Skip to content
atlas
← Back to the entry

What NIS2 is and who it applies to

NIS2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It replaces the first NIS Directive (2016/1148), which covered a narrow set of “operators of essential services” and was applied very unevenly between member states. As a directive, NIS2 does not apply directly: each member state writes it into national law. In Denmark this is the NIS2 law (NIS2-loven), in force since 1 July 2025, with Styrelsen for Samfundssikkerhed (SAMSIK, the Danish Resilience Agency), as the coordinating authority and sector authorities supervising their own sectors. Incident reports are made via Virk.dk and handled by the Danish Defence Intelligence Service (Forsvarets Efterretningstjeneste) as national CSIRT; Center for Cybersikkerhed (CFCS), whose advisory work moved into the agency in January 2025, publishes threat assessments and guidance. Finance is largely governed by DORA instead.

Scope is decided by sector and size:

In-scope organisations are either essential or important entities. Both face the same security and reporting duties; the difference is supervision. Essential entities are supervised proactively (inspections and audits can happen without any incident), while important entities are supervised reactively, typically after an incident or a complaint. The directive requires maximum fines of at least EUR 10 million or 2 % of global turnover for essential entities, and EUR 7 million or 1.4 % for important entities, whichever is higher.

The key requirements

Article 20 - governance. The management body must approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for breaches. Members of management must follow training, and staff should be offered similar training regularly. This is the article that moves security from the IT department to the boardroom.

Article 21 - risk-management measures. Measures must be appropriate and proportionate to the risk, based on an “all-hazards” approach (not only hackers, but also fire, power failure and human error). Article 21(2) lists ten minimum areas:

Minimum measure
a Policies on risk analysis and information system security
b Incident handling
c Business continuity: backup management, disaster recovery, crisis management
d Supply chain security, including relationships with direct suppliers
e Security in acquisition, development and maintenance, incl. vulnerability handling and disclosure
f Policies and procedures to assess the effectiveness of the measures
g Basic cyber hygiene practices and cybersecurity training
h Cryptography and, where appropriate, encryption
i Human resources security, access control policies and asset management
j Multi-factor or continuous authentication, secured voice/video/text and emergency communications

Article 23 - reporting. A significant incident (one that has caused or can cause severe operational disruption or financial loss, or considerable damage to others) must be reported to the CSIRT or competent authority in stages:

Deadline Report
Within 24 hours of becoming aware Early warning - is it suspected to be malicious, could it have cross-border impact?
Within 72 hours Incident notification - initial assessment of severity, impact and indicators of compromise
On request Intermediate report on status
Within one month of the notification Final report - root cause, measures taken, cross-border impact (a progress report if still ongoing)

Where relevant, the organisation must also inform the recipients of its services.

How NIS2 connects to the other frameworks

NIS2 says what must be achieved, not how. That is where the voluntary frameworks come in:

What a coordinator actually does with it

  1. Scope check. Confirm whether the organisation is in scope, as essential or important, and register with the authority if the national law requires it.
  2. Gap analysis. Compare current practice against the ten Article 21 areas. A simple spreadsheet with “requirement - current state - owner - next step” is often enough to start.
  3. Roadmap. Prioritise the gaps by risk and effort; get management to approve the plan and the budget (Article 20 makes that approval a legal duty, not a courtesy).
  4. Reporting procedure. Write down who decides that an incident is “significant”, who submits the 24-hour early warning, and how the GDPR track is handled in parallel. Test it in a table-top exercise.
  5. Suppliers. Inventory critical suppliers, add security terms to contracts and follow up.
  6. Training and documentation. Arrange management training, run awareness for staff and keep evidence - minutes, approvals, training logs - because the supervisory authority will ask for it.

Common misunderstandings

Atlas is in beta.