Article 33 — Supervisory and enforcement measures in relation to important entities
NIS2 — Directive (EU) 2022/2555
| In the act | EU 2022/2555 |
| Chapter | VII · Supervision and enforcement |
| CELEX | 32022L2555 |
| Read on | 2026-08-14 |
Official text
Read from the EU Publications Office for this CELEX number. The wording stands as published; nothing here is rewritten or summarised.
1. When provided with evidence, indication or information that an important entity allegedly does not comply with this Directive, in particular Articles 21 and 23 thereof, Member States shall ensure that the competent authorities take action, where necessary, through ex post supervisory measures. Member States shall ensure that those measures are effective, proportionate and dissuasive, taking into account the circumstances of each individual case.
2. Member States shall ensure that the competent authorities, when exercising their supervisory tasks in relation to important entities, have the power to subject those entities at least to:
(a) on-site inspections and off-site ex post supervision conducted by trained professionals;
(b) targeted security audits carried out by an independent body or a competent authority;
(c) security scans based on objective, non-discriminatory, fair and transparent risk assessment criteria, where necessary with the cooperation of the entity concerned;
(d) requests for information necessary to assess, ex post , the cybersecurity risk-management measures adopted by the entity concerned, including documented cybersecurity policies, as well as compliance with the obligation to submit information to the competent authorities pursuant to Article 27;
(e) requests to access data, documents and information necessary to carry out their supervisory tasks;
(f) requests for evidence of implementation of cybersecurity policies, such as the results of security audits carried out by a qualified auditor and the respective underlying evidence.
The article continues in the official text.
Other articles in this chapter
The text is quoted from the official source and is not legal advice. A national court reads the language version that binds in its jurisdiction.
Back to the act · EU acts, read down to the national law
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.