Directive NIS2 European Union
Art. 32

What a NIS2 inspection actually is


· Cryptaguard · 7 min read

Almost every NIS2 conversation is about fines. Almost no NIS2 enforcement starts there. What supervisors actually do is inspect, and whether they can inspect you without a reason at all depends on one word in your classification.

Ask what happens if you get NIS2 wrong and you will be told about ten million euros or two per cent of worldwide turnover. That is article 34, it is real, and it is almost never where enforcement starts. What supervisors actually do, day to day, is supervise — and the design of that supervision contains one distinction that matters more to your risk profile than the size of the fine.

Ex ante and ex post: the whole difference in one word

NIS2 splits supervision by entity class, and the split is not cosmetic.

  • Essential entities are supervised under article 32, ex ante AND ex post. An authority may inspect proactively, on a plan, without any indication that anything is wrong.
  • Important entities are supervised under article 33, ex post only. Supervisory action requires evidence, an indication, or information suggesting non-compliance.

In practice: an essential entity can find a supervisor at the door because its name came up in a sampling plan. An important entity generally cannot. Something has to have happened first — an incident notification, a complaint, a sector alert, a referral from another authority, a press report.

What the classification really buys

This is why the essential-versus-important classification is worth getting right early rather than at the first inspection. It does not just change the fine ceiling from ten million to seven million; it changes whether you can be inspected for no reason at all. Sector and size decide it, under Annexes I and II and the size cap of article 2.

What "ex post" does not mean

Two misreadings are common and both are expensive.

It does not mean "after a breach". The trigger is an indication of non-compliance, not an incident. Filing an article 23 early warning is not what exposes you — but a pattern of late filings, or a notification whose content shows no incident process behind it, is exactly the kind of indication that opens a file. The notification itself is required; the impression it leaves is not neutral.

It does not mean lighter powers once triggered. Article 33 is narrower than article 32, but an important entity under supervision is not being handled gently. The distinction is about when supervision may begin, not about how thorough it is once it has.

The audit at your expense

Among the article 32 powers there is one that surprises finance directors more than the fines do: the authority can require targeted security audits carried out by an independent body, and require the entity to bear the cost.

Read that mechanic carefully. The supervisor decides the audit is needed, the supervisor sets the scope, an independent body it accepts performs it, and you pay. You do not choose the auditor to suit your budget or your calendar, and you cannot substitute the assessment you already commissioned. For a mid-sized entity this is routinely a larger and less predictable number than any fine it was actually likely to receive.

The defence is unglamorous and works: be able to produce a current, independent assessment on request. A supervisor holding credible recent evidence has less reason to commission its own.

The power that actually costs reputation

Authorities may order an entity to make aspects of its non-compliance public, and may order it to inform the natural or legal persons affected by a significant threat. Neither is a fine. Both are disclosed.

A fine is a line in an annual report that most customers never read. A published finding of non-compliance is a document your competitors, your customers and your insurers can link to. In sectors where procurement asks about regulatory standing, this is the sanction with the longest tail — and it does not require the authority to have got as far as a penalty decision.

And the one aimed at a person

Article 32(6) allows the competent authority, where other enforcement has failed, to request the temporary prohibition of a natural person exercising managerial responsibilities at chief executive or legal representative level from exercising those functions in that entity. It can also suspend a certification or authorisation the entity holds. These apply to essential entities.

Note the sequencing: "where other enforcement has failed". This is not a first move, and it is not a routine outcome. Its function is to make the article 20 management duties real by attaching a consequence to a named individual rather than to a budget. It changes how a board reads an agenda item, which is what it was designed to do.

What an inspection actually asks for

Supervision in practice is documentary before it is technical. Across the member states already inspecting — Belgium has been running NIS2 inspections through the CCB since April 2026 — the opening requests are consistent and none of them requires a security specialist to answer.

  1. Proof of registration, and the date of it.
  2. The management body decision approving the risk-management measures — the minute, with a date and an attendance list.
  3. Evidence that the management body followed training, per article 20(2).
  4. The risk assessment, and the link from it to the measures actually implemented.
  5. The incident process, and the record of what was notified, when, and to whom.
  6. Supplier assurance: what you asked of direct suppliers and what you did with the answers.

Every one of those is a document that either exists on the day or does not. Nothing on the list can be produced retrospectively without it being obvious, which is the point of asking for them first.

The practical conclusion

If you are an essential entity, assume you will be inspected without a trigger and keep the six documents above current. If you are an important entity, your exposure is dominated by what your own filings and incidents reveal about you — the quality of an incident notification is a supervisory signal, not just a compliance step.

And in both cases, the expensive outcome is rarely the fine. It is the audit you did not scope and the finding you did not get to phrase.

What to do about it
  • Settle your essential-or-important classification early: it decides whether you can be inspected without cause.
  • Keep six documents current — registration, board approval, board training, risk assessment, incident record, supplier assurance.
  • Hold a recent independent assessment. It is the practical defence against an audit commissioned at your expense.
  • Treat every incident notification as a supervisory signal, not just a filing.
  • Brief the board on article 32(6). The personal prohibition is what makes article 20 more than paperwork.
Cart 0