Skip to content
atlas

Danish NIS2 Act (NIS2-loven)

Also known as: Danish NIS 2 Act, Act No. 434 of 6 May 2025

The Danish law that writes the EU's NIS2 rules into national law and names who checks that firms follow them.

Draft - this entry has not been reviewed yet.

Formal

Act No. 434 of 6 May 2025, in force from 1 July 2025, which carries out the NIS2 Directive in Denmark; it sets the security measures, the duties of the management body and the reporting deadlines, and makes each sector authority supervise the entities in its own sector.

In plain English

The EU writes the recipe, but each country bakes its own cake - this is the Danish one, with Danish inspectors tasting it.

In practice

A waste company owned by several municipalities registers online with the authorities by 1 October 2025, has its board approve the security measures and, after a serious attack, sends an early warning within 24 hours, a fuller notice within 72 hours and a final report within a month.

Why it matters

A directive binds the member state, not the firm; only this act makes the NIS2 duties binding on Danish companies and public bodies and names the authorities who can inspect and fine them.

Technical deep dive

The act, formally "lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau", is a horizontal framework law, and three sectors sit outside it: energy has its own act on strengthened preparedness in the energy sector, telecommunications its own act on security and preparedness in the telecom sector, and finance is governed by DORA and the Danish Financial Business Act. Within its scope the structure follows the directive closely. § 1 sets the scope by reference to the act's Annexes 1 and 2, § 2 jurisdiction, § 3 definitions, and §§ 4-5 classify entities as essential or important using the directive's size thresholds, with central government bodies, TLD registries, DNS providers and qualified trust service providers essential regardless of size.

The core duties are in §§ 6-7 and 12-15. § 6 lists the technical, operational and organisational measures corresponding to NIS2 Article 21(2), and § 7 requires the management body to approve and oversee them and its members to take part in training. § 12 requires significant incidents to be reported to the competent authority and the CSIRT, and § 13 fixes the stages: early warning within 24 hours, incident notification within 72 hours, intermediate reports on request and a final report within one month, with the CSIRT replying to an early warning within 24 hours. § 15 requires recipients of the service to be informed without undue delay where they may be affected.

Registration is split in two: § 9 covers DNS, TLD, domain registration, cloud, CDN, managed and managed security service providers, online marketplaces, search engines and social network platforms, and § 10 covers all essential and important entities; for entities existing at entry into force, § 33(3) set the deadline at 1 October 2025. § 11 imposes duties on TLD registries and registrars to keep accurate registration data. Reports and registrations go through Virk, with incidents handled by the national CSIRT at the Danish Defence Intelligence Service (Forsvarets Efterretningstjeneste).

Supervision is decentralised. Under § 20 rules issued by the Minister for Resilience and Preparedness designate the competent authority for each sector, while Styrelsen for Samfundssikkerhed acts as the coordinating authority. Authorities can issue binding orders to essential (§ 22) and important (§ 25) entities, and § 23 allows, for essential entities only and after other measures have failed, a temporary ban on a person at managing-director level from exercising management functions. Under § 32 violations are punishable by fine; as usual in Danish law this is a criminal sanction decided through the courts rather than an administrative fine set by the supervisory authority, which is a practical difference from how many other member states have implemented NIS2 Article 34.

Relationships

Implements
NIS2 Directive

Sources & further reading

Official documentation

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.