← All modules and pricing

NIS2

NIS2 in Denmark — the NIS 2-loven, guided.

Registration via virk.dk, the same ten minimum measures, Danish reporting deadlines — we translate the law into a task list.

Price

Price on request

Depends on which country or countries you implement NIS2 for — we calculate it together with you.

Request a quote →

All prices plus VAT, flat per company, hosted in Germany, cancel monthly.

See bundles →Questions? Request a demo →

What NIS2 requires of you.

1

Find out whether you're in scope, and at which tier — before anything else gets registered or reported.

2

Register with the competent national authority inside the statutory deadline.

3

Put all ten statutory minimum measures in place — from risk analysis to multi-factor authentication — each backed by dated evidence, not a checkbox.

4

Report incidents through the correct channel, at every stage the law requires: early warning, formal report, and follow-up.

In numbers, from our requirement catalogue

12

Requirements in the catalogue

11

Provisions checked against the statute text and backed by at least one measure in the catalogue

Every requirement carries a source, every one has at least one measure — checked by an automated catalogue test on every change. That's the foundation of our promise: audit-ready.

Denmark's NIS 2-loven (Act No. 434 of 6 May 2025)

Competent authority

A sector-specific competent authority, designated under Executive Order (Bekendtgørelse) No. 620 of 2 June 2025 — Denmark splits NIS2 oversight by sector rather than assigning it to one central agency

Classification: NIS 2-loven, Sections 1, 4, 5 and Annexes 1 and 2 · Registration: Register via virk.dk — within 3 months (Section 9) for domain-name registries, cloud and platform providers, or within 2 weeks (Section 10) for all other in-scope entities

Reporting incidents: Section 13(1) of the NIS 2-loven — reported to the authority responsible for your sector under BEK nr 620 af 02/06/2025

Key dates — all already in force

  • Denmark: Executive Order on authority assignment in force — in force since 01/07/2025(BEK nr 620 af 02/06/2025, § 17)
  • Denmark: common registration start date — in force since 01/10/2025(NIS 2-loven § 33 stk. 3)

The ten minimum measures — same duty, your source citation

01

Risk analysis and information security policies

Section 6(1), No. 1, NIS 2-loven

02

Incident handling

Section 6(1), No. 2, NIS 2-loven

03

Business continuity — backup, disaster recovery, crisis management

Section 6(1), No. 3, NIS 2-loven

04

Supply chain security

Section 6(1), No. 4, NIS 2-loven

05

Security in acquisition, development and maintenance

Section 6(1), No. 5, NIS 2-loven

06

Effectiveness assessment

Section 6(1), No. 6, NIS 2-loven

07

Basic training and awareness measures

Section 6(1), No. 7, NIS 2-loven

08

Cryptographic procedures

Section 6(1), No. 8, NIS 2-loven

09

Personnel security, access control and management of ICT systems

Section 6(1), No. 9, NIS 2-loven

10

Multi-factor authentication and secure communications

Section 6(1), No. 10, NIS 2-loven

Named openly and honestly: The NIS 2-loven doesn't name a CSIRT — it only refers to “the CSIRT.” Which body that is for your sector follows from the authority assignment in Executive Order (Bekendtgørelse) No. 620 of 2 June 2025. Clarify this before an incident, not during one.

One honest note: There is no official NIS2 certificate. Unlike ISO 27001, NIS2 is a regulatory obligation, not a certification scheme — no accredited body issues a "NIS2-certified" seal, and no vendor can honestly sell you one. What we deliver instead is audit-ready evidence: every requirement met, documented, and dated, so you can show a regulator or a large customer exactly how you meet the law.

NIS2 in Denmark: frequently asked questions

What does the NIS2 in Denmark module cost at Compliverse?

We don't publish a list price for this module — we calculate it with you, because scope, the number of companies and, for NIS2, the number of countries differ too much. You get a written quote with a fixed amount before anything starts. You can ask for one through the contact form; a sales call is not a precondition.

NIS2 in Denmark: legal obligation or voluntary?

An obligation — though not for every company. Sector and size decide whether you are in scope (NIS 2-loven, Sections 1, 4, 5 and Annexes 1 and 2). No official notice arrives: you assess the classification yourself and register if it applies (Sections 9, 10 NIS 2-loven). Judging your individual case is a lawyer's job; we supply structure and evidence, not legal advice.

What does NIS2 in Denmark actually require of us?

Find out whether you're in scope, and at which tier — before anything else gets registered or reported. Register with the competent national authority inside the statutory deadline. Put all ten statutory minimum measures in place — from risk analysis to multi-factor authentication — each backed by dated evidence, not a checkbox. Report incidents through the correct channel, at every stage the law requires: early warning, formal report, and follow-up.

How completely does Compliverse cover NIS2 in Denmark?

Our catalogue holds 12 requirements for this framework. Each carries a legal source and each has at least one measure behind it — checked by an automated test on every change, not by good intentions. That is what "audit-ready" means for us: we do not guarantee that you end up compliant, because nobody can do that honestly. We guarantee that it is provable.

Which authority is responsible in Denmark — and where do we report an incident?

Registration and supervision: A sector-specific competent authority, designated under Executive Order (Bekendtgørelse) No. 620 of 2 June 2025 — Denmark splits NIS2 oversight by sector rather than assigning it to one central agency. Registering: Register via virk.dk — within 3 months (Section 9) for domain-name registries, cloud and platform providers, or within 2 weeks (Section 10) for all other in-scope entities. Reporting an incident: to the authority responsible for your sector under BEK nr 620 af 02/06/2025, under Section 13(1) of the NIS 2-loven. The incident assistant takes you there with the clock running.

Our promise

We don't say “compliant”. We say audit-ready — and we can prove it.

Nobody can guarantee that a company did everything right in an audit — not even a provider who promises it more confidently. What can be guaranteed is this. Four points, each independently verifiable.

01

Complete against the statute text

Every provision we cover has at least one requirement, every requirement at least one measure — and every one carries its source citation. That's not a promise: an automated test checks the catalogue on every change. If it finds a gap, the module doesn't ship.

→ Verifiable in each framework's requirement catalogue

02

Current, with a date

We re-read the legal texts in the original wording every month and update the product, training and website to match. Every check lands publicly in the change log — even when nothing changed.

→ Public change log on the Legal Landscape page

03

Evidenced, not asserted

Every requirement we mark as met has a document, certificate or log behind it — with a source citation and a legal-status date. What you can't hand an auditor doesn't count as done with us.

→ Evidence package as PDF, exportable at any time

04

Honest about the boundary

We provide structure, documents and evidence — not legal advice for your specific case. Where a question belongs with a lawyer, we say so instead of selling you something.

→ No legal advice — printed on every document

See the change log →

Last checked on 01/09/2026. That's how you get evidence that survives scrutiny — instead of a binder that falls apart at the first follow-up question.

What becomes important next

More modules

Legal status checked on 01/09/2026 · Every statement with a source · No legal advice