NIS2 in Denmark — a coordinating authority, a CSIRT under Defence Intelligence, and a passed registration deadline.
Denmark transposed through lov nr. 434/2025 (L 141), in force since 1 July 2025, with registration via the virk.dk portal due by 1 October 2025 — a deadline now behind us. Around 6,000 entities are in scope. The structure is the distinctive part: SAMSIK, the cybersecurity centre inside the Agency for Digital Government, serves as coordinating authority, while the Centre for Cyber Security (CFCS) — seated under Defence Intelligence — operates as the national CSIRT.
Denmark also legislated in pieces: separate acts carry the energy, finance and telecom sectors, so an entity's obligations can come from more than one statute. Teams that mapped “the NIS2 law” once have had to check whether their sector act added or moved something.
Who it applies to
Essential and important entities across the NIS2 sectors — around 6,000 by official estimates — registered through virk.dk by 1 October 2025, with entities crossing thresholds later registering without delay. SAMSIK coordinates; CFCS runs the national CSIRT function; sectoral regulators supervise their own. Energy, finance and telecom entities answer to sector acts alongside the framework law, and incident reporting runs the directive's three stages.
The clock
Competent authority: SAMSIK (coordinating authority) · CFCS as national CSIRT · sectoral regulators. Transposition: Lov nr. 434/2025 (L 141).
| When | What happens |
|---|---|
| 1 Jul 2025 | Lov nr. 434/2025 enters into force |
| 1 Oct 2025 | Registration deadline via virk.dk · now passed |
| Ongoing | Incident reporting to CFCS · 24 h, 72 h, one month |
| Sector acts | Separate energy, finance and telecom statutes carry sector-specific duties |
A CSIRT under Defence Intelligence
Denmark places its national CSIRT — the Centre for Cyber Security — under Defence Intelligence, combining civilian incident-handling at national scale with an intelligence-adjacent institutional home, while SAMSIK coordinates supervision from the digital-government side and sectoral regulators supervise their own sectors. It is the arrangement most unlike the standalone-civilian-agency pattern elsewhere in the Union, and it shapes the working relationship: the CSIRT that receives an incident report sits inside the defence establishment, with sectoral supervision running in parallel. TruSecure records the routing — CFCS for incidents, SAMSIK for coordination, the sector regulator for supervision — as facts on the entity, so an incident at 2 a.m. routes on the first attempt.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Denmark transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register via virk.dk (deadline 1 October 2025 — late filers act now) | Entity profile · registration status tracked, facts filed without further delay |
| Meet security-measures duties under the framework and sector acts | Control library · framework plus sector-act requirements in one set |
| Report incidents to CFCS: 24 h, 72 h, one month | Incident workflow · clocked from awareness, routed to CFCS |
| Show management-body oversight and training | Governance workspace · approvals and training records, dated |
| Answer SAMSIK and sectoral supervision with evidence | Supervision export · per control, sealed |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Registration
- virk.dk · filed 18 Sep 2025
- Supervision
- SAMSIK coordination · sectoral regulator confirmed
- Controls evidenced
- 85/103 · 18 open, each with an owner and a date
- Incident drills
- 2 this year · 24 h / 72 h clocks met
- Export
- sealed · sha256:7f1a...3d8b
Where teams usually start
With a demo walked through by TruSecure — your registration status confirmed, the framework and sector-act requirements mapped onto one control set, and a sample incident routed to CFCS against the clocks. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Denmark by SAMSIK (coordinating authority) · CFCS as national CSIRT · sectoral regulators. TruSecure determines applicability against Denmark's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.