Cybersecurity Β· Denmark
Cybersecurity law in Denmark: NIS2 compliance (2026)
Denmark shaded by its cybersecurity status
Cybersecurity in Denmark: comprehensive law.
FrameworkDanish NIS2 Act (Act No. 434 of 6 May 2025 on Measures for a High Level of Cybersecurity β 'Cybersikkerhedsloven'), transposing EU Directive 2022/2555; supplemented by sector-specific acts (telco Act No. 435/2025, plus energy and finance rules) and the CER Act (Act on the Resilience of Critical Entities); DORA (Reg. (EU) 2022/2554) applies directly to financial entities. Baseline oversight sits with the Danish Resilience Agency (SAMSIK) under the Ministry of Resilience and Preparedness (est. 29 Aug 2024); the Centre for Cyber Security (CFCS, under the Danish Defence Intelligence Service) remains national CSIRT.
Denmark has a comprehensive, in-force cybersecurity regime: the NIS2 Act (Act No. 434/2025) and CER Act both entered into force on 1 July 2025, alongside sector-specific implementations for telecoms, energy and finance. Supervision is deliberately decentralised β each sector's regulator acts as competent authority, coordinated by SAMSIK (Danish Resilience Agency) under the new Ministry of Resilience and Preparedness, while CFCS operates the national CSIRT. In finance, DORA has applied directly since 17 January 2025 with Finanstilsynet as competent authority.
NIS2 & cybersecurity law in Denmark
In Denmark, baseline cybersecurity obligations come from the EU NIS2 Directive, transposed into national law, which sets risk-management and incident-reporting duties for essential and important entities.
- Framework
- the NIS2 Directive (EU) 2022/2555, transposed into national law
- Approach
- cybersecurity risk-management measures plus mandatory incident reporting for in-scope entities
- Applies to
- medium and large entities in critical sectors: energy, transport, banking, health, water, digital infrastructure, ICT and public administration
- Incident reporting
- an early warning within 24 hours and a full notification within 72 hours to the national CSIRT
- Maximum fine
- up to β¬10 million or 2% of global annual turnover for essential entities
- Oversight
- the national competent authority and CSIRT designated under NIS2
NIS2 is a directive, so Denmark implements it through national law; exact scope and deadlines can vary slightly by transposition.
NIS2 in Denmark: FAQ
Yes. As an EU member, Denmark has transposed the NIS2 Directive (EU) 2022/2555 into national law, covering essential and important entities in critical sectors.
Medium and large organisations in sectors such as energy, transport, banking, health, water, digital infrastructure and public administration.
An early warning within 24 hours of becoming aware and a fuller incident notification within 72 hours to the national CSIRT.
Up to β¬10 million or 2% of global annual turnover for essential entities, with lower ceilings for important entities.
Key points
The Act on Measures for a High Level of Cybersecurity (Lov nr. 434 af 6. maj 2025) entered into force on 1 July 2025, imposing risk-management, governance and reporting duties on 'essential' and 'important' entities across sectors listed in Annexes I and II of NIS2.
Denmark opted for a decentralised model: telecoms are covered by Act No. 435 of 6 May 2025 (Security and Preparedness in the Telco Sector), energy and finance by dedicated sector laws, and each ministry's regulator (e.g., Finanstilsynet, Energistyrelsen) acts as competent authority rather than a single national cyber regulator.
Entities must submit an early warning within 24 hours of becoming aware of a significant incident, a fuller incident notification within 72 hours (deadlines run concurrently), and a final report within one month (or one month after the incident is handled). Reports go via the competent sector authority; CFCS receives them in its CSIRT role.
Entities in scope of the Danish NIS2 Act were required to register by 1 October 2025; missing the deadline is itself a compliance breach. CFCS/SAMSIK have signalled audits of essential entities from early 2026, and Danish penalties are notably criminal rather than administrative in structure.
The EU Digital Operational Resilience Act (Reg. (EU) 2022/2554) has applied directly since 17 January 2025 to banks, insurers, payment/e-money institutions, investment firms and CASPs. Finanstilsynet (Danish FSA) is the sole competent authority, formally designated via an amendment to the Financial Business Act adopted 2 May 2024, and began preparing its first DORA inspections in 2025.
Denmark's Act on the Resilience of Critical Entities (transposing EU Directive 2022/2557) also entered into force on 1 July 2025, covering 11 sectors including energy, transport, banking, health, water, digital infrastructure, public administration, space and food. Sector authorities must designate critical entities by July 2026; those entities then have 9 months for a risk assessment and 10 months to implement a resilience plan.
Timeline - major decisions & events
Denmark's general cross-sector NIS2 statute (LOV nr. 434, 'Lov om foranstaltninger til sikring af et hΓΈjt cybersikkerhedsniveau') takes effect, imposing risk-management, governance and incident-reporting duties on essential/important entities; covered entities had to self-register by 1 October 2025.
Retsinformation (Danish official legislation portal) βDenmark missed the 17 October 2024 EU deadline to transpose NIS2, prompting Commission infringement action; the delay is why Danish cyber obligations only became binding from mid-2025.
European Commission (Shaping Europe's digital future) βA dedicated act on security and preparedness in the telecommunications and digital-infrastructure sector (LOV nr. 435) is enacted alongside the main law, reflecting Denmark's multi-statute, sector-responsibility implementation model rather than a single cyber code.
Retsinformation βLOV nr. 258 consolidates security and emergency-preparedness rules for electricity, gas, oil, heating and hydrogen operators, implementing both NIS2 and the Critical Entities Resilience directive and more than doubling the number of regulated energy companies to ~160.
Retsinformation βThe EU Digital Operational Resilience Act starts applying, setting ICT risk-management, incident-reporting and third-party (cloud) oversight rules for banks, insurers and other financial firms, supervised in Denmark by Finanstilsynet.
ESMA βThe Danish Data Protection Agency reported Netcompany to police and recommended a record ~DKK 15m fine after a coding flaw in the mit.dk digital-post authentication component briefly exposed citizens' confidential data, faulting inadequate security and a missing impact assessment.
Datatilsynet βSektorCERT's report details a May 2023 wave of attacks compromising ~22 energy companies via Zyxel firewall flaw CVE-2023-28771 (with possible GRU/Sandworm links), the largest such incident in Danish history and a key driver of tougher energy-sector rules.
SektorCERT βThe government's third national cyber strategy, funded with ~DKK 270m across 34 initiatives, continues Denmark's 'sector responsibility principle' approach where each ministry secures its own domain.
Danish Agency for Digital Government (Digitaliseringsstyrelsen) βAct no. 502 of 23 May 2018 (Databeskyttelsesloven) supplements the GDPR and applies from the same day, establishing Datatilsynet's supervisory role and the security/breach-notification regime underpinning data-related cyber obligations.
Datatilsynet βLOV nr. 713 regulates the Centre for Cyber Security (CFCS) within the Defence Intelligence Service as Denmark's national IT-security authority, network-security service and centre of excellence, the foundational institution of today's framework.
Retsinformation βDenmark - other topics
Cybersecurity in other countries
Last verified 8/31/2026 Β· Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite Β· State of Technology Regulation 2026 Β· Explore the full world map β