We help you get ready for NIS2 in Denmark
Denmark transposed NIS2 through NIS 2-loven, LOV nr 434, supervised by Styrelsen for Samfundssikkerhed together with a named sector authority for each sector. Energy, telecoms and the financial sector answer to separate Danish rules instead.
Audit41 Readiness assesses you against the Danish requirements, shows you exactly where you stand, and gives you the ranked actions to close each gap.
Check your Denmark NIS2 scope- 1
Registration
1 October 2025
- 2
Measures
1 July 2025
- 3
Audit
No recurring audit. Sections 21 and 24 let the authority demand documentation of how cybersecurity policies are implemented, and require a qualified independent body to audit the entity and hand over the results
No fixed cycle. Supervision is continuous for essential entities and reactive for important ones
Which tier are you?
Essential entities are Annex 1 organisations with at least 250 staff, or with turnover above the large-enterprise ceiling and a balance sheet total above it as well. Both financial figures have to be exceeded, not just one. Essential entities are supervised continuously, whether or not anything has gone wrong.
Penalties
Fines are set by the courts under the Act, and companies carry criminal liability. Denmark did not transpose the directive ceiling, so the Danish act names no maximum amount and no turnover percentage. The authority can also suspend a certification and temporarily bar the chief executive from management functions.
Important entities are Annex 1 or Annex 2 organisations at the medium threshold, meaning at least fifty staff, or turnover and balance sheet total both above the medium ceiling. Supervision here is reactive, so the authority acts when it has a specific reason. The security obligations themselves are identical to those of an essential entity.
Penalties
The same fine provision applies. The certification suspension and the management ban do not; those powers reach essential entities only.
Your obligations under NIS 2-loven
Establish first whether NIS 2-loven reaches you at all. Energy undertakings answer to a separate act supervised by Energistyrelsen, telecoms to another, and designated financial entities to DORA. In Denmark the sector question comes before the size question.
Register with your sector authority through virk.dk using MitID, and keep the registered details current. This is a standing duty rather than a one-off window: an organisation that grows into scope registers within the statutory period, and later changes are notified within it too.
Implement the risk management measures the Act sets out across its ten categories, from risk analysis policies and incident handling through supply chain security and cryptography to multi-factor authentication.
Have your management body approve those measures and supervise their implementation. Members of the management body have to attend training on managing cybersecurity risk, and have to encourage equivalent training for the rest of the organisation.
Report significant incidents to your sector authority and to the CSIRT, through the same virk.dk channel, on the statutory early warning, notification and final report chain.
Tell the recipients of your services about a significant incident where it is likely to affect the service you deliver to them.
Be able to produce documentation of how your cybersecurity policies are implemented. The authority can demand it, and can require a qualified independent body to audit you and hand the results over.
Danish law does not name a standard. The implementation guidance from Styrelsen for Samfundssikkerhed maps the required measures onto ISO/IEC 27001 among other frameworks, and says plainly that following a standard helps with compliance without being assurance of it in itself. ISO 27001 is a strong foundation in Denmark, and it is not a presumption of conformity.
Sectors in scope
Denmark runs three regimes, not one
Section 1(2) of NIS 2-loven states that the Act does not apply to entities to the extent they are covered by the energy sector preparedness act. Danish electricity, gas, hydrogen, oil, district heating and district cooling undertakings therefore answer to Energistyrelsen under a separate act and its executive order, which carry their own security and incident rules and their own recurring filing. Telecoms are carved out the same way, and the financial sector is taken by DORA. A multi-utility can sit under two regimes at once, because the carve-out is scoped to the extent the entity is covered.
The digital sector follows an EU regulation, not the Danish act
DNS providers, TLD registries, cloud and data centre services, content delivery networks, managed service and managed security service providers, online marketplaces, search engines, social platforms and trust service providers are not covered by the general security and incident reporting requirements of NIS 2-loven. Digitaliseringsstyrelsen states that they follow the EU implementing regulation instead, which is considerably more prescriptive. Operating one listed service brings the whole company under it, even where that service is a small part of the business.
No audit cycle, and no notice either
Denmark sets no recurring audit, no self-assessment filing and nothing to submit on a schedule. What it sets instead is a standing power: your authority can demand documentation of how your cybersecurity policies are implemented, and can require a qualified independent body to audit you and give it the results. The guidance splits the measures into what has to be implemented and what should be, and where you have not implemented one of the second kind you have to be able to explain to the supervisor why, from a documented risk position. That explanation is a specific document, and most organisations do not hold it in a form that survives review.
Your sector authority is probably not the one you expect
A separate executive order names a supervisor for each sector, and the split is finer than most organisations assume. Health and medical device manufacture go to Sundhedsdatastyrelsen. Drinking water, waste water and most waste go to Miljøstyrelsen, while waste incineration goes to Energistyrelsen. Air, rail, road, ports and postal go to Trafikstyrelsen, but shipping companies go to Søfartsstyrelsen. Food goes to Fødevarestyrelsen. Manufacturing, chemicals and several others sit with Styrelsen for Samfundssikkerhed. Knowing which one supervises you decides who you register with and who you report an incident to.
From gap report to a position you can defend
Danish supervision does not announce itself, so the useful question is not when the audit falls but whether you could answer a request for documentation this week. Audit41 Readiness assesses you against the Danish requirements and produces the part that matters: every finding linked to the evidence it came from, and every gap ranked by severity with the action that closes it. Sage, the advisor built into the platform, explains a requirement when it is not obvious and helps you draft the policy text a fix needs. You leave with the documented, risk-based position the guidance expects you to hold.

Know which Danish rules apply to you
The free self-check applies the Danish rules, tells you which regime and which authority reaches you, and recommends the right assessment.
Check your Denmark NIS2 scopeThis self-check result is for information only. Audit41 and EMP42 Consulting Kft. accept no liability for the accuracy of the classification. Consult a qualified legal advisor before making a final decision.