Skip to content
atlas

Danish NIS2 Act (NIS2-loven)

Also known as: Danish NIS 2 Act, Act No. 434 of 6 May 2025

The Danish law that writes the EU's NIS2 rules into national law and names who checks that firms follow them.

Draft - this entry has not been reviewed yet.

Formal

Act No. 434 of 6 May 2025, in force from 1 July 2025, which carries out the NIS2 Directive in Denmark; it sets the security measures, the duties of the management body and the reporting deadlines, and makes each sector authority supervise the entities in its own sector.

In plain English

The EU writes the recipe, but each country bakes its own cake - this is the Danish one, with Danish inspectors tasting it.

In practice

A waste company owned by several municipalities registers online with the authorities by 1 October 2025, has its board approve the security measures and, after a serious attack, sends an early warning within 24 hours, a fuller notice within 72 hours and a final report within a month.

Why it matters

A directive binds the member state, not the firm; only this act makes the NIS2 duties binding on Danish companies and public bodies and names the authorities who can inspect and fine them.

How to put it into practice

The usual steps, in order. Adapt them to your organisation.

  1. Check whether you are covered with the NIS2 check on sikkerdigital.dk and SAMSIK's guidance on scope, and whether you are an essential or important entity (§§ 4-5); energy, telecom and finance follow their own acts.
  2. Find the competent authority for your sector in SAMSIK's list of sector authorities, and read its sector-specific rules and guidance.
  3. Register on virk.dk with MitID Erhverv (§ 10) within two weeks of becoming covered (entities covered at entry into force had until 1 October 2025), and report changes within two weeks.
  4. Have the management body approve the § 6 measures and oversee their implementation, and make sure its members attend relevant cybersecurity courses (§ 7).
  5. Carry out a risk assessment and implement the § 6 minimum measures, from risk policy, incident handling, backup and supply chain security to cryptography, access control and MFA.
  6. Write an incident procedure for §§ 12-13 with an early warning within 24 hours, an incident notification within 72 hours and a final report within one month, submitted through the joint form on virk.dk.
  7. Decide how you will inform the recipients of your services without undue delay about significant incidents and threats that may affect them (§ 15).
  8. Keep documentation ready for supervision, since the authority can issue orders (§§ 22 and 25), temporarily ban a manager in an essential entity (§ 23), and violations are punished by fines (§ 32).
  9. Review the risk assessment, measures and procedures at least yearly and after major changes, and report them to management.

Common pitfalls

  • Thinking the October 2025 registration deadline is history, when an entity that becomes covered later has only two weeks to register.
  • Letting an outsourced IT provider handle incident reporting without checking it, although the responsibility for reporting on time always stays with the entity.
  • Treating the NIS2 notification as covering a personal data breach, instead of also notifying Datatilsynet, which the Virk form lets you select.
  • Assuming an energy, telecom or financial company follows this act, when they have their own sector laws.

Good guides

Technical deep dive

The act, formally "lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau", is a horizontal framework law, and three sectors sit outside it: energy has its own act on strengthened preparedness in the energy sector, telecommunications its own act on security and preparedness in the telecom sector, and finance is governed by DORA and the Danish Financial Business Act. Within its scope the structure follows the directive closely. § 1 sets the scope by reference to the act's Annexes 1 and 2, § 2 jurisdiction, § 3 definitions, and §§ 4-5 classify entities as essential or important using the directive's size thresholds, with central government bodies, TLD registries, DNS providers and qualified trust service providers essential regardless of size.

The core duties are in §§ 6-7 and 12-15. § 6 lists the technical, operational and organisational measures corresponding to NIS2 Article 21(2), and § 7 requires the management body to approve and oversee them and its members to take part in training. § 12 requires significant incidents to be reported to the competent authority and the CSIRT, and § 13 fixes the stages: early warning within 24 hours, incident notification within 72 hours, intermediate reports on request and a final report within one month, with the CSIRT replying to an early warning within 24 hours. § 15 requires recipients of the service to be informed without undue delay where they may be affected.

Registration is split in two: § 9 covers DNS, TLD, domain registration, cloud, CDN, managed and managed security service providers, online marketplaces, search engines and social network platforms, and § 10 covers all essential and important entities; for entities existing at entry into force, § 33(3) set the deadline at 1 October 2025. § 11 imposes duties on TLD registries and registrars to keep accurate registration data. Reports and registrations go through Virk, with incidents handled by the national CSIRT at the Danish Defence Intelligence Service (Forsvarets Efterretningstjeneste).

Supervision is decentralised. Under § 20 rules issued by the Minister for Resilience and Preparedness designate the competent authority for each sector, while Styrelsen for Samfundssikkerhed acts as the coordinating authority. Authorities can issue binding orders to essential (§ 22) and important (§ 25) entities, and § 23 allows, for essential entities only and after other measures have failed, a temporary ban on a person at managing-director level from exercising management functions. Under § 32 violations are punishable by fine; as usual in Danish law this is a criminal sanction decided through the courts rather than an administrative fine set by the supervisory authority, which is a practical difference from how many other member states have implemented NIS2 Article 34.

Relationships

Implements
NIS2 Directive

Sources & further reading

Official documentation

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.