What is the NIS2 Directive?
NIS2 is the EU's directive on network and information security, the successor to the original NIS Directive from 2016. Where NIS1 only affected a narrow circle of operators, the NIS2 Directive extends the requirements to 18 sectors and to far more company sizes. The NIS2 legislation makes cybersecurity a management responsibility: management must approve the risk management, oversee it, and can be held liable if it fails.
Who is covered by NIS2?
The directive distinguishes between essential and important entities across sectors such as energy, transport, health, drinking water, wastewater, digital infrastructure, public administration, food, waste management and manufacturing of critical products. As a general rule, you are covered if you operate in one of the sectors and have at least 50 employees or an annual turnover above EUR 10 million, but there are exceptions in both directions.
Pay attention to the supply chain: even if you are not directly covered yourself, your customers may be, and they are required to impose security requirements on their suppliers. NIS2 therefore reaches wider than the organisations on the list.
What are the requirements of the NIS2 legislation?
The core is ten minimum risk management measures, including:
- Risk analysis and security policies for information systems
- Incident handling with reporting of significant incidents to the authorities (initial notification within 24 hours)
- Business continuity: backup, disaster recovery and crisis management
- Supply chain security across the entire supply chain
- Encryption, MFA and secured communications
- Awareness training for management and employees
The requirements resemble the structure of ISO 27001: if you already have an information security management system, you are well on your way. See also IT compliance for the full overview of rules and standards.
When does NIS2 take effect in Denmark?
NIS2 has been implemented in Danish law through the act on measures to ensure a high level of cybersecurity, with accompanying executive orders that set out the sector-specific details. As deadlines and executive orders are continuously clarified, you should always check the current dates with the Danish Agency for Societal Security, which oversees compliance, and find the legislative text itself on Retsinformation. What matters is not the date, but the fact that risk management and documentation work takes months. Do not wait for the final deadline.
NIS2 registration: how to do it
Covered businesses must register themselves with the relevant authority. Registration takes place via the Danish Agency for Societal Security's digital solution. Here is how to approach it:
- Clarify coverage: match your activities against the sector annexes and the size thresholds.
- Appoint responsible persons: a management representative and an operational contact person.
- Register the entity with master data, sector and contact details before the deadline.
- Start the gap analysis: registration is only the starting signal; the requirements must be met on an ongoing basis.
How MI Support IT can help
We help you all the way: clarifying whether you are covered, a gap analysis against the ten minimum requirements, implementation of technical controls and preparation of an IT contingency plan that holds up in practice, as part of a comprehensive IT security effort. Contact us for a no-obligation conversation about where you stand in relation to NIS2.