World Watch/Norway/Cybersecurity

Cybersecurity · Norway

Cybersecurity regulation in Norway (2026)

Comprehensive lawLov om digital sikkerhet (digitalsikkerhetsloven, Act 2023-12-20-108) and its implementing regulation (digitalsikkerhetsforskriften), supervised by the National Security Authority (Nasjonal sikkerhetsmyndighet, NSM); complemented by the national Security Act (sikkerhetsloven) for national-security functions.Country index 70 · B

Norway shaded by its cybersecurity status

Norway has a comprehensive horizontal cybersecurity regime: the Digital Security Act (digitalsikkerhetsloven) and its regulation entered into force on 1 October 2025, transposing the EU NIS1 directive and imposing risk-management and incident-reporting duties on providers of essential services and digital service providers. NSM (which hosts the national CERT/NCSC) is the supervisory authority and national incident-response body. NIS2 and the CER directive have not yet been transposed; a new law expected during 2026 is set to replace the current Act and broadly expand scope.

Key points

Primary law in force

The Digital Security Act (Act of 20 Dec 2023 no. 108) and the Digital Security Regulation (Regulation of 20 Jun 2025 no. 1131) entered into force on 1 October 2025, transposing the EU NIS1 directive as an overarching framework law with detail in regulation.

Scope

Applies to operators of essential services and digital service providers across sectors including energy, transport, health, water supply, banking, financial market infrastructure and digital infrastructure; covered entities must register their services with NSM and the relevant sectoral authority.

Incident-reporting duties

Covered entities must notify significant incidents to NSM and the sectoral authority without undue delay — reporting within 24 hours, an update within 72 hours, and a full incident report to NSM within one month of the first notification.

Supervisor and national response body

The National Security Authority (NSM) is the supervisory authority and national incident-response environment; it hosts the Norwegian National Cyber Security Centre (NCSC), home to the national CERT (NorCERT).

Enforcement

NSM may impose administrative fines for non-compliance, up to 25 times the National Insurance base amount or 4% of the prior year's turnover, whichever is higher, capped at NOK 50 million.

NIS2 / CER still pending

As of May 2026 the EU NIS2 directive (2022/2555) and the CER directive have not yet been transposed into Norwegian law; a new act expected during 2026 is set to replace the current Digital Security Act and significantly broaden the regime's scope.

Timeline - major decisions & events

Jul 1, 2026law
NIS2 Implementation via Security Act Amendment — Registration Phase Opens

Norway's amendment to the Security Act to transpose the EU NIS2 Directive (2022/2555) enters its registration phase, bringing roughly 5,000 organisations into scope across expanded critical sectors; NSM will act as central CSIRT coordinator, with first audits scheduled from 1 October 2026.

DLA Piper Norway
Oct 1, 2025lawofficial
Digital Security Act (Digitalsikkerhetsloven) Enters into Force

Norway's Digital Security Act, implementing EU NIS1 Directive (2016/1148) into EEA law, took effect — the first cross-sector framework mandating risk assessments, technical/organisational security measures, and 24-hour initial incident notification to NSM, with penalties up to 4% of annual turnover.

NSM (Nasjonal sikkerhetsmyndighet)
Oct 1, 2024guidanceofficial
Meld. St. 9 (2024–2025): Total Preparedness White Paper

The government presented a comprehensive white paper on total societal preparedness to the Storting, elevating cybersecurity alongside conventional defence and civil-emergency planning and setting direction for integrated crisis resilience.

Norwegian Government (Regjeringen)
Jul 24, 2023incident
Ivanti Zero-Day (CVE-2023-35078) Exploited Against 12 Government Ministries

Hackers exploited a critical CVSS-10 authentication-bypass zero-day in Ivanti EPMM to breach mobile-device management systems at 12 ministries; NSM deliberately delayed public disclosure to limit wider exploitation, later alerting CISA and partner nations.

The Record (Recorded Future News)
Dec 1, 2022guidanceofficial
Meld. St. 9 (2022–2023): Cyber Resilience and National Control White Paper

The government submitted a landmark white paper to the Storting framing cyber resilience as a national-security imperative, addressing hybrid threats, critical-infrastructure protection, and the need for tighter foreign-ownership screening — directly shaping the subsequent Digital Security Act.

Norwegian Government (Regjeringen)
Mar 10, 2021incident
Storting Breached Again via Microsoft Exchange ProxyLogon Vulnerabilities

Attackers exploited the ProxyLogon zero-days (CVE-2021-26855 et al.) to exfiltrate data from Norwegian Parliament email accounts just six months after the 2020 breach; parliamentary leadership described it as more severe than the prior attack.

Nasdaq / AFP wire
Aug 24, 2020incident
APT28 (GRU) Breaches Norwegian Parliament Email Systems

Russia-linked APT28/Fancy Bear used brute-force credential attacks to access a limited number of Storting email accounts; Norway's Foreign Minister publicly attributed the intrusion to Russia in December 2020, marking a rare state-level public attribution.

BleepingComputer
Mar 19, 2019incident
LockerGoga Ransomware Attack on Norsk Hydro

LockerGoga ransomware crippled Norsk Hydro's global IT across 40 countries, causing ~USD 70 million in losses; Hydro's decision not to pay the ransom and to operate in full public transparency — in close coordination with NSM and Kripos — became an international benchmark for ransomware incident response.

Norsk Hydro (official company page)
Jan 30, 2019guidanceofficial
4th National Cyber Security Strategy Published

Norway released its fourth — and most comprehensive — national cyber security strategy, allocating ~NOK 1.6 billion to 46 measures across five priority areas, cementing NSM's cross-sector coordination role and recommending ten baseline security measures for all public and private entities.

Norwegian Government (Regjeringen)
Jan 1, 2019lawofficial
Revised Security Act (Sikkerhetsloven) Enters into Force

Norway's new Lov om nasjonal sikkerhet (passed by the Storting 1 June 2018) replaced the 1998 Act, creating binding obligations for all entities handling classified information or critical national functions: mandatory risk assessments, ICT security measures, and immediate incident notification to NSM.

Lovdata (official Norwegian legislation portal)
Jul 20, 2018lawofficial
Personal Data Act (Personopplysningsloven) Enters into Force — GDPR Implementation

Norway enacted a new Personal Data Act (passed 15 June 2018) incorporating the EU GDPR, requiring mandatory 72-hour breach notification to Datatilsynet and proportionate technical-security safeguards, extending cybersecurity obligations to all personal-data controllers and processors.

Lovdata (official Norwegian legislation portal)
Jan 1, 2012guidanceofficial
Third National Cyber Security Strategy Published

Norway issued its third revision of the national cyber security strategy, adapting the national framework to an increasingly sophisticated threat landscape; the document entrenched NSM's cross-sector mandate and remained the operative policy guide until the 2019 fourth strategy.

Norwegian Government (Regjeringen)
Jan 1, 2003lawofficial
NSM Established and First National Cyber Security Strategy Published

Norway established the National Security Authority (NSM) as the state's lead protective-security and cyber coordination body, and simultaneously published its first national cyber security strategy — making Norway one of the first countries in the world to adopt such a strategy — laying the institutional foundation for the entire current framework.

NSM (Nasjonal sikkerhetsmyndighet)

Norway - other topics

Last verified 5/23/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →