NIS2 Denmark: Compliance, Authorities & Key Requirements
Denmark’s NIS-2-loven has applied since 1 July 2025. Two things set it apart: penalties are criminal fines imposed by a court, and the Act states no maximum at all - the turnover caps quoted everywhere are the Directive’s, not Denmark’s. And the body you deal with is Styrelsen for Samfundssikkerhed, not the Centre for Cyber Security.
Introduction: NIS2 Directive & the Danish context
The NIS2 Directive strengthens cybersecurity requirements across the EU. In Denmark, NIS2 is implemented through a general framework law and sector-specific acts. If you operate in Denmark (or offer services there), assess whether you are an essential or important entity and prepare accordingly.
The framework law is the NIS-2-loven, and sector-specific acts sit alongside it for energy, telecoms and finance. Supervision is deliberately decentralised: the Act speaks only of den kompetente myndighed - the competent authority - and leaves it to each sector’s responsible authority. There is no single Danish cyber regulator that supervises everyone.
How Denmark transposed NIS2
Denmark transposed NIS2 via the NIS-2-loven — Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau (Act on measures to ensure a high level of cybersecurity). The Act entered into force on 1 July 2025.
Status
In force since 1 July 2025 (Act no. 434 of 6 May 2025). Section 33 also requires the minister to report to the Folketing on experience with the Act within three years - by 1 July 2028.
Official law
Registration
Via Virk.dk with MitID Erhverv, run by SAMSIK. It opened 1 July 2025 and the first deadline was 1 October 2025 - but it remains a standing duty.
| Sector | Danish note |
|---|---|
| Energy | Sector law in force since 7 March 2025; implements elements of the CER Directive. Stricter requirements may apply based on risk classification. |
| Telecom | In force since 1 July 2025. Providers with limited/ancillary public access (e.g., cafés, hotels) are generally exempt from most NIS2 requirements. |
| Finance | Aligned with the DORA Regulation; in force. Supervision by sector authority. |
Public sector: most administrative bodies (incl. municipalities) are covered, with exclusions (e.g., Parliament, Ombudsman, courts). Defence, law enforcement and certain security bodies are exempt.
Chemicals: entities not subject to REACH registration for hazardous industrial chemicals are considered out of scope.
Who is in scope
Denmark follows NIS2’s two-tier model (Essential / Important) and applies size criteria in line with the directive.
The thresholds, precisely
- Essential (section 4): 250 staff or more, or annual turnover above EUR 50m and a balance sheet total above EUR 43m.
- Important (section 5): 50 staff or more, or annual turnover above EUR 10m and a balance sheet total above EUR 10m.
- Note the and in the financial limbs - one figure on its own does not bring you in.
In scope regardless of size
- Qualified trust service providers, top-level domain name administrators and DNS service providers are essential whatever their size (section 4(3)).
- Other trust service providers that do not meet the essential criteria are important regardless of size (section 5(3)).
- Providers of public electronic communications networks or publicly available services come in at 50 staff or EUR 10m.
Municipalities and regions
Section 4(2): municipalities and regions count as essential entities where they commercially carry out the tasks of a provider of public electronic communications networks or publicly available electronic communications services. Most other administrative bodies are covered too, with the Folketing, the Ombudsman and the courts excluded, and defence, law enforcement and certain security bodies exempt.
Registration on Virk.dk
Registration is handled by Styrelsen for Samfundssikkerhed (SAMSIK) through Virk.dk, logging in with MitID Erhverv. It opened on 1 July 2025 and the first deadline was 1 October 2025.
That date has passed - the duty has not
If you were covered on 1 July 2025, registration was due by 1 October 2025 and is now overdue rather than closed. If you came into scope afterwards, you register when the Act applies to you.
Keeping it current
Changes must be filed as a fresh form stating what has changed, been added or removed, within three months of the change. Registration is a standing obligation.
Digital providers file more
Section 9: DNS providers, TLD administrators, domain registration services, cloud, data centres, CDNs, managed service and managed security providers, online marketplaces, search engines and social platforms register with the relevant competent authority and give name, main establishment and other EU establishments, contact details and the member states served.
What the management body must do
Section 7 is short and carries two duties that are easy to miss because they are not phrased as "training and oversight".
- The measures must be approved by the management body (ledelsesorgan), which then supervises their implementation. The approval is the statutory act - drafting the measures does not discharge section 7 on its own, and an unapproved set of controls is a gap on the face of the Act.
- Members of the management body must attend relevant courses on managing cybersecurity risk, and must encourage equivalent courses being offered to the entity’s other staff. The duty to promote staff training sits on the management body itself, not on the security function.
Incident reporting: 24h / 72h / one month
Section 12 requires notification to two recipients - the relevant competent authority and the CSIRT - and the notification must carry enough information to establish any cross-border effects. Most transpositions name one destination.
Trust services: 24 hours
Section 13(2): a trust service provider files the incident notification within 24 hours of becoming aware, not 72.
The CSIRT owes you the most on this project
Section 13(3): within 24 hours of the early warning the CSIRT must respond with initial feedback, and on request provide guidance, operational advice on mitigations and supplementary technical assistance.
Near-misses can be reported voluntarily
Section 14: entities outside the Act’s scope may notify the CSIRT of incidents, nærvedhændelser (near-misses) and cyber threats. The CSIRT handles them the same way but may prioritise statutory reports.
The ten required measures
Section 6 requires appropriate and proportionate technical, operational and organisational measures, and sets a floor of ten. They must be approved by the management body under section 7.
- Policies for risk analysis and information system security
- Incident handling
- Business continuity, including backup management, disaster recovery and crisis management
- Supply chain security, including the security aspects of relationships with direct suppliers and service providers
- Security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure
- Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
- Basic cyber hygiene practices and cybersecurity training
- Policies on the use of cryptography and, where appropriate, encryption
- Personnel security, access control policies and asset management
- Multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communication systems where appropriate
Timeline & key dates
Sector-specific notes
- Telecom: entities with limited, ancillary public access (e.g., cafés, hotels, housing associations) are generally exempt from most NIS2 obligations.
- Energy: sub-sector thresholds apply; stricter duties may be imposed based on risk classification.
- Finance: aligned with DORA requirements; supervised by the financial authority.
Penalties: criminal, not administrative
Denmark did not create an administrative fining power. Chapter 9, section 32 makes breach a criminal offence punishable by fine (med bøde straffes den, der…), prosecuted through the ordinary criminal process and decided by a court.
What section 32 actually reaches:
- Breach of section 6(1) or (2) - the risk-management measures - and of sections 9, 10, 11(1)-(6), 12(1), 13(1)-(2) or 15.
- Failing to comply with a decision under section 23(1)(1) or (2).
- Failing to comply with orders or prohibitions under section 22(1)(3)-(6) or section 25(1)(3)-(6).
- Failing to comply with a decision under section 16(2), section 21(1)(2) or (5)-(7), or section 24(1)(2) or (4)-(6).
- Obstructing supervision under section 21(1)(1)-(4) or section 24(1)(1)-(3).
Section 32(2) applies corporate criminal liability under Chapter 5 of the Danish Criminal Code, so the company itself is the defendant. Section 32(3) allows regulations issued under the Act to attach their own fines, so the sector orders can extend the criminal exposure beyond the Act.
Enforcement powers
Before any prosecution, the competent authority has a ladder of measures under sections 21 to 25, and two of them are unusual enough to plan for.
A monitor placed inside the entity
Section 22(7): the authority may appoint a person responsible for supervising the entity’s compliance with sections 6, 12, 13 and 15 and section 16(2) for a defined period.
Non-anonymised publication
Sections 22(8) and 25(6): the authority may order the entity to publish, in non-anonymised form and in a specified manner, decisions on enforcement measures and summaries of judgments or accepted fines. Naming and shaming is a statutory power here.
Escalation on a deadline
Section 23: where measures under section 22(1)(1)-(4) have proved insufficient, the authority sets a deadline within which the essential entity must remedy the shortcomings or meet its requirements.
Other measures in the ladder include ordering the entity to implement the recommendations of a completed security audit, and ordering it to inform the natural or legal persons affected by a significant cyber threat about the threat and the protective or remedial steps available to them.
How Denmark differs
If you are running NIS2 across several member states, these are the points where Denmark will not behave like your other jurisdictions.
- There is no administrative fine. Breach is a criminal offence prosecuted in the ordinary way, and the Act states no maximum - so the Directive’s caps are not Danish law.
- Corporate criminal liability applies under Chapter 5 of the Criminal Code.
- The Act names no authority. It says only den kompetente myndighed; your supervisor is your sector-responsible authority, while SAMSIK runs registration and guidance.
- Incidents are reported to two recipients - the competent authority and the CSIRT.
- The CSIRT owes you the most of any on this site: a 24-hour reply, plus guidance, operational advice and supplementary technical assistance on request.
- Near-misses can be reported voluntarily, including by entities outside the Act.
- The authority can place a monitor inside the entity and can order non-anonymised publication of enforcement decisions and fine summaries.
- Municipalities and regions are essential entities where they commercially provide electronic communications.
- Certification can be made compulsory by order under section 8, even though no standard is mandated today.
Danish terms you will meet
SAMSIK, the sector authorities and the Act itself use these terms. There is no official English translation of the Act.
| Danish | English |
|---|---|
| NIS-2-loven | the Danish NIS2 Act (Act no. 434 of 6 May 2025) |
| Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau | its full title: Act on measures to ensure a high level of cybersecurity |
| Styrelsen for Samfundssikkerhed (SAMSIK) | the agency running NIS2 registration and guidance |
| den kompetente myndighed | the competent authority - your sector-responsible supervisor |
| væsentlig enhed / vigtig enhed | essential entity / important entity |
| væsentlig hændelse | significant incident |
| tidlig varsling | early warning, due in 24 hours |
| nærvedhændelse | near-miss - reportable voluntarily under section 14 |
| ledelsesorgan | the management body that must approve the measures |
| bøde | fine - here a criminal one, imposed by a court |
| håndhævelsesforanstaltninger | enforcement measures (sections 22 and 25) |
| MitID Erhverv | the business login used for Virk.dk |
How to prepare
- Determine scope: confirm your Annex I/II services and size thresholds; classify EE/IE.
- Register on Virk.dk with MitID Erhverv. The 1 October 2025 deadline applied to entities covered on 1 July 2025; if that was you and you have not filed, it is overdue rather than closed. Set a reminder for the three-month change-notification duty.
- Get the management body to formally approve the measures - section 7 makes the approval itself the statutory act - and book the required courses for its members.
- Risk management: implement/upscale ISO 27001/NIST CSF aligned controls across IT/OT.
- Supply chain: assess MSPs/MSSPs and critical suppliers; build contractual security requirements.
- Build the reporting chain to reach two recipients - your competent authority and the CSIRT - on 24 hours, 72 hours and one month, and identify your sector-responsible authority before you need it.
- Continuity & crisis: document BCP/DR, run exercises and penetration tests.
- Train & prove: management training, staff awareness, and auditable evidence.
