NIS2
NIS2 in Denmark — the NIS 2-loven, guided.
Registration via virk.dk, the same ten minimum measures, Danish reporting deadlines — we translate the law into a task list.
Price
Price on request
Depends on which country or countries you implement NIS2 for — we calculate it together with you.
Request a quote →All prices plus VAT, flat per company, hosted in Germany, cancel monthly.
See bundles →Questions? Request a demo →What NIS2 requires of you.
Find out whether you're in scope, and at which tier — before anything else gets registered or reported.
Register with the competent national authority inside the statutory deadline.
Put all ten statutory minimum measures in place — from risk analysis to multi-factor authentication — each backed by dated evidence, not a checkbox.
Report incidents through the correct channel, at every stage the law requires: early warning, formal report, and follow-up.
In numbers, from our requirement catalogue
12
Requirements in the catalogue
11
Provisions checked against the statute text and backed by at least one measure in the catalogue
Every requirement carries a source, every one has at least one measure — checked by an automated catalogue test on every change. That's the foundation of our promise: audit-ready.
Denmark's NIS 2-loven (Act No. 434 of 6 May 2025)
Competent authority
A sector-specific competent authority, designated under Executive Order (Bekendtgørelse) No. 620 of 2 June 2025 — Denmark splits NIS2 oversight by sector rather than assigning it to one central agency
Classification: NIS 2-loven, Sections 1, 4, 5 and Annexes 1 and 2 · Registration: Register via virk.dk — within 3 months (Section 9) for domain-name registries, cloud and platform providers, or within 2 weeks (Section 10) for all other in-scope entities
Reporting incidents: Section 13(1) of the NIS 2-loven — reported to the authority responsible for your sector under BEK nr 620 af 02/06/2025
Key dates — all already in force
- Denmark: Executive Order on authority assignment in force — in force since 01/07/2025(BEK nr 620 af 02/06/2025, § 17)
- Denmark: common registration start date — in force since 01/10/2025(NIS 2-loven § 33 stk. 3)
The ten minimum measures — same duty, your source citation
Risk analysis and information security policies
Section 6(1), No. 1, NIS 2-loven
Incident handling
Section 6(1), No. 2, NIS 2-loven
Business continuity — backup, disaster recovery, crisis management
Section 6(1), No. 3, NIS 2-loven
Supply chain security
Section 6(1), No. 4, NIS 2-loven
Security in acquisition, development and maintenance
Section 6(1), No. 5, NIS 2-loven
Effectiveness assessment
Section 6(1), No. 6, NIS 2-loven
Basic training and awareness measures
Section 6(1), No. 7, NIS 2-loven
Cryptographic procedures
Section 6(1), No. 8, NIS 2-loven
Personnel security, access control and management of ICT systems
Section 6(1), No. 9, NIS 2-loven
Multi-factor authentication and secure communications
Section 6(1), No. 10, NIS 2-loven
Named openly and honestly: The NIS 2-loven doesn't name a CSIRT — it only refers to “the CSIRT.” Which body that is for your sector follows from the authority assignment in Executive Order (Bekendtgørelse) No. 620 of 2 June 2025. Clarify this before an incident, not during one.
One honest note: There is no official NIS2 certificate. Unlike ISO 27001, NIS2 is a regulatory obligation, not a certification scheme — no accredited body issues a "NIS2-certified" seal, and no vendor can honestly sell you one. What we deliver instead is audit-ready evidence: every requirement met, documented, and dated, so you can show a regulator or a large customer exactly how you meet the law.
NIS2 in Denmark: frequently asked questions
What does the NIS2 in Denmark module cost at Compliverse?
We don't publish a list price for this module — we calculate it with you, because scope, the number of companies and, for NIS2, the number of countries differ too much. You get a written quote with a fixed amount before anything starts. You can ask for one through the contact form; a sales call is not a precondition.
NIS2 in Denmark: legal obligation or voluntary?
An obligation — though not for every company. Sector and size decide whether you are in scope (NIS 2-loven, Sections 1, 4, 5 and Annexes 1 and 2). No official notice arrives: you assess the classification yourself and register if it applies (Sections 9, 10 NIS 2-loven). Judging your individual case is a lawyer's job; we supply structure and evidence, not legal advice.
What does NIS2 in Denmark actually require of us?
Find out whether you're in scope, and at which tier — before anything else gets registered or reported. Register with the competent national authority inside the statutory deadline. Put all ten statutory minimum measures in place — from risk analysis to multi-factor authentication — each backed by dated evidence, not a checkbox. Report incidents through the correct channel, at every stage the law requires: early warning, formal report, and follow-up.
How completely does Compliverse cover NIS2 in Denmark?
Our catalogue holds 12 requirements for this framework. Each carries a legal source and each has at least one measure behind it — checked by an automated test on every change, not by good intentions. That is what "audit-ready" means for us: we do not guarantee that you end up compliant, because nobody can do that honestly. We guarantee that it is provable.
Which authority is responsible in Denmark — and where do we report an incident?
Registration and supervision: A sector-specific competent authority, designated under Executive Order (Bekendtgørelse) No. 620 of 2 June 2025 — Denmark splits NIS2 oversight by sector rather than assigning it to one central agency. Registering: Register via virk.dk — within 3 months (Section 9) for domain-name registries, cloud and platform providers, or within 2 weeks (Section 10) for all other in-scope entities. Reporting an incident: to the authority responsible for your sector under BEK nr 620 af 02/06/2025, under Section 13(1) of the NIS 2-loven. The incident assistant takes you there with the clock running.
Our promise
We don't say “compliant”. We say audit-ready — and we can prove it.
Nobody can guarantee that a company did everything right in an audit — not even a provider who promises it more confidently. What can be guaranteed is this. Four points, each independently verifiable.
01
Complete against the statute text
Every provision we cover has at least one requirement, every requirement at least one measure — and every one carries its source citation. That's not a promise: an automated test checks the catalogue on every change. If it finds a gap, the module doesn't ship.
→ Verifiable in each framework's requirement catalogue
02
Current, with a date
We re-read the legal texts in the original wording every month and update the product, training and website to match. Every check lands publicly in the change log — even when nothing changed.
→ Public change log on the Legal Landscape page
03
Evidenced, not asserted
Every requirement we mark as met has a document, certificate or log behind it — with a source citation and a legal-status date. What you can't hand an auditor doesn't count as done with us.
→ Evidence package as PDF, exportable at any time
04
Honest about the boundary
We provide structure, documents and evidence — not legal advice for your specific case. Where a question belongs with a lawyer, we say so instead of selling you something.
→ No legal advice — printed on every document
Last checked on 01/09/2026. That's how you get evidence that survives scrutiny — instead of a binder that falls apart at the first follow-up question.
What becomes important next
Legal Landscape
Deadline radar and change log — every update with a checked date.
To Legal Landscape →More modules
Legal status checked on 01/09/2026 · Every statement with a source · No legal advice