Skip to main content

Compliance

What is IT compliance?

IT compliance means being able to document that your IT meets legislation and standards. Get an overview of GDPR, NIS2 and ISO 27001 in one place.

In short

IT compliance means that the company's use of IT meets applicable legislation, standards and contractual requirements, and that you can document it to customers, authorities and auditors.

For Danish businesses it typically comes down to three sets of rules: GDPR for personal data, NIS2 for cybersecurity in critical sectors and ISO 27001 as the standard customers and partners most often request as proof that security is under control.

Compliance matters because failure to comply can cost fines, lost contracts and trust, and because the requirements are increasingly passed down through the supply chain, so smaller businesses face them too.

Three points: compliance is documentation of practice, not just policies on paper; the requirements from the different sets of rules overlap, so the work can be reused across them; and the responsibility sits with management, not the IT department alone. MI Support IT helps Danish businesses turn compliance requirements into concrete technical solutions and documentation.

Back to the glossary

What is IT compliance?

IT compliance is the ability to meet (and prove that you meet) the laws, standards and contractual requirements that apply to your use of IT. In other words, it is not enough to have security; you must be able to document it: policies, risk assessments, logging, data processing agreements and evidence that the controls are actually running. What is compliance in practice? An ongoing effort where requirements are translated into controls, controls into operations, and operations into documentation.

GDPR, NIS2 and ISO 27001: which apply to you?

The three sets of rules hit differently, but overlap in content:

  • GDPR applies to every business that processes personal data, which in reality means everyone. GDPR compliance covers legal bases for processing, data processing agreements, deletion and breach notification. Datatilsynet, the Danish Data Protection Agency, is the supervisory authority and publishes guidance on most of it.
  • NIS2 applies to businesses in 18 critical sectors and imposes legal requirements for risk management, incident reporting and management accountability for cybersecurity.
  • ISO 27001 is voluntary, but is requested in tenders and supplier agreements as documentation of systematic security work.

The good news: the requirements point in the same direction. Risk assessments, access management, backup, encryption and contingency planning can be documented once and reused across all three.

What is the difference between governance and compliance?

IT governance is the internal framework: who decides what about IT, how investments are prioritised, who owns risks, and how follow-up happens. Compliance is meeting the external requirements: laws, standards and contracts. The connection is simple: Without governance, compliance becomes a firefighting exercise every time a customer or authority asks. With governance in place, compliance is a by-product of the way you already work. The responsibility for both sits with management; the IT department executes, but cannot carry it alone.

How to document compliance

A practical approach in four steps:

  1. Map the requirements: which laws, standards and customer requirements apply to you, and which data and systems do they cover?
  2. Gap analysis: compare the requirements with your current controls and find the holes.
  3. Close the holes with controls that can be evidenced: MFA, logging, access management, tested backup and a contingency plan, in other words technology that leaves documentation behind by itself.
  4. Operations and follow-up: an annual cycle of internal controls, supplier reviews and updates to the risk assessment. Compliance is a process, not a project.

How MI Support IT can help

We translate compliance requirements into concrete IT: gap analyses, implementation of technical controls and documentation that stands up to auditors and customers. It happens through IT advisory and ongoing IT security. Contact us if you want an overview of which requirements actually apply to your business, and how far you are from meeting them.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.