Compliance
Also known as: regulatory compliance
Living up to the laws, rules and standards that apply - for example NIS2, GDPR or ISO 27001.
Draft - this entry has not been reviewed yet.
Formal
The state of meeting the requirements set by laws, contracts, standards and the organisation's own policies, and being able to show proof that they are met.
In plain English
Like a car passing its road-worthiness check - it proves the car meets the rules, but not that it is driven safely.
In practice
Before the yearly audit, the compliance officer at a Danish pension fund gathers proof that backups have been test-restored and that every employee has completed the required security training.
Why it matters
Failing to comply can mean fines, lost customers and personal liability for managers - and requirements often force needed work that would otherwise be put off.
Technical deep dive
Compliance has three sources of obligation with different consequences. Law and regulation, such as GDPR, NIS2 as transposed in Denmark by the NIS2 law in force since 1 July 2025, DORA for financial entities since 17 January 2025, and sector rules, are enforced by authorities with fines and orders. Contracts, such as data processing agreements under GDPR Art. 28, customer security schedules and PCI DSS for card data, are enforced by counterparties. Voluntary standards such as ISO/IEC 27001 bind only once the organisation commits to them, although Danish state authorities have been required to follow ISO/IEC 27001 since 2014. ISO/IEC 27002:2022 controls 5.31 (legal, statutory, regulatory and contractual requirements) and 5.36 (compliance with policies, rules and standards) require these obligations to be identified, kept current and checked.
Assurance comes in distinct forms. ISO/IEC 27001 certification is performed by an accredited certification body in a stage 1 (documentation and readiness) and stage 2 (implementation) audit, followed by surveillance audits in years two and three and recertification on a three-year cycle; certificates to the 2013 edition expired at the end of the transition period on 31 October 2025. SOC 2 reports against the AICPA Trust Services Criteria come as Type I (design at a point in time) or Type II (operating effectiveness over a period, typically six to twelve months). In Denmark, ISAE 3000 and ISAE 3402 assurance reports from auditors are the common way processors demonstrate compliance with data processing agreements.
Sanctions differ by regime. GDPR Art. 83 allows administrative fines of up to 20 million euros or 4 % of global annual turnover for the most serious infringements, although in Denmark fines are imposed by the courts after a police report rather than directly by Datatilsynet. NIS2 Art. 34 sets maxima of at least 10 million euros or 2 % of turnover for essential entities and 7 million euros or 1.4 % for important entities, and Art. 20 makes management bodies responsible for approving and overseeing the measures.
Compliance and security overlap but are not the same. Frameworks lag behind threats, audits sample rather than test everything, and a control can be documented without being effective, a pattern often called checkbox compliance. Conversely, a well-defended organisation can fail an audit for missing evidence. Mature programmes use a unified control framework that maps one control to many requirements, collect evidence continuously from systems rather than by hand before each audit, and use gap analysis to prioritise. Compliance proves that a required baseline exists and is evidenced; governance and risk management decide whether that baseline is enough.
Relationships
Sources & further reading
Standards & official texts
- ISO/IEC 27002:2022 - Control 5.36, Compliance with policies, rules and standards for information security · ISO/IEC
Official documentation
- Styrelsen for Samfundssikkerhed - Implementering af NIS 2 i dansk ret · Styrelsen for Samfundssikkerhed
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…