Skip to main content
NIS2 · DENMARK

NIS2 in Denmark — a coordinating authority, a CSIRT under Defence Intelligence, and a passed registration deadline.

Denmark transposed through lov nr. 434/2025 (L 141), in force since 1 July 2025, with registration via the virk.dk portal due by 1 October 2025 — a deadline now behind us. Around 6,000 entities are in scope. The structure is the distinctive part: SAMSIK, the cybersecurity centre inside the Agency for Digital Government, serves as coordinating authority, while the Centre for Cyber Security (CFCS) — seated under Defence Intelligence — operates as the national CSIRT.

Denmark also legislated in pieces: separate acts carry the energy, finance and telecom sectors, so an entity's obligations can come from more than one statute. Teams that mapped “the NIS2 law” once have had to check whether their sector act added or moved something.

Who it applies to

Essential and important entities across the NIS2 sectors — around 6,000 by official estimates — registered through virk.dk by 1 October 2025, with entities crossing thresholds later registering without delay. SAMSIK coordinates; CFCS runs the national CSIRT function; sectoral regulators supervise their own. Energy, finance and telecom entities answer to sector acts alongside the framework law, and incident reporting runs the directive's three stages.

The clock

Competent authority: SAMSIK (coordinating authority) · CFCS as national CSIRT · sectoral regulators. Transposition: Lov nr. 434/2025 (L 141).

NIS2 in Denmark · timeline
WhenWhat happens
1 Jul 2025Lov nr. 434/2025 enters into force
1 Oct 2025Registration deadline via virk.dk · now passed
OngoingIncident reporting to CFCS · 24 h, 72 h, one month
Sector actsSeparate energy, finance and telecom statutes carry sector-specific duties

A CSIRT under Defence Intelligence

Denmark places its national CSIRT — the Centre for Cyber Security — under Defence Intelligence, combining civilian incident-handling at national scale with an intelligence-adjacent institutional home, while SAMSIK coordinates supervision from the digital-government side and sectoral regulators supervise their own sectors. It is the arrangement most unlike the standalone-civilian-agency pattern elsewhere in the Union, and it shapes the working relationship: the CSIRT that receives an incident report sits inside the defence establishment, with sectoral supervision running in parallel. TruSecure records the routing — CFCS for incidents, SAMSIK for coordination, the sector regulator for supervision — as facts on the entity, so an incident at 2 a.m. routes on the first attempt.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Denmark transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Denmark requirements · how TruSecure answers them
What the law asksWhere it is answered
Register via virk.dk (deadline 1 October 2025 — late filers act now)Entity profile · registration status tracked, facts filed without further delay
Meet security-measures duties under the framework and sector actsControl library · framework plus sector-act requirements in one set
Report incidents to CFCS: 24 h, 72 h, one monthIncident workflow · clocked from awareness, routed to CFCS
Show management-body oversight and trainingGovernance workspace · approvals and training records, dated
Answer SAMSIK and sectoral supervision with evidenceSupervision export · per control, sealed

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Denmark NIS2 readiness file · excerptSample data
Registration
virk.dk · filed 18 Sep 2025
Supervision
SAMSIK coordination · sectoral regulator confirmed
Controls evidenced
85/103 · 18 open, each with an owner and a date
Incident drills
2 this year · 24 h / 72 h clocks met
Export
sealed · sha256:7f1a...3d8b

Where teams usually start

With a demo walked through by TruSecure — your registration status confirmed, the framework and sector-act requirements mapped onto one control set, and a sample incident routed to CFCS against the clocks. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Denmark by SAMSIK (coordinating authority) · CFCS as national CSIRT · sectoral regulators. TruSecure determines applicability against Denmark's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Is Denmark's NIS2 authority part of its intelligence service?
The Centre for Cyber Security (CFCS), Denmark's national CSIRT, sits under Defence Intelligence, while SAMSIK coordinates supervision from the digital-government side and sectoral regulators supervise their own sectors.