acquis · Law · NIS2

NIS2 · CELEX 02022L2555-20221227

Article 33

Verbatim text of the current consolidated version (consolidated 2022-12-27) · status: in force. Check it on EUR-Lex ↗

NIS2, Article 33(1) — Supervisory and enforcement measures in relation to important entities
When provided with evidence, indication or information that an important entity allegedly does not comply with this Directive, in particular Articles 21 and 23 thereof, Member States shall ensure that the competent authorities take action, where necessary, through ex post supervisory measures. Member States shall ensure that those measures are effective, proportionate and dissuasive, taking into account the circumstances of each individual case.
NIS2, Article 33(2) — Supervisory and enforcement measures in relation to important entities
Member States shall ensure that the competent authorities, when exercising their supervisory tasks in relation to important entities, have the power to subject those entities at least to: The targeted security audits referred to in the first subparagraph, point (b), shall be based on risk assessments conducted by the competent authority or the audited entity, or on other risk-related available information. The results of any targeted security audit shall be made available to the competent authority. The costs of such targeted security audit carried out by an independent body shall be paid by the audited entity, except in duly substantiated cases when the competent authority decides otherwise.
NIS2, Article 33(2)(a) — Supervisory and enforcement measures in relation to important entities
on-site inspections and off-site ex post supervision conducted by trained professionals;
NIS2, Article 33(2)(b) — Supervisory and enforcement measures in relation to important entities
targeted security audits carried out by an independent body or a competent authority;
NIS2, Article 33(2)(c) — Supervisory and enforcement measures in relation to important entities
security scans based on objective, non-discriminatory, fair and transparent risk assessment criteria, where necessary with the cooperation of the entity concerned;
NIS2, Article 33(2)(d) — Supervisory and enforcement measures in relation to important entities
requests for information necessary to assess, ex post, the cybersecurity risk-management measures adopted by the entity concerned, including documented cybersecurity policies, as well as compliance with the obligation to submit information to the competent authorities pursuant to Article 27;
NIS2, Article 33(2)(e) — Supervisory and enforcement measures in relation to important entities
requests to access data, documents and information necessary to carry out their supervisory tasks;
NIS2, Article 33(2)(f) — Supervisory and enforcement measures in relation to important entities
requests for evidence of implementation of cybersecurity policies, such as the results of security audits carried out by a qualified auditor and the respective underlying evidence.
NIS2, Article 33(3) — Supervisory and enforcement measures in relation to important entities
When exercising their powers under paragraph 2, point (d), (e) or (f), the competent authorities shall state the purpose of the request and specify the information requested.
NIS2, Article 33(4) — Supervisory and enforcement measures in relation to important entities
Member States shall ensure that the competent authorities, when exercising their enforcement powers in relation to important entities, have the power at least to:
NIS2, Article 33(4)(a) — Supervisory and enforcement measures in relation to important entities
issue warnings about infringements of this Directive by the entities concerned;
NIS2, Article 33(4)(b) — Supervisory and enforcement measures in relation to important entities
adopt binding instructions or an order requiring the entities concerned to remedy the deficiencies identified or the infringement of this Directive;
NIS2, Article 33(4)(c) — Supervisory and enforcement measures in relation to important entities
order the entities concerned to cease conduct that infringes this Directive and desist from repeating that conduct;
NIS2, Article 33(4)(d) — Supervisory and enforcement measures in relation to important entities
order the entities concerned to ensure that their cybersecurity risk-management measures comply with Article 21 or to fulfil the reporting obligations laid down in Article 23, in a specified manner and within a specified period;
NIS2, Article 33(4)(e) — Supervisory and enforcement measures in relation to important entities
order the entities concerned to inform the natural or legal persons with regard to which they provide services or carry out activities which are potentially affected by a significant cyber threat of the nature of the threat, as well as of any possible protective or remedial measures which can be taken by those natural or legal persons in response to that threat;
NIS2, Article 33(4)(f) — Supervisory and enforcement measures in relation to important entities
order the entities concerned to implement the recommendations provided as a result of a security audit within a reasonable deadline;
NIS2, Article 33(4)(g) — Supervisory and enforcement measures in relation to important entities
order the entities concerned to make public aspects of infringements of this Directive in a specified manner;
NIS2, Article 33(4)(h) — Supervisory and enforcement measures in relation to important entities
impose, or request the imposition by the relevant bodies, courts or tribunals, in accordance with national law, of an administrative fine pursuant to Article 34 in addition to any of the measures referred to in points (a) to (g) of this paragraph.
NIS2, Article 33(5) — Supervisory and enforcement measures in relation to important entities
Article 32(6), (7) and (8) shall apply mutatis mutandis to the supervisory and enforcement measures provided for in this Article for important entities.
NIS2, Article 33(6) — Supervisory and enforcement measures in relation to important entities
Member States shall ensure that their competent authorities under this Directive cooperate with the relevant competent authorities of the Member State concerned under Regulation (EU) 2022/2554. In particular, Member States shall ensure that their competent authorities under this Directive inform the Oversight Forum established pursuant to Article 32(1) of Regulation (EU) 2022/2554 when exercising their supervisory and enforcement powers aimed at ensuring compliance of an important entity that is designated as a critical ICT third-party service provider pursuant to Article 31 of Regulation (EU) 2022/2554. with this Directive.
This text is not written by an AI. It is rendered from a corpus built from the official EUR-Lex source, where every fragment is content-hashed and signed at ingestion — which is what lets you cite it and defend the citation. Ask a question about this article →

Other articles of the NIS2

← Article 32 · Article 34

Acquis returns official sources verbatim with citations; it is not legal advice. Texts © European Union, reuse permitted (Decision 2011/833/EU) — only the EUR-Lex original is authentic. Why legal AI fails · Coverage