Skip to main content
In forceNIS2

NIS2 in Denmark

Denmark transposed NIS2 via amendments to the national Netsikkerhedslov. CFCS coordinates cross-sector cybersecurity strategies.

Transposition law
Lov om Γ¦ndring af lov om netsikkerhed (Cybersecurity Act)
In force since
1 July 2025
Competent authority
Center for Cyber Security (CFCS)
Max fine (Essential)
DKK 75 million (~€10 million) or 2% of global annual turnover
Max fine (Important)
DKK 50 million (~€6.7 million) or 1.4% of global annual turnover
Law adopted
1 July 2025

Key Deadlines

Law in force
1 July 2025

Competent Authority

Center for Cyber Security (CFCS)
Lead cybersecurity coordinator and supervisory support agency
https://www.cfcs.dk β†—

CFCS acts as the core technical lead, working closely with industry-specific authorities (such as the Danish Energy Agency) that execute sector audits.

Registration Process

Register via the central Virk.dk corporate administration portal under specific NIS2 categories.

πŸ“Š Quick Test

Find out if your company is in scope

Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?

Check NIS2 Scope β†’

Key Requirements

  • 1Registration with the designated sector authority
  • 2Implementation of ISO 27001 standard frameworks
  • 324-hour incident warning to CFCS

National Additions

β˜…Denmark integrates strict requirements for maritime infrastructure and offshore digital networks

FAQ: NIS2 in Denmark

Who conducts the audits in Denmark?
Audits are decentralised; the Danish Business Authority or specific sector agencies conduct them with CFCS technical support.

Ready to assess your NIS2 compliance?

Use our free tools to check your NIS2 scope and run a gap assessment.

Currency and sources

The legal details on this page were last checked on 25 July 2026. Some details rest on a single secondary source and are not verified against the national authority or official journal. Confirm with the competent authority before relying on them for a compliance decision.