NIS2 Country Guide

NIS2 Denmark: Compliance, Authorities & Key Requirements

Denmark’s NIS-2-loven has applied since 1 July 2025. Two things set it apart: penalties are criminal fines imposed by a court, and the Act states no maximum at all - the turnover caps quoted everywhere are the Directive’s, not Denmark’s. And the body you deal with is Styrelsen for Samfundssikkerhed, not the Centre for Cyber Security.

In force: 1 Jul 2025 Authority: SAMSIK Penalties: criminal fines Report: 24h / 72h / 1 month Last updated: 12 August 2026

Introduction: NIS2 Directive & the Danish context

The NIS2 Directive strengthens cybersecurity requirements across the EU. In Denmark, NIS2 is implemented through a general framework law and sector-specific acts. If you operate in Denmark (or offer services there), assess whether you are an essential or important entity and prepare accordingly.

The framework law is the NIS-2-loven, and sector-specific acts sit alongside it for energy, telecoms and finance. Supervision is deliberately decentralised: the Act speaks only of den kompetente myndighed - the competent authority - and leaves it to each sector’s responsible authority. There is no single Danish cyber regulator that supervises everyone.

Quick link: Read our overview “What is NIS2?” and “NIS vs NIS2” for background before diving into Denmark’s specifics.

How Denmark transposed NIS2

Denmark transposed NIS2 via the NIS-2-lovenLov om foranstaltninger til sikring af et højt cybersikkerhedsniveau (Act on measures to ensure a high level of cybersecurity). The Act entered into force on 1 July 2025.

Status

In force since 1 July 2025 (Act no. 434 of 6 May 2025). Section 33 also requires the minister to report to the Folketing on experience with the Act within three years - by 1 July 2028.

Registration

Via Virk.dk with MitID Erhverv, run by SAMSIK. It opened 1 July 2025 and the first deadline was 1 October 2025 - but it remains a standing duty.

SectorDanish note
EnergySector law in force since 7 March 2025; implements elements of the CER Directive. Stricter requirements may apply based on risk classification.
TelecomIn force since 1 July 2025. Providers with limited/ancillary public access (e.g., cafés, hotels) are generally exempt from most NIS2 requirements.
FinanceAligned with the DORA Regulation; in force. Supervision by sector authority.

Public sector: most administrative bodies (incl. municipalities) are covered, with exclusions (e.g., Parliament, Ombudsman, courts). Defence, law enforcement and certain security bodies are exempt.

Chemicals: entities not subject to REACH registration for hazardous industrial chemicals are considered out of scope.

Who is in scope

Denmark follows NIS2’s two-tier model (Essential / Important) and applies size criteria in line with the directive.

The thresholds, precisely

  • Essential (section 4): 250 staff or more, or annual turnover above EUR 50m and a balance sheet total above EUR 43m.
  • Important (section 5): 50 staff or more, or annual turnover above EUR 10m and a balance sheet total above EUR 10m.
  • Note the and in the financial limbs - one figure on its own does not bring you in.

In scope regardless of size

  • Qualified trust service providers, top-level domain name administrators and DNS service providers are essential whatever their size (section 4(3)).
  • Other trust service providers that do not meet the essential criteria are important regardless of size (section 5(3)).
  • Providers of public electronic communications networks or publicly available services come in at 50 staff or EUR 10m.

Municipalities and regions

Section 4(2): municipalities and regions count as essential entities where they commercially carry out the tasks of a provider of public electronic communications networks or publicly available electronic communications services. Most other administrative bodies are covered too, with the Folketing, the Ombudsman and the courts excluded, and defence, law enforcement and certain security bodies exempt.

Certification can be made mandatory by order. The Act mandates no standard, and official guidance points at ISO/IEC 27001:2023, NIST CSF 2.0 and IEC 62443 as alignment frameworks. But section 8 lets the relevant minister require entities to use ICT products, services or processes certified under a European cybersecurity certification scheme to demonstrate compliance - built in-house or bought in.

Registration on Virk.dk

Registration is handled by Styrelsen for Samfundssikkerhed (SAMSIK) through Virk.dk, logging in with MitID Erhverv. It opened on 1 July 2025 and the first deadline was 1 October 2025.

That date has passed - the duty has not

If you were covered on 1 July 2025, registration was due by 1 October 2025 and is now overdue rather than closed. If you came into scope afterwards, you register when the Act applies to you.

Keeping it current

Changes must be filed as a fresh form stating what has changed, been added or removed, within three months of the change. Registration is a standing obligation.

Digital providers file more

Section 9: DNS providers, TLD administrators, domain registration services, cloud, data centres, CDNs, managed service and managed security providers, online marketplaces, search engines and social platforms register with the relevant competent authority and give name, main establishment and other EU establishments, contact details and the member states served.

Domain registries carry a separate duty. Section 11 requires TLD administrators and domain-name registration services to keep a distinct database of accurate and complete registration data - domain name, registration date, registrant name, e-mail and telephone, and the contact point administering the domain - with published verification policies, non-personal data made public without undue delay, and lawful access for legitimate access seekers on a case-by-case necessity assessment.

What the management body must do

Section 7 is short and carries two duties that are easy to miss because they are not phrased as "training and oversight".

  • The measures must be approved by the management body (ledelsesorgan), which then supervises their implementation. The approval is the statutory act - drafting the measures does not discharge section 7 on its own, and an unapproved set of controls is a gap on the face of the Act.
  • Members of the management body must attend relevant courses on managing cybersecurity risk, and must encourage equivalent courses being offered to the entity’s other staff. The duty to promote staff training sits on the management body itself, not on the security function.
Breach of section 6(1) or (2) is one of the provisions that carries a criminal fine under section 32. Section 7 approval is how you evidence that section 6 has been discharged.

Who supervises you

The Act names nobody. It refers throughout to den kompetente myndighed - the competent authority - and leaves the designation to sector-responsible authorities. That is deliberate, and it means the answer to "who is our regulator" is different for a hospital, a water utility and a cloud provider.

RoleWhoNotes
National NIS2 body: registration, guidanceStyrelsen for Samfundssikkerhed (SAMSIK)Runs the Virk.dk registration and publishes the national NIS2 guidance.
Your supervisorThe sector-responsible authority for your sectorThese are the kompetente myndigheder of the Act. They guide, supervise and enforce. SAMSIK publishes the list.
National CSIRTHosted by the Danish Defence Intelligence Service, where the Centre for Cyber Security sitsReceives incident reports and owes a reply within 24 hours.
Registration channelVirk.dk with MitID ErhvervOpened 1 July 2025; first deadline 1 October 2025.
If your file says the Centre for Cyber Security is the NIS2 authority, update it. The CFCS NIS2 page now redirects to SAMSIK. The Centre’s CSIRT role continues under the Defence Intelligence Service; what has moved is the registration, the guidance and the national point of entry. Incident reports go to both your competent authority and the CSIRT - see reporting.

Incident reporting: 24h / 72h / one month

Section 12 requires notification to two recipients - the relevant competent authority and the CSIRT - and the notification must carry enough information to establish any cross-border effects. Most transpositions name one destination.

24 hourstidlig varsling, an early warning stating whether the incident is suspected to have been caused by unlawful or malicious acts.
72 hours — the incident notification proper.
Interim report — sent on the CSIRT’s request, with relevant status updates.
Final report — within one month of the incident notification: a detailed description including severity and impact, the threat type or root cause likely to have triggered it, mitigations applied and ongoing, and any cross-border effects.
Still ongoing? Send a status report at that point and a final report within one month of the incident being handled.

Trust services: 24 hours

Section 13(2): a trust service provider files the incident notification within 24 hours of becoming aware, not 72.

The CSIRT owes you the most on this project

Section 13(3): within 24 hours of the early warning the CSIRT must respond with initial feedback, and on request provide guidance, operational advice on mitigations and supplementary technical assistance.

Near-misses can be reported voluntarily

Section 14: entities outside the Act’s scope may notify the CSIRT of incidents, nærvedhændelser (near-misses) and cyber threats. The CSIRT handles them the same way but may prioritise statutory reports.

Telling customers, and going public. Section 15 requires you to inform service recipients without undue delay of significant incidents likely to affect your services, and to tell potentially affected recipients about significant cyber threats and the countermeasures they can take. Section 16 lets the competent authority inform the public itself, after hearing you, where that is needed to prevent or handle the incident or is otherwise in the public interest - or order you to do it.

The ten required measures

Section 6 requires appropriate and proportionate technical, operational and organisational measures, and sets a floor of ten. They must be approved by the management body under section 7.

  1. Policies for risk analysis and information system security
  2. Incident handling
  3. Business continuity, including backup management, disaster recovery and crisis management
  4. Supply chain security, including the security aspects of relationships with direct suppliers and service providers
  5. Security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure
  6. Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
  7. Basic cyber hygiene practices and cybersecurity training
  8. Policies on the use of cryptography and, where appropriate, encryption
  9. Personnel security, access control policies and asset management
  10. Multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communication systems where appropriate

Timeline & key dates

27 Dec 2022 — NIS2 published in the EU Official Journal.
17 Oct 2024 — EU transposition deadline for Member States.
1 Jul 2025 — Danish NIS-2 Act enters into force; sectoral acts (energy, telecom, finance) in force.
1 Oct 2025 — registration deadline for organisations covered on 1 July 2025. Entities coming into scope later register when the Act applies to them.
By 1 Jul 2028 — section 33 requires the minister to report to the Folketing on experience with the Act within three years of entry into force.

Sector-specific notes

  • Telecom: entities with limited, ancillary public access (e.g., cafés, hotels, housing associations) are generally exempt from most NIS2 obligations.
  • Energy: sub-sector thresholds apply; stricter duties may be imposed based on risk classification.
  • Finance: aligned with DORA requirements; supervised by the financial authority.

Penalties: criminal, not administrative

Denmark did not create an administrative fining power. Chapter 9, section 32 makes breach a criminal offence punishable by fine (med bøde straffes den, der…), prosecuted through the ordinary criminal process and decided by a court.

The Act sets no maximum fine. The EUR 10 million / 2% and EUR 7 million / 1.4% figures quoted across the advisory market are the Directive’s ceilings. They do not appear in the Danish Act: the only EUR 10 million figures in the text are the section 5 size thresholds, and the percentage caps appear nowhere. A Danish fine is set by a court under ordinary sentencing principles. We would rather print no number than one that gets quoted back to us.

What section 32 actually reaches:

  • Breach of section 6(1) or (2) - the risk-management measures - and of sections 9, 10, 11(1)-(6), 12(1), 13(1)-(2) or 15.
  • Failing to comply with a decision under section 23(1)(1) or (2).
  • Failing to comply with orders or prohibitions under section 22(1)(3)-(6) or section 25(1)(3)-(6).
  • Failing to comply with a decision under section 16(2), section 21(1)(2) or (5)-(7), or section 24(1)(2) or (4)-(6).
  • Obstructing supervision under section 21(1)(1)-(4) or section 24(1)(1)-(3).

Section 32(2) applies corporate criminal liability under Chapter 5 of the Danish Criminal Code, so the company itself is the defendant. Section 32(3) allows regulations issued under the Act to attach their own fines, so the sector orders can extend the criminal exposure beyond the Act.

Enforcement powers

Before any prosecution, the competent authority has a ladder of measures under sections 21 to 25, and two of them are unusual enough to plan for.

A monitor placed inside the entity

Section 22(7): the authority may appoint a person responsible for supervising the entity’s compliance with sections 6, 12, 13 and 15 and section 16(2) for a defined period.

Non-anonymised publication

Sections 22(8) and 25(6): the authority may order the entity to publish, in non-anonymised form and in a specified manner, decisions on enforcement measures and summaries of judgments or accepted fines. Naming and shaming is a statutory power here.

Escalation on a deadline

Section 23: where measures under section 22(1)(1)-(4) have proved insufficient, the authority sets a deadline within which the essential entity must remedy the shortcomings or meet its requirements.

Other measures in the ladder include ordering the entity to implement the recommendations of a completed security audit, and ordering it to inform the natural or legal persons affected by a significant cyber threat about the threat and the protective or remedial steps available to them.

You have a right to be heard first. Section 26: before deciding to apply enforcement measures under sections 22, 23 or 25, the authority must notify the entity of the measures it intends to take and the reasons, and give it a reasonable period to comment - except where doing so would defeat the purpose of the measure.

How Denmark differs

If you are running NIS2 across several member states, these are the points where Denmark will not behave like your other jurisdictions.

  • There is no administrative fine. Breach is a criminal offence prosecuted in the ordinary way, and the Act states no maximum - so the Directive’s caps are not Danish law.
  • Corporate criminal liability applies under Chapter 5 of the Criminal Code.
  • The Act names no authority. It says only den kompetente myndighed; your supervisor is your sector-responsible authority, while SAMSIK runs registration and guidance.
  • Incidents are reported to two recipients - the competent authority and the CSIRT.
  • The CSIRT owes you the most of any on this site: a 24-hour reply, plus guidance, operational advice and supplementary technical assistance on request.
  • Near-misses can be reported voluntarily, including by entities outside the Act.
  • The authority can place a monitor inside the entity and can order non-anonymised publication of enforcement decisions and fine summaries.
  • Municipalities and regions are essential entities where they commercially provide electronic communications.
  • Certification can be made compulsory by order under section 8, even though no standard is mandated today.

Danish terms you will meet

SAMSIK, the sector authorities and the Act itself use these terms. There is no official English translation of the Act.

DanishEnglish
NIS-2-loventhe Danish NIS2 Act (Act no. 434 of 6 May 2025)
Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveauits full title: Act on measures to ensure a high level of cybersecurity
Styrelsen for Samfundssikkerhed (SAMSIK)the agency running NIS2 registration and guidance
den kompetente myndighedthe competent authority - your sector-responsible supervisor
væsentlig enhed / vigtig enhedessential entity / important entity
væsentlig hændelsesignificant incident
tidlig varslingearly warning, due in 24 hours
nærvedhændelsenear-miss - reportable voluntarily under section 14
ledelsesorganthe management body that must approve the measures
bødefine - here a criminal one, imposed by a court
håndhævelsesforanstaltningerenforcement measures (sections 22 and 25)
MitID Erhvervthe business login used for Virk.dk

How to prepare

  1. Determine scope: confirm your Annex I/II services and size thresholds; classify EE/IE.
  2. Register on Virk.dk with MitID Erhverv. The 1 October 2025 deadline applied to entities covered on 1 July 2025; if that was you and you have not filed, it is overdue rather than closed. Set a reminder for the three-month change-notification duty.
  3. Get the management body to formally approve the measures - section 7 makes the approval itself the statutory act - and book the required courses for its members.
  4. Risk management: implement/upscale ISO 27001/NIST CSF aligned controls across IT/OT.
  5. Supply chain: assess MSPs/MSSPs and critical suppliers; build contractual security requirements.
  6. Build the reporting chain to reach two recipients - your competent authority and the CSIRT - on 24 hours, 72 hours and one month, and identify your sector-responsible authority before you need it.
  7. Continuity & crisis: document BCP/DR, run exercises and penetration tests.
  8. Train & prove: management training, staff awareness, and auditable evidence.

Official links & resources

NIS-2-loven — the full Act on Retsinformation (2025/434) — the primary source for everything on this page

FAQ: NIS2 in Denmark

When did NIS2 enter into force in Denmark?
On 1 July 2025 the Danish NIS-2 Act entered into force.
Who do I register with, and has the deadline passed?
With SAMSIK via Virk.dk using MitID Erhverv. 1 October 2025 applied to entities covered when the Act commenced on 1 July 2025 - if that was you and you have not registered, it is overdue, not closed. Entities coming into scope later register when the Act applies to them, and changes must be filed within three months.
Who is our supervisory authority?
Your sector-responsible authority. The Act names nobody - it refers only to den kompetente myndighed - and SAMSIK publishes the list. SAMSIK itself runs registration and guidance rather than supervising every sector.
Is the Centre for Cyber Security still the NIS2 authority?
No. The CFCS NIS2 page now redirects to SAMSIK, which is the national NIS2 body. The Centre’s CSIRT role continues under the Danish Defence Intelligence Service, and incident reports still reach it - but registration, guidance and the national point of entry have moved.
How much can we be fined?
The Act sets no maximum. Denmark created no administrative fining power: section 32 makes breach a criminal offence punishable by fine, prosecuted in the ordinary way and decided by a court, with corporate liability under Chapter 5 of the Criminal Code. The EUR 10 million / 2% and EUR 7 million / 1.4% figures quoted widely are the Directive’s ceilings and do not appear in the Danish Act.
What are the reporting deadlines?
24 hours for the early warning, 72 hours for the incident notification, and a final report within one month - or within one month of the incident being handled if it is still running. Trust service providers file the notification within 24 hours. Reports go to both your competent authority and the CSIRT.
Does the CSIRT have to respond?
Yes. Within 24 hours of your early warning it must give initial feedback, and on request provide guidance, operational advice on mitigating measures and supplementary technical assistance.
Can we report something that was not a real incident?
Yes. Section 14 allows public and private entities - including those outside the Act - to notify the CSIRT of incidents, near-misses and cyber threats. The CSIRT handles them the same way, though it may prioritise statutory reports.
Does NIS2 apply regardless of size?
Generally the thresholds are 250 staff or turnover above EUR 50m and a balance sheet above EUR 43m for essential entities, and 50 staff or turnover above EUR 10m and a balance sheet above EUR 10m for important ones. But qualified trust service providers, TLD administrators and DNS providers are essential regardless of size.
Are there specific standards I must certify against?
Not today - but section 8 lets the relevant minister require ICT products, services or processes certified under a European cybersecurity certification scheme. Current guidance points at ISO/IEC 27001:2023, NIST CSF 2.0 and IEC 62443.
What can the authority do short of prosecuting us?
Quite a lot. It can order an audit’s recommendations to be implemented, appoint a person to monitor your compliance for a set period, and order you to publish enforcement decisions and fine summaries in non-anonymised form. It must give you a reasonable chance to comment first (section 26).
Information provided for general guidance; consult official national sources for updates.