Law / Denmark

NIS 2-loven, Cybersecurity Risk-Management Measures and Registration

NIS 2-loven, §§ 6-10

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 July 2025.

A sector security regimes rule binding public and private bodies.

As of 15 September 2026.

What it requires

  • This binds an essential entity (Section 4) or an important entity (Section 5) drawn from Annex 1 or Annex 2; Annex 1's digital-infrastructure entry (item 8) names an internet-exchange-point provider, a DNS provider other than a root-server operator, a top-level-domain registry, a cloud-computing-service provider, a data-centre-service provider, a content-delivery-network provider, a trust-service provider, and a provider of a public electronic-communications network or service, and Annex 2's digital-provider entry (item 6) separately names an online marketplace, an online search engine, and a social-networking-services-platform provider, so a service in any of those lines is reached once it clears the entity's size threshold. The wider sector classes (energy, transport, water, health, waste, chemicals, food, manufacturing and the rest) are a designation and size class no activity in this vocabulary expresses, and neither are the entities Section 1(2) routes to Denmark's separate energy-sector, telecom-sector or financial-entity regimes; none is raised here on that account.
  • Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems you use for your operations or to provide your services, and to prevent an incident or minimise its impact on the recipients of your services and on other services.
  • Cover at minimum: risk-analysis and information-system-security policies; incident handling; operational continuity, including backup management, disaster recovery and crisis management; supply-chain security, including your relationship with your direct suppliers and service providers; security in acquiring, developing and maintaining your network and information systems, including vulnerability handling and disclosure; policies and procedures for assessing the effectiveness of your cybersecurity risk-management measures; basic cyber-hygiene practices and cybersecurity training; policies and procedures on the use of cryptography and, where relevant, encryption; personnel security, access-control policies and asset management; and, where relevant, multi-factor or continuous authentication, secured voice, video and text communication, and secured internal emergency-communication systems.
  • Where you fall short of any of these requirements, take without undue delay all necessary, appropriate and proportionate corrective measures.
  • Have your management board (ledelsesorgan) approve these measures and oversee their implementation, and ensure its members attend relevant cybersecurity risk-management training and encourage similar training for your other staff.
  • If you are a DNS provider, top-level-domain registry, domain-name-registration-service provider, or a provider of cloud-computing, data-centre, content-delivery-network, managed, managed-security, online-marketplace, online-search-engine or social-networking-services-platform services, register with the relevant competent authority within 3 months of first falling within the Act's scope, stating your name, address, sector and sub-sector, contact details, and the EU member states where you provide services. Other essential and important entities register within 2 weeks of first falling within scope. Anyone already in scope when the Act commenced had to register by 1 October 2025.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Section 32(1) punishes a violation of, among other provisions, Section 6(1) or (2), Sections 9 or 10, or Section 11(1) to (6) with a criminal fine (bøde), not an administrative fine the competent authority itself may impose; the offence is prosecuted through Denmark's ordinary criminal process (police and public prosecutor, with the courts where contested) rather than a supervisory penalty decision. Section 32(2) attaches corporate (legal-person) criminal liability under Chapter 5 of the Criminal Code (straffeloven). The Act states no fixed monetary maximum and no turnover-percentage cap of its own; the amount of a Section 32 fine is set case by case under Denmark's general criminal-sentencing principles rather than by a statutory ceiling, unlike the EUR 10 million/2 percent and EUR 7 million/1.4 percent administrative-fine tiers most other Member States' NIS2 transpositions enact.

Who enforces it

Enforcement body

The authority the Minister for Societal Security and Preparedness (Ministeren for samfundssikkerhed og beredskab) designates by executive order as competent authority for the entity's sector, subsector or entity type, after negotiating with the minister responsible for that sector (Section 20(1)); retsinformation.dk's own list of orders and circulars issued under this Act showed none as of the date read, so which named authority that will be for the digital-infrastructure and digital-provider lines this row flags is not yet settled in the primary record.

Settledness

As of
15 September 2026
Open questions
  • Retsinformation.dk's own register of orders and circulars issued under this Act listed none as of 2026-09-15, so which authority has the Minister for Societal Security and Preparedness designated under Section 20 as competent for the digital-infrastructure and digital-provider lines this row flags?
  • Has the responsible minister issued the further rules on risk-management measures that Section 6(3) reserves the power to set, and if so, do they narrow or particularise any of the ten minimum elements Section 6(1) already lists?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 6 requires an essential entity or an important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems it uses for its operations or to provide its services, and to prevent an incident or minimise its impact on the recipients of its services and on other services, covering at minimum risk-analysis and information-system-security policy, incident handling, operational continuity, supply-chain security, secure acquisition and development including vulnerability handling and disclosure, effectiveness-assessment policy, cyber hygiene and training, cryptography policy, personnel and access-management security, and, where relevant, multi-factor or continuous authentication and secured communications (Section 6(1)); an entity that falls short must take corrective measures without undue delay (Section 6(2)).

Section 7 requires the entity's management board (ledelsesorgan) to approve these measures, oversee their implementation, and ensure its own members receive cybersecurity risk-management training.

Section 9 requires a DNS provider, a top-level-domain registry, a domain-name-registration-service provider, and a provider of cloud-computing, data-centre, content-delivery-network, managed, managed-security, online-marketplace, online-search-engine or social-networking-services-platform services to register with the relevant competent authority within 3 months of first falling within the Act's scope; Section 10 requires other essential and important entities to register within 2 weeks.

This Act, Lov nr 434 af 6. maj 2025 (NIS 2-loven), transposes NIS2 Directive Articles 21 and 24. By Section 1(2), it does not apply to an entity covered by Denmark's separate energy-sector preparedness Act, its telecommunications-sector security and preparedness Act, or the financial entities the Financial Business Act's Section 333(1) designates, each of which runs its own parallel regime.

By Section 33(4) to (7), it also repeals Denmark's four 2018 NIS1-era security laws (Lov nr 436, 437, 440 and 441 af 8. maj 2018).

When LexLint raises it

  • operates_social_platform

Read the law

Consolidated text, retsinformation.dk, NIS 2-loven, LOV nr 434 af 06/05/2025, gældende (current) version

Back to the example  ·  Lint your app