Skip to content
World Watch/Denmark/Cybersecurity

Cybersecurity Β· Denmark

Cybersecurity law in Denmark: NIS2 compliance (2026)

Comprehensive lawCountry index 93 Β· A+

Denmark shaded by its cybersecurity status

Cybersecurity in Denmark: comprehensive law.

FrameworkDanish NIS2 Act (Act No. 434 of 6 May 2025 on Measures for a High Level of Cybersecurity β€” 'Cybersikkerhedsloven'), transposing EU Directive 2022/2555; supplemented by sector-specific acts (telco Act No. 435/2025, plus energy and finance rules) and the CER Act (Act on the Resilience of Critical Entities); DORA (Reg. (EU) 2022/2554) applies directly to financial entities. Baseline oversight sits with the Danish Resilience Agency (SAMSIK) under the Ministry of Resilience and Preparedness (est. 29 Aug 2024); the Centre for Cyber Security (CFCS, under the Danish Defence Intelligence Service) remains national CSIRT.

Denmark has a comprehensive, in-force cybersecurity regime: the NIS2 Act (Act No. 434/2025) and CER Act both entered into force on 1 July 2025, alongside sector-specific implementations for telecoms, energy and finance. Supervision is deliberately decentralised β€” each sector's regulator acts as competent authority, coordinated by SAMSIK (Danish Resilience Agency) under the new Ministry of Resilience and Preparedness, while CFCS operates the national CSIRT. In finance, DORA has applied directly since 17 January 2025 with Finanstilsynet as competent authority.

NIS2 & cybersecurity law in Denmark

In Denmark, baseline cybersecurity obligations come from the EU NIS2 Directive, transposed into national law, which sets risk-management and incident-reporting duties for essential and important entities.

Framework
the NIS2 Directive (EU) 2022/2555, transposed into national law
Approach
cybersecurity risk-management measures plus mandatory incident reporting for in-scope entities
Applies to
medium and large entities in critical sectors: energy, transport, banking, health, water, digital infrastructure, ICT and public administration
Incident reporting
an early warning within 24 hours and a full notification within 72 hours to the national CSIRT
Maximum fine
up to €10 million or 2% of global annual turnover for essential entities
Oversight
the national competent authority and CSIRT designated under NIS2

NIS2 is a directive, so Denmark implements it through national law; exact scope and deadlines can vary slightly by transposition.

NIS2 in Denmark: FAQ

Does NIS2 apply in Denmark?

Yes. As an EU member, Denmark has transposed the NIS2 Directive (EU) 2022/2555 into national law, covering essential and important entities in critical sectors.

Who must comply with NIS2 in Denmark?

Medium and large organisations in sectors such as energy, transport, banking, health, water, digital infrastructure and public administration.

What are the NIS2 incident-reporting deadlines in Denmark?

An early warning within 24 hours of becoming aware and a fuller incident notification within 72 hours to the national CSIRT.

What are the penalties under NIS2 in Denmark?

Up to €10 million or 2% of global annual turnover for essential entities, with lower ceilings for important entities.

Key points

Primary law (NIS2 transposition)

The Act on Measures for a High Level of Cybersecurity (Lov nr. 434 af 6. maj 2025) entered into force on 1 July 2025, imposing risk-management, governance and reporting duties on 'essential' and 'important' entities across sectors listed in Annexes I and II of NIS2.

Sector-specific approach

Denmark opted for a decentralised model: telecoms are covered by Act No. 435 of 6 May 2025 (Security and Preparedness in the Telco Sector), energy and finance by dedicated sector laws, and each ministry's regulator (e.g., Finanstilsynet, Energistyrelsen) acts as competent authority rather than a single national cyber regulator.

Incident reporting duties

Entities must submit an early warning within 24 hours of becoming aware of a significant incident, a fuller incident notification within 72 hours (deadlines run concurrently), and a final report within one month (or one month after the incident is handled). Reports go via the competent sector authority; CFCS receives them in its CSIRT role.

Registration and enforcement timeline

Entities in scope of the Danish NIS2 Act were required to register by 1 October 2025; missing the deadline is itself a compliance breach. CFCS/SAMSIK have signalled audits of essential entities from early 2026, and Danish penalties are notably criminal rather than administrative in structure.

Financial sector β€” DORA

The EU Digital Operational Resilience Act (Reg. (EU) 2022/2554) has applied directly since 17 January 2025 to banks, insurers, payment/e-money institutions, investment firms and CASPs. Finanstilsynet (Danish FSA) is the sole competent authority, formally designated via an amendment to the Financial Business Act adopted 2 May 2024, and began preparing its first DORA inspections in 2025.

Critical infrastructure β€” CER Act

Denmark's Act on the Resilience of Critical Entities (transposing EU Directive 2022/2557) also entered into force on 1 July 2025, covering 11 sectors including energy, transport, banking, health, water, digital infrastructure, public administration, space and food. Sector authorities must designate critical entities by July 2026; those entities then have 9 months for a risk assessment and 10 months to implement a resilience plan.

Timeline - major decisions & events

Jul 1, 2025lawofficial
NIS2 main cybersecurity act enters into force

Denmark's general cross-sector NIS2 statute (LOV nr. 434, 'Lov om foranstaltninger til sikring af et hΓΈjt cybersikkerhedsniveau') takes effect, imposing risk-management, governance and incident-reporting duties on essential/important entities; covered entities had to self-register by 1 October 2025.

Retsinformation (Danish official legislation portal) β†—
May 7, 2025enforcementofficial
European Commission opens infringement step over late NIS2 transposition

Denmark missed the 17 October 2024 EU deadline to transpose NIS2, prompting Commission infringement action; the delay is why Danish cyber obligations only became binding from mid-2025.

European Commission (Shaping Europe's digital future) β†—
May 6, 2025lawofficial
Sector-specific NIS2 act for telecoms adopted

A dedicated act on security and preparedness in the telecommunications and digital-infrastructure sector (LOV nr. 435) is enacted alongside the main law, reflecting Denmark's multi-statute, sector-responsibility implementation model rather than a single cyber code.

Retsinformation β†—
Mar 6, 2025lawofficial
Strengthened preparedness law for the energy sector (NIS2 + CER)

LOV nr. 258 consolidates security and emergency-preparedness rules for electricity, gas, oil, heating and hydrogen operators, implementing both NIS2 and the Critical Entities Resilience directive and more than doubling the number of regulated energy companies to ~160.

Retsinformation β†—
Jan 17, 2025lawofficial
DORA becomes applicable to Danish financial entities

The EU Digital Operational Resilience Act starts applying, setting ICT risk-management, incident-reporting and third-party (cloud) oversight rules for banks, insurers and other financial firms, supervised in Denmark by Finanstilsynet.

ESMA β†—
Jan 1, 2024enforcementofficial
Datatilsynet recommends record GDPR fine against Netcompany over mit.dk

The Danish Data Protection Agency reported Netcompany to police and recommended a record ~DKK 15m fine after a coding flaw in the mit.dk digital-post authentication component briefly exposed citizens' confidential data, faulting inadequate security and a missing impact assessment.

Datatilsynet β†—
Nov 12, 2023incident
Largest coordinated cyberattack on Danish critical infrastructure disclosed

SektorCERT's report details a May 2023 wave of attacks compromising ~22 energy companies via Zyxel firewall flaw CVE-2023-28771 (with possible GRU/Sandworm links), the largest such incident in Danish history and a key driver of tougher energy-sector rules.

SektorCERT β†—
Dec 1, 2021guidanceofficial
National Strategy for Cyber and Information Security 2022-2024 adopted

The government's third national cyber strategy, funded with ~DKK 270m across 34 initiatives, continues Denmark's 'sector responsibility principle' approach where each ministry secures its own domain.

Danish Agency for Digital Government (Digitaliseringsstyrelsen) β†—
May 25, 2018lawofficial
Danish Data Protection Act enters into force with GDPR

Act no. 502 of 23 May 2018 (Databeskyttelsesloven) supplements the GDPR and applies from the same day, establishing Datatilsynet's supervisory role and the security/breach-notification regime underpinning data-related cyber obligations.

Datatilsynet β†—
Jun 25, 2014lawofficial
Centre for Cyber Security Act establishes Denmark's national cyber authority

LOV nr. 713 regulates the Centre for Cyber Security (CFCS) within the Defence Intelligence Service as Denmark's national IT-security authority, network-security service and centre of excellence, the foundational institution of today's framework.

Retsinformation β†—

Denmark - other topics

Cybersecurity in other countries

Last verified 8/31/2026 Β· Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite Β· State of Technology Regulation 2026 Β· Explore the full world map β†’