliance Officer, and Board Should Each Prepare

In plain terms: an audit touches every level of the organisation differently, and each role needs a different kind of readiness, not just a shared copy of the same policy folder.

Role What an auditor is actually testing
CISO / IT security manager Whether the Article 21(2) technical controls, access control, encryption, patching, MFA, are demonstrable in the live environment, not just described on paper
Compliance officer / legal Whether the documentation trail is complete and dated: risk register updated when, training records covering which staff, incident log matching actual notification timestamps against the 24h/72h/1-month clock
Board / C-suite Whether management can show active oversight, meeting minutes discussing cyber risk, budget decisions tied to the risk register, given that Article 20 places accountability for compliance failures on the management body itself, not on the security function alone

The most common friction point across all three roles is the same: policies exist, but nobody can produce the specific evidence, the specific log entry, the specific meeting minute, that proves the policy was followed on a specific date. That’s the gap an ex-ante audit is designed to find.

This article covers what to expect once an audit is underway. A separate guide on this site will cover how to prepare for one before it’s scheduled.

Disclaimer: This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Frequently Asked Questions

Is there one EU-wide deadline for a first NIS2 audit?

No. NIS2 itself sets no single first-audit date. Dates like Hungary’s 30 June 2026 first-audit deadline or Belgium’s 18 April 2026 first compliance verification are national obligations set by individual member states, not EU-wide requirements.[7]

Can an important entity be audited without an incident?

Generally no. Article 33’s ex-post model requires the competent authority to already have “evidence, indication or information” of non-compliance before acting, unlike the ex-ante model that applies to essential entities under Article 32.[2][3]

Who pays for a targeted security audit?

The audited entity, in most cases, unless the competent authority decides otherwise for duly substantiated reasons.[2]

Does a finding during an audit mean an automatic fine?

No. Article 32’s enforcement sequence starts with warnings and binding instructions; fines and the harsher escalated measures (certification suspension, management bans) apply after an entity fails to remedy the issue.[2]

Sources

  • NIS 2 Directive, Article 21: Cybersecurity risk-management measures — nis-2-directive.com
  • NIS 2 Directive, Article 23: Reporting obligations — nis-2-directive.com
  • NIS 2 Directive, Article 31: General provisions concerning supervision and enforcement — nis-2-directive.com
  • NIS 2 Directive, Article 32: Supervisory and enforcement measures in relation to essential entities — nis-2-directive.com
  • NIS 2 Directive, Article 33: Supervisory and enforcement measures in relation to important entities — nis-2-directive.com
  • NIS 2 Directive, Article 34: Penalties — nis-2-directive.com
  • NIS2 Regulatory Timeline — NISD2.eu
  • “EU cyber filing: Ireland, Spain, France, Netherlands over NIS2” — The Record, Recorded Future News
  • “NIS2 fines in Belgium: what enforcement actually looks like” — Jimber
  • “How to Prepare for NIS2 Audits” — Heimdal Security
  • “NIS2 Implementation in Germany” — OpenKRITIS
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: