which supervisory authority oversees my sector under NIS2
Supervision arranged by country and by sector
Which supervisory authority carries out supervision depends on the country and the sector in which an organisation operates. NIS2 requires each Member State to itself designate one or more competent authorities, and that choice differs from country to country. In the Netherlands, that designation takes place via the Cybersecurity Act, the national transposition of NIS2, and there the sector-specific supervision is established — that can be a sectoral supervisory authority or an authority specifically designated for this purpose. For general information on the duty of care and the reporting obligation, the NCSC is a reliable point of reference, but the NCSC is not automatically the supervisory authority for every sector.
For those who do not yet know whether this subject is relevant at all, it is useful first to examine how to determine whether a company falls under NIS2 — the question "who supervises me" only follows the question "am I supervised". Once that is clear, the next step is usually the overview of the ten measures that follow from the duty of care, because the supervisory authority tests compliance with those in practice. This subject deliberately receives no definitive assignment of a specific supervisory authority per sector here, because that classification is worked out differently from country to country and in the Netherlands will be further developed via the Cybersecurity Act.
Ground in the Directive and the national law
NIS2 itself addresses in Article 21(2) the ten measures that essential and important entities must take, but the question of which authority carries out supervision is left to the Member States in the Directive and is only made concrete in the national transposition — in the Netherlands the Cybersecurity Act. That is why the correct source for the exact supervisory authority per sector is the text of that law itself, supplemented by the publications of the supervisory authorities that the NCSC maintains.
What this is based on
- Directive (EU) 2022/2555 (NIS2), Article 21(2) — the ten measures
- Cybersecurity Act — the Dutch transposition of NIS2
- ISO/IEC 27001 — Annex A, the control measures
- NCSC — guidance on the security obligation and the reporting obligation
The Regulation itself is available on EUR-Lex. We provide references for each statement; you need not take our word for it.
What you concretely need to do
The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.
View the subscription First the free NIS2 checkThis is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.
Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.