Skip to content

NIS 2 IN DENMARK

Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau (NIS 2-loven) — the national act transposing Directive (EU) 2022/2555 in Denmark. Supervised by Center for Cybersikkerhed (CFCS).

TRANSPOSED — IN FORCE

Key facts

In force
1 July 2025
National law
Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau (NIS 2-loven)
Primary supervisor
Center for Cybersikkerhed (CFCS)
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Covered entities register with the relevant sector supervisor within three months of becoming subject to the act; the central CFCS register collates the records.

Scope and national nuance

Denmark transposed via a sector-by-sector approach with multiple parallel acts, coordinated by CFCS under the Ministry of Defence. The framework law sets the baseline; sector-specific regulations supplement it for energy, telecom and finance.

Sector supervisors

SectorAuthorityAcronym
EnergyEnergistyrelsenENS
HealthSundhedsdatastyrelsenSDS
Drinking water and waste waterMiljøstyrelsenMST
Financial servicesFinanstilsynetFT

What is specific to Denmark

DSI Advisory — NIS 2 Programme

Move from reading the law to evidencing compliance

Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to CFCS’s supervisory expectations.

NIS 2 Scorecard →Scope & gap assessment →NIS 2 reference page →