Directive NIS2 European Union
DK · Member state

NIS2 in Denmark


What binds you in Denmark is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.

Transposition
Transposed
Competent authority
Styrelsen for Samfundssikkerhed
National CSIRT
VAT on your purchase
25%

Reviewed . Verify against the national official journal before relying on this for a filing.

The text that actually binds you

National transposition


Status of the national text · In force since 1 July 2025

§ 6

Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau (NIS 2-loven), LOV nr. 434 af 6. maj 2025

Adopted
In force
Risk-management measures
10

Adopted at third reading on 29 April 2025, promulgated on 6 May 2025 and in force since 1 July 2025 (§ 33, stk. 1) — entities have been required to comply since that date. Two companion acts took effect the same day: the CER act, and a separate act on security and preparedness in the telecoms sector (LOV nr. 435 af 6. maj 2025). A telecoms operator works from that act, not from the NIS 2-loven.

This is not the article you read in the directive

The ten measures of article 21(2) are carried by § 6, stk. 1 of the NIS 2-loven, one for one: Denmark layered no national obligation on top. Cite § 6 in your documentation rather than article 21(2) — the supervisor reads the Danish act. What Denmark did delegate is the detail, which arrives through sector regulation and SAMSIK guidance rather than through the act itself.

Registration

Digital form on virk.dk, signed in with MitID Erhverv

The register opened on 1 July 2025 and the deadline was 1 October 2025. An entity that comes into scope later registers within two weeks of coming into scope, not on the original national deadline. Incident notifications under § 12 go through the same virk.dk access and are routed to the CSIRT and to the sector-responsible authority; the CSIRT itself is reachable at CSIRT@fe-ddis.dk.

Open the portal →

Supervision

SAMSIK inspections

Supervision is split by sector rather than concentrated in one regulator: § 20, stk. 1 leaves the designation to ministerial rules, and BEK nr. 620 af 2. juni 2025 names one sector-responsible authority per sector — the act calls them the competent authorities. SAMSIK supervises public administration and municipalities, manufacturing including chemicals, the telecoms sector and maritime traffic services. Elsewhere it is Energistyrelsen (energy), Trafikstyrelsen and Søfartsstyrelsen (transport, postal services), Sundhedsdatastyrelsen (health, medical devices), Finanstilsynet (banking and financial market infrastructure), Miljøstyrelsen (drinking water, wastewater, waste), Digitaliseringsstyrelsen (digital infrastructure and digital providers), Fødevarestyrelsen (food) and Uddannelses- og Forskningsstyrelsen (research, space). Establish which one is yours before you need to file anything.

Who supervises you

Styrelsen for Samfundssikkerhed is the competent authority designated by Denmark. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.

Incident notifications under article 23 normally go to FE/DDIS, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.

What differs from the directive

Because NIS2 is a directive, Denmark legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:

  • Registration. The portal, the information required and the deadline are national.
  • Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
  • Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
  • Reporting format. Deadlines are fixed by the directive; the form and the language are national.

If you operate in several member states

You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.

Cart 0