NIS2 is the EU's updated cybersecurity directive, and it is far more comprehensive than its predecessor. Since October 2024, the directive has been implemented in Danish law, and it sets clear requirements for how businesses must protect themselves against digital threats. The question is: does it apply to you?
Who is covered by NIS2?
NIS2 distinguishes between two categories: essential entities and important entities. The category depends primarily on your sector and the size of your business.
The directive covers 18 sectors: energy, transport, healthcare, finance, water distribution, digital infrastructure, and public administration. But many IT vendors, cloud providers, and managed service providers are now directly regulated as well.
As a starting point, NIS2 applies to businesses that:
- Have at least 50 employees, or
- Have an annual turnover or balance sheet exceeding €10 million
Smaller businesses may still be covered if they provide essential services, for example, a small supplier to a hospital or energy company. Here, the supplier's role in the supply chain determines whether NIS2 applies.
Important to know: Even if your business is not directly regulated by NIS2, your customers may require you to meet equivalent standards as part of their supply chain security. NIS2 therefore indirectly affects many SMBs in Denmark.
What does NIS2 specifically require?
NIS2 sets out a number of technical and organizational requirements that businesses must meet. The key elements are:
Risk management
You must have documented processes to identify and manage cybersecurity risks. This includes ongoing risk assessments, clear access control policies, encryption, and secure system configuration. Having a firewall alone is not sufficient. You must be able to demonstrate how you systematically manage risks.
Incident reporting
If a serious security breach occurs, you must notify the relevant authorities within 24 hours with an initial warning and provide a more detailed report within 72 hours. This requires that you already have processes in place to detect and classify incidents.
Supply chain security
You are responsible for assessing the security of your suppliers and sub-suppliers. Supply chain attacks, where attackers compromise a supplier to reach the customer, are one of the fastest-growing threat types. NIS2 requires that you actively address this risk.
First steps toward NIS2 compliance
Many businesses don't know where to start. Here is a practical checklist to begin:
- Clarify whether you are directly covered: review your sector and size based on the Danish implementing legislation.
- Map your critical systems and data: what would cost the most if it were down for 48 hours?
- Conduct a gap analysis: where are the gaps between your current security level and the requirements of NIS2?
- Assign responsibility: NIS2 explicitly places responsibility at management level. The board cannot wash its hands of it.
- Create an incident response plan: who does what when it happens? And who contacts the authorities?
NIS2 is more than a compliance requirement. It strengthens your business's resilience against threats that actually exist out there. The earlier you start, the better positioned you'll be when regulators begin oversight.