September 1, 2026

What is NIS2? And what do the requirements mean for your business in 2026?

NIS 2 imposes significantly higher requirements for cybersecurity, risk management, and management responsibility in Danish companies and organizations. For affected companies, NIS 2 is not just about technical security solutions, but also about…
NIS 2 Requirements and Cybersecurity for Danish Companies

NIS 2 imposes significantly higher requirements for cybersecurity, risk management, and management responsibility in Danish companies and organizations. For affected companies, NIS 2 is not only about technical security solutions, but also about employees, suppliers, emergency preparedness, documentation, and active management involvement.

The Danish NIS 2 Act took effect on July 1, 2025. This means that covered companies must already be able to address the requirements in a structured manner and document their cybersecurity efforts.

What is NIS 2?

NIS 2 is the EU’s common framework for enhancing cybersecurity at companies and public organizations that provide services critical to society and the economy.

In Denmark, the requirements have been implemented through the NIS 2 Act and associated sector-specific regulations. The purpose is to make organizations more resilient to, among other things, cyberattacks, operational disruptions, compromised suppliers, and other incidents that could affect critical services.

The key point is that NIS 2 shifts cybersecurity away from being an isolated IT issue.

Cybersecurity is increasingly becoming a matter of business risk, management responsibility, and organizational resilience.

For businesses, this means, among other things, that safety efforts must be risk-based, documented, and supported by management.

Who is covered by NIS 2?

NIS 2 covers companies and organizations in a wide range of sectors that are considered critical or particularly critical to society.

This applies, among other things, to areas such as energy, transportation, health care, drinking water, wastewater, digital infrastructure, IT services, public administration, digital services, waste management, food, chemicals, certain manufacturing companies, and research.

However, the sector alone does not necessarily determine whether a company is covered.

The size of the business, its specific activities, services, and significance may also be of crucial importance. There are also exceptions under which a business may be subject to the regulations regardless of its size.

Size can be a deciding factor

In the digital sector, criteria such as the number of employees, revenue, and balance sheet are used, among other things, to assess whether a company is a major or significant entity.

Generally speaking, a company may be classified as a significant entity if it has between 50 and 249 employees or meets certain financial thresholds. Larger companies may be categorized as material entities. Group relationships may also affect the calculation.

Therefore, companies should not conclude that they are exempt from NIS 2 based solely on the number of employees.

Short answer: If your company operates in a sector covered by NIS 2, you should conduct a specific assessment of the company’s activities, size, corporate structure, and any exemptions.

What are the most important NIS 2 requirements?

For companies subject to NIS 2, the requirements can generally be grouped into four key obligations:

  1. Registration as a Covered Entity
  2. Active Responsibility on the Part of Company Management
  3. Reporting of Significant Safety Incidents
  4. Implementation of appropriate technical, operational, and organizational cybersecurity measures

That last point is important.

NIS 2 compliance is not achieved by purchasing a single security product or drafting a single policy. The company must be able to demonstrate a coherent and risk-based approach to cybersecurity.

NIS 2 Requires More Than Just Technical IT Security

One of the key principles of NIS 2 is that organizations must implement technical, operational, and organizational security measures.

The key areas include, among others:

  • Policies for Risk Analysis and Information Security
  • Security Incident Management
  • business continuity, backup, disaster recovery, and crisis management
  • supply chain security
  • the secure development, procurement, and maintenance of IT systems
  • vulnerability management
  • assessment of the effectiveness of security measures
  • Basic cyber hygiene and cybersecurity training
  • cryptography and encryption
  • access control, employee safety, and asset management
  • multi-factor authentication and secure communication solutions, where appropriate

At the same time, this shows why NIS 2 cannot be the sole responsibility of the IT department.

Technology is one aspect of security. Processes, management, and people are at least as important.

Awareness training is part of the NIS 2 initiative

Human error, phishing, social engineering, and compromised login credentials can bypass even robust technical security solutions.

For this reason, NIS 2 explicitly mentions basic cyber hygiene and cybersecurity training as part of the security measures that covered organizations must implement. The directive also emphasizes the training of management bodies and calls for regular training of employees.

That does not mean that awareness training alone ensures NIS 2 compliance.

However, a documented and ongoing awareness initiative can be an important part of the company’s overall security program.

It should help employees to:

  • Identify phishing and social engineering
  • handle suspicious emails, links, and login attempts correctly
  • understand the company's security policies
  • respond to potential security incidents
  • protect credentials and sensitive data

The most effective approach, therefore, is not a single annual course, but ongoing training combined with realistic exercises and the assessment of employees' safety behavior.

Do you want to strengthen the human element of your NIS 2 efforts?
Check out SecureFirst’s awareness training

NIS 2 Makes Phishing a Management Issue

Imagine that an employee receives a credible email that appears to be from a vendor.

The employee clicks a link and enters their login credentials on a fake Microsoft 365 page. Shortly thereafter, the attacker gains access to the email account and uses it as a stepping stone for further compromise.

Technically speaking, the incident begins with a single login.

The consequences for the business could be far greater.

This can lead to data breaches, fraud, downtime, compromised customers or suppliers, and, in serious cases, an incident that the company must handle in accordance with NIS 2 regulations.

Therefore, phishing training should not be viewed as an isolated HR activity. It should be integrated with the company’s risk management, incident response, and overall cybersecurity program.

Do you know how your employees would react to a realistic phishing attack?
Test security behavior with SecureFirst’s phishing training

Management has a direct responsibility under NIS 2

One of the biggest changes under NIS 2 is the clear assignment of cybersecurity responsibilities to management.

The relevant management body must take an active role in the company’s management of cybersecurity risks. This means, among other things, that security measures cannot simply be implemented by the IT department without management involvement.

Management must have sufficient insight to be able to assess the company's risks and security level.

That changes the question from:

“Does IT have security under control?”

to:

“Can management demonstrate that the company has identified its material cyber risks and implemented appropriate measures?”

It's a much more business-oriented approach.

The board of directors and executive management should therefore have ongoing insight into, for example, the risk profile, critical systems, supplier risks, security incidents, training levels, and the effectiveness of the company’s security measures.

Supplier security is also part of NIS 2

A company can have strong internal security and still be compromised through a vendor.

That is why supply chain security is a key element of NIS 2.

Companies must address security risks in their relationships with direct suppliers and service providers. This may involve, among other things, assessing the suppliers’ security levels as well as relevant requirements in contracts and supplier management.

This is particularly relevant for companies that rely on cloud platforms, IT operations, software providers, hosting, managed services, or other external solutions.

NIS 2 compliance, therefore, does not stop at the company's own firewall.

The company must be aware of the dependencies on which its critical services rely.

How quickly must a NIS 2 incident be reported?

If a covered entity is affected by a significant incident, strict deadlines apply.

As a general rule, the process involves:

  • early warning within 24 hours
  • Incident reporting within 72 hours
  • any preliminary report
  • final report, as a rule, no later than one month after notification of the incident

This places significant demands on the company's incident response.

If the organization has to first figure out who is responsible, who to contact, and what data is needed after a cyberattack has begun, valuable time may be lost.

Effective NIS 2 response therefore requires that procedures, roles, and escalation pathways be established before an incident occurs.

Documentation Will Be Crucial for NIS 2 Compliance

There is a difference between having security measures in place and being able to demonstrate that the company takes a systematic approach to cybersecurity.

The latter is becoming increasingly important.

Companies should therefore be able to document, for example:

  • identified risks
  • security policies and procedures
  • Responsibilities and Roles
  • security measures implemented
  • Awareness and leadership training
  • Tests and Exercises
  • Incidents and Follow-Up
  • Supplier Evaluations
  • ongoing improvements

Not only does this create a stronger foundation for compliance.

It also gives management a better picture of where the company is actually vulnerable.

CIS18 can make NIS 2 more operational

One challenge with legislation is that the requirements tell companies what they must achieve, but not necessarily exactly how their day-to-day safety efforts should be organized.

This is where a recognized control framework such as CIS Controls can be useful.

CIS18 brings together specific security controls in areas such as asset management, access control, vulnerabilities, backups, logging, awareness, and incident response.

It can therefore be used as a practical tool for structuring aspects of the company's cybersecurity efforts.

CIS18 is not the same as NIS 2 compliance, but the framework can serve as a strong foundation when translating legal requirements into operational security measures.

See how SecureFirst works with CIS18 compliance

How Your Company Can Get Started with NIS 2

For many companies, the biggest mistake is to start by purchasing multiple security products.

Instead, start by getting an overview.

A practical process might be:

1. Determine whether the company is covered

Assess the sector, activities, company size, group structure, and any special regulations.

2. Identify critical services and systems

What IT systems, data, employees, and suppliers are necessary to maintain the company's most critical services?

3. Conduct a risk assessment

Identify the scenarios that could affect availability, integrity, confidentiality, and continuity.

4. Identify existing security measures

Compare the company’s current controls with the NIS 2 requirements and identify any gaps.

5. Assign responsibility to management

Clearly define ownership, reporting, and decision-making authority.

6. Promote Safe Behavior Among Employees

Conduct ongoing awareness training and phishing simulations so that human risks are measured and managed systematically.

7. Establish incident response and reporting procedures

The company must be able to quickly detect, escalate, analyze, and report relevant incidents.

8. Document and continuously improve

NIS 2 should be treated as an ongoing process rather than a project that is completed after a single compliance review.

What is the difference between NIS 2 and general IT security?

General IT security often focuses on technical solutions. NIS 2 sets broader requirements for an organization’s overall management of cybersecurity risks.

This includes technology, processes, people, suppliers, management responsibilities, emergency preparedness, and documentation.

It is precisely this connection that is crucial.

A company can have antivirus software, a firewall, and MFA and still have serious security vulnerabilities if employees aren’t trained, critical vendors aren’t evaluated, backups are never tested, or management lacks an overview of the risks.

Frequently Asked Questions About NIS 2

What does NIS 2 mean?

NIS 2 is the EU’s framework for achieving a higher common level of cybersecurity. In Denmark, the rules have been implemented through Danish legislation and sector-specific regulations.

When did NIS 2 take effect in Denmark?

The general Danish NIS 2 Act took effect on July 1, 2025.

Who is covered by NIS 2?

NIS 2 applies to businesses and public organizations in a number of critical and particularly critical sectors. Whether a specific business is covered depends, among other things, on its activities, sector, size, and specific exemptions.

Are small businesses covered by NIS 2?

As a general rule, the size of a business plays a significant role, but there are exceptions. A smaller business may therefore, in certain cases, be covered due to the services it provides or its importance to society.

Is awareness training a NIS 2 requirement?

NIS 2 emphasizes basic cyber hygiene and cybersecurity training as part of the relevant cybersecurity measures. The training should be part of a broader, risk-based security effort.

Is management responsible for NIS 2?

Yes. NIS 2 places a clear responsibility on management for managing cybersecurity risks and for the company’s security measures. This makes cybersecurity a management and business issue, rather than merely a technical IT task.

Should suppliers also be assessed under NIS 2?

Supplier and supply chain security is a key area of NIS 2. Companies must therefore address cybersecurity risks associated with relevant direct suppliers and service providers.

How quickly must a cyber incident be reported?

In the event of a significant incident, the general rule is to issue an early warning within 24 hours and a more comprehensive incident report within 72 hours. Further reporting follows thereafter.

NIS 2 Must Be Translated from Requirements into Actual Cybersecurity

NIS 2 should not be viewed as just another compliance exercise.

The companies that derive the greatest value from this work use the requirements as an opportunity to gain a better overview of their critical systems, cyber risks, employees, suppliers, and contingency planning.

It requires both technology and governance.

But it also requires that people know how to respond when an attack occurs.

At SecureFirst, we work to make cybersecurity and NIS 2 concrete and operational, so that companies can move from requirements on paper to security practices, processes, and controls that work in practice.

Do you need help organizing your NIS 2 efforts?
Check out SecureFirst’s solution for NIS 2 compliance

Dion Grydell

Introductory Meeting – SecureFirst

Questions?

Should you have any questions, please do not hesitate to contact us by phone or email.

What is ransomware, and why do companies choose to pay millions to cybercriminals?

What is ransomware, and why do companies choose to pay millions to cybercriminals?

Ransomware has become one of the most serious cyber threats facing modern businesses. These attacks are no longer just about locking files; they increasingly involve extortion, data theft, and threats to a company’s operations and reputation. When the consequences become severe enough, even well-protected organizations may find themselves in a situation where paying a ransom becomes a real consideration.

But why does this happen, and what can companies do to reduce the risk?

How phishing training works

How phishing training works

Phishing remains one of the most common ways for cybercriminals to gain access to businesses. Even though spam filters, firewalls, and security systems are getting better, fake...