Skip to main content

Compliance

What is the NIS2 Directive?

The NIS2 Directive sets IT security requirements across 18 sectors. See whether your business is covered, what the requirements mean, and how to get started.

In short

NIS2 is an EU directive that imposes binding cybersecurity and risk management requirements on businesses and organisations in 18 critical sectors, including energy, transport, health, food, digital infrastructure and manufacturing.

The directive significantly expands the original NIS Directive, so far more Danish businesses are now covered, including many medium-sized manufacturing and utility companies as well as their suppliers. If you are covered, you must among other things carry out systematic risk management, address supply chain security, report significant incidents to the authorities within short deadlines and anchor responsibility for cybersecurity with management, who can be held personally liable.

Non-compliance can trigger substantial fines and orders from the supervisory authorities. NIS2 is therefore not a pure IT task but a management responsibility that requires documented processes and continuous follow-up. MI Support IT helps Danish businesses clarify whether they are covered by NIS2 and implement the technical and organisational measures the directive requires.

Back to the glossary

What is the NIS2 Directive?

NIS2 is the EU's directive on network and information security, the successor to the original NIS Directive from 2016. Where NIS1 only affected a narrow circle of operators, the NIS2 Directive extends the requirements to 18 sectors and to far more company sizes. The NIS2 legislation makes cybersecurity a management responsibility: management must approve the risk management, oversee it, and can be held liable if it fails.

Who is covered by NIS2?

The directive distinguishes between essential and important entities across sectors such as energy, transport, health, drinking water, wastewater, digital infrastructure, public administration, food, waste management and manufacturing of critical products. As a general rule, you are covered if you operate in one of the sectors and have at least 50 employees or an annual turnover above EUR 10 million, but there are exceptions in both directions.

Pay attention to the supply chain: even if you are not directly covered yourself, your customers may be, and they are required to impose security requirements on their suppliers. NIS2 therefore reaches wider than the organisations on the list.

What are the requirements of the NIS2 legislation?

The core is ten minimum risk management measures, including:

  • Risk analysis and security policies for information systems
  • Incident handling with reporting of significant incidents to the authorities (initial notification within 24 hours)
  • Business continuity: backup, disaster recovery and crisis management
  • Supply chain security across the entire supply chain
  • Encryption, MFA and secured communications
  • Awareness training for management and employees

The requirements resemble the structure of ISO 27001: if you already have an information security management system, you are well on your way. See also IT compliance for the full overview of rules and standards.

When does NIS2 take effect in Denmark?

NIS2 has been implemented in Danish law through the act on measures to ensure a high level of cybersecurity, with accompanying executive orders that set out the sector-specific details. As deadlines and executive orders are continuously clarified, you should always check the current dates with the Danish Agency for Societal Security, which oversees compliance, and find the legislative text itself on Retsinformation. What matters is not the date, but the fact that risk management and documentation work takes months. Do not wait for the final deadline.

NIS2 registration: how to do it

Covered businesses must register themselves with the relevant authority. Registration takes place via the Danish Agency for Societal Security's digital solution. Here is how to approach it:

  1. Clarify coverage: match your activities against the sector annexes and the size thresholds.
  2. Appoint responsible persons: a management representative and an operational contact person.
  3. Register the entity with master data, sector and contact details before the deadline.
  4. Start the gap analysis: registration is only the starting signal; the requirements must be met on an ongoing basis.

How MI Support IT can help

We help you all the way: clarifying whether you are covered, a gap analysis against the ten minimum requirements, implementation of technical controls and preparation of an IT contingency plan that holds up in practice, as part of a comprehensive IT security effort. Contact us for a no-obligation conversation about where you stand in relation to NIS2.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.