Law / Denmark

NIS 2-loven, Significant-Incident Reporting and Recipient-Notice Duties

NIS 2-loven, §§ 12-13, 15

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 July 2025.

A vulnerability and incident reporting rule binding public and private bodies.

As of 15 September 2026.

What it requires

  • This binds the same essential and important entities as this jurisdiction's companion risk-management row: Annex 1's digital-infrastructure entry (item 8) and Annex 2's digital-provider entry (item 6), at the size thresholds Sections 4 and 5 set; the wider sector classes, and the entities Section 1(2) routes to Denmark's separate energy-sector, telecom-sector or financial-entity regimes, are not raised here for the same reason.
  • Notify your competent authority and Denmark's CSIRT of every significant incident, one that has caused or can cause serious operational disruption or financial loss for you, or has affected or can affect another person through significant physical or non-physical harm.
  • Send an early warning without undue delay, and no later than 24 hours after becoming aware of the significant incident, stating whether it is suspected to result from an unlawful or malicious act and whether it may have a cross-border effect.
  • Follow with a notification, without undue delay and in any case within 72 hours of becoming aware of the incident, updating the early warning with an initial assessment of the incident's severity and impact, including any indicators of compromise where available.
  • Submit an interim report if your CSIRT asks for one, and a final report no later than one month after your notification, describing the incident in detail, its severity and impact, the likely threat or root cause, mitigating measures applied and under way, and any cross-border effects. If the incident is still ongoing at that point, submit a status report instead and the final report within one month of the incident being handled.
  • If you are a trust-service provider, send only the 72-hour-shaped notification, without undue delay and no later than 24 hours after becoming aware of the significant incident, rather than the separate two-step early-warning and notification sequence.
  • Notify the recipients of your service, without undue delay, of a significant incident likely to adversely affect the delivery of your service to them, and inform any recipient potentially affected by a significant cyber threat of the measures or countermeasures they can take in response, and of the threat itself where relevant.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Section 32(1) punishes a violation of, among other provisions, Section 12(1) or Section 13(1) or (2) or Section 15 with a criminal fine (bøde), not an administrative fine the competent authority itself may impose; the offence is prosecuted through Denmark's ordinary criminal process (police and public prosecutor, with the courts where contested) rather than a supervisory penalty decision. Section 32(2) attaches corporate (legal-person) criminal liability under Chapter 5 of the Criminal Code (straffeloven). The Act states no fixed monetary maximum and no turnover-percentage cap of its own; the amount of a Section 32 fine is set case by case under Denmark's general criminal-sentencing principles rather than by a statutory ceiling, unlike the EUR 10 million/2 percent and EUR 7 million/1.4 percent administrative-fine tiers most other Member States' NIS2 transpositions enact.

Who enforces it

Enforcement body

The authority the Minister for Societal Security and Preparedness designates by executive order as competent authority for the entity's sector (Section 20(1)), with the CSIRT receiving the incident notifications directly (Section 12(1)); retsinformation.dk's own list of orders and circulars issued under this Act showed none as of the date read, so the named authority for the digital-infrastructure and digital-provider lines this row flags is not yet settled in the primary record.

Settledness

As of
15 September 2026
Open questions
Has the responsible minister issued the further rules Section 12(3) reserves the power to set on when an incident counts as significant, beyond the two general triggers Section 12(2) already states, since retsinformation.dk's own register listed no order under this Act as of 2026-09-15?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 12 requires an essential entity or an important entity to notify the relevant competent authority and Denmark's CSIRT of every significant incident, defined as one that has caused or can cause serious operational disruption or financial loss for the entity, or that has affected or can affect another person through significant physical or non-physical harm.

Section 13 sets the notification clock: an early warning without undue delay and no later than 24 hours after becoming aware of the incident (Section 13(1)(1)); a notification without undue delay and in any case within 72 hours, updating the early warning with an initial severity and impact assessment (Section 13(1)(2)); an interim report on the CSIRT's request (Section 13(1)(3)); and a final report no later than one month after the notification, or, if the incident is still ongoing, a status report at that point and a final report within one month of the incident being handled (Section 13(1)(4) and (5)).

A trust-service provider instead sends only the Section 13(1)(2) notification, without undue delay and within 24 hours (Section 13(2)); the CSIRT must acknowledge an early warning within 24 hours and, on request, can offer guidance and operational advice (Section 13(3)).

Section 15 separately requires an essential or important entity to notify its service recipients, without undue delay, of a significant incident likely to adversely affect the delivery of their service, and to inform any recipient potentially affected by a significant cyber threat of the protective or responsive measures available to them.

This Act, Lov nr 434 af 6. maj 2025 (NIS 2-loven), transposes NIS2 Directive Articles 23 and 30 and, by Section 33(4) to (7), repeals Denmark's four 2018 NIS1-era security laws (Lov nr 436, 437, 440 and 441 af 8. maj 2018).

When LexLint raises it

  • operates_social_platform

Read the law

Consolidated text, retsinformation.dk, NIS 2-loven, LOV nr 434 af 06/05/2025, gældende (current) version

Back to the example  ·  Lint your app