A Competent Authority is the sector regulator or designated authority that assesses whether an organisation meets relevant cybersecurity requirements under the framework. In practice, the authority may adapt CAF expectations to the sector it oversees and decide how compliance is reviewed or evidenced.
What a Competent Authority Does
A competent authority is the designated regulator or assessor for a specific framework or sector. It determines how requirements are interpreted in practice, what evidence is acceptable, and how organisations are reviewed against the relevant cybersecurity expectations.
Why the Role Matters in Compliance Reviews
This role matters because the same underlying control set can be assessed differently across sectors, and the authority’s interpretation often becomes the practical standard organisations must meet. For regulated entities, the authority is the body that turns abstract requirements into an enforceable review model, often shaping documentation, testing, and remediation expectations.
Competent authority decisions can also affect consistency across firms, especially when sector guidance leaves room for judgement. That makes the role important not just for formal compliance, but for how risk is evidenced and accepted in day-to-day supervision.
How the Authority Shapes Evidence and Oversight
The authority typically influences the evidence model, including what is considered sufficient assurance, how gaps are prioritised, and whether a control is judged by design, operation, or outcome. In practice, this can affect audit trails, third-party evidence, remediation timelines, and the extent to which sector context is reflected in assessments.
For organisations, this means the same control may require different supporting material depending on the regulator or designated body. The practical challenge is less about the control text itself and more about aligning internal assurance to the authority’s review expectations.
Where Competent Authority Sits in the Governance Chain
A competent authority is not the control owner and not the implementing team. It sits above the organisation as an external oversight function, while still shaping how governance is exercised within the regulated domain. That distinction matters because it separates policy interpretation from internal responsibility.
In sectors with multiple obligations, the competent authority may also be the point that harmonises sector-specific expectations with broader regulatory requirements. That makes it a key reference point for governance, escalation, and supervisory accountability.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 and NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | A competent authority defines the sector context in which cybersecurity requirements are interpreted. |
| Recommendation — Map the authority’s remit to governance context so compliance evidence matches the sector it oversees. | ||
| ISO/IEC 27001:2022 | A.5.31 — Legal, statutory, regulatory and contractual requirements | Competent authorities operationalise regulatory requirements that organisations must evidence and meet. |
| Recommendation — Track the authority’s expectations as part of your legal and regulatory obligations register. | ||
| NIS2 | N/A — Competent Authority Oversight | NIS2 relies on designated authorities for supervision, enforcement and sector-specific oversight. |
| Recommendation — Align reporting and assurance processes to the competent authority that supervises your sector. | ||
Related resources from NHI Mgmt Group
- What is the difference between identity governance and authority governance?
- What is the difference between access visibility and access authority?
- What is the difference between delegated user access and machine authority for AI agents?
- What is the difference between delegated access and agent authority?