NIS2 in Denmark 2026 – 6,000 companies and active supervision
Denmark's NIS2 law has been in force since 1 July 2025, and supervision has begun. See how many companies are covered, what inspectors ask for, and which documentation you need to be able to produce.
Denmark's NIS2 law entered into force on 1 July 2025. The first year was about working out who was covered. 2026 is about something else: supervision.
The Centre for Cyber Security began active supervision during the first half of 2026. That moves the question from "are we in scope?" to "can we prove we meet the requirements?"
The number is 6,000 – not 1,000
One of the most persistent misconceptions about NIS2 in Denmark is the number of companies affected.
| Regime | Danish organisations covered |
|---|---|
| NIS1 (previous) | approx. 1,000 |
| NIS2 (current) | approx. 6,000 |
That is a sixfold increase. Many of the newly covered organisations have never been subject to cybersecurity regulation before — and are only now discovering that the requirements also reach the physical world: who can walk through which doors, and whether that can be evidenced.
A European survey from late 2025 found that only around 16% of respondents felt fully prepared. That is the situation supervision is walking into.
The problem: the requirements are met but cannot be shown
Most organisations we speak to are doing sensible things. There are locks on the doors, keys are not handed out to just anyone, and there is a tidy-up when someone leaves.
The problem starts when supervision asks for evidence. And evidence is not the same as practice:
❌ "We only grant access to those who need it"
Inspector: show me the list of who has access to the site, and when it was last reviewed.
❌ "We collect keys when people leave"
Inspector: show me that the keys from the last 12 departures were actually returned.
❌ "We'd notice a break-in"
Inspector: when did you detect your last incident, and how many hours passed before it was handled?
❌ "Contractors get access by arrangement"
Inspector: show me which external parties had access this year, and for which periods.
None of those four questions can be answered with a key cabinet and a spreadsheet.
The requirements that hit access control directly
NIS2 sets risk-management requirements across ten areas. Four of them are, in practice, about who can get in:
- Access control policies – documented rules for who gets access to what, and how access is granted and removed
- Asset management – an overview of assets, including the physical access points to them
- Human resources security – managing access across the whole employment lifecycle, especially at departure
- Supply chain security – managing the access of suppliers and contractors
On top of that comes incident handling, where access-related events – forced entries, repeated denied attempts, doors left standing open – are one of the categories that must be detectable and handled.
The reporting deadlines: 24 / 72 / 1 month
For a significant incident, three deadlines apply:
Incident detected ← the clock starts here, not when you begin investigating
│
├─ 24 hours ───► Early warning to the authority
│
├─ 72 hours ───► Notification with severity assessment
│ and indicators of compromise
│
└─ 1 month ────► Final report
In Denmark, incidents are reported to the Centre for Cyber Security (CFCS), which acts as the national CSIRT. Certain sectors have their own supervisory authorities — for example the Danish Energy Agency for the energy sector and the Danish FSA for financial services.
The detail that costs organisations most is that the clock starts when you become aware of the incident. Not when the investigation concludes. If three days pass before anyone sees the event in a log, the deadline is blown before the work has begun.
Management liability and fines
NIS2 places responsibility on management personally. Management must approve the measures, supervise them, and be able to document having done so.
For essential entities, penalties can reach EUR 10 million or 2% of global turnover — whichever is higher.
In practice, management liability means "that sits with IT" is no longer a valid answer. There has to be an approved, dated and documented decision.
What to have ready for an inspection
| Documentation | Typical question from supervision |
|---|---|
| Current access overview | Who has access to your critical sites today? |
| Access log for a chosen period | Who was on site in March, and for what reason? |
| Key inventory | How many keys are issued, and which have gone unused for 90 days? |
| Incident log with response times | How long from detection to handling? |
| Offboarding trail | Can you show that access was removed when employment ended? |
| Management approval | When did management last approve your measures? |
The point is not that it has to be beautiful. The point is that it has to exist, and that it has to be datable.
How SnapKey helps
Digital access control answers the NIS2 requirements because documentation becomes a by-product of daily operations instead of a project you start when supervision calls:
✅ Access is always named – every unlock ties to a person, not to a key that can be lent out
✅ Time limits by default – contractor access expires on its own
✅ Instant withdrawal – when someone leaves, access is gone the same minute
✅ Incidents recorded automatically – with a timestamp, so the 24-hour clock runs from a documented moment
✅ Signed reports – generated for a chosen period with a SHA-256 checksum, so the document can be verified
If you already run an iLOQ system, none of this requires new cylinders — see SnapKey for iLOQ.
FAQ
How many Danish companies are covered by NIS2?
Approximately 6,000 – a sixfold increase on the roughly 1,000 organisations covered by the previous NIS1 legislation.
When did supervision start in Denmark?
The NIS2 law entered into force on 1 July 2025, and the Centre for Cyber Security began active supervision during the first half of 2026.
When does the 24-hour deadline start?
When you become aware of the incident – not when the investigation is complete. This is why automatic incident recording matters: it establishes a documented moment of detection.
Is access control really in scope for NIS2?
Yes. Access control policies are explicitly named among the risk-management measures, and both human resources security and supply chain security concern who can physically get in.
What are the penalties?
For essential entities, up to EUR 10 million or 2% of global turnover – whichever is higher – plus personal management liability.
Contact us
Want to know how your access control measures up against NIS2? Contact SnapKey for a review.
Related articles
Compliance documentation that exists before the auditor asks
Most organisations only produce reports when the authority calls – and then discover the data is missing. See how scheduled reports, signed PDFs with SHA-256 and fixed cadences make documentation an automatic part of operations.
NIS2 Directive – Access Control and Cybersecurity Requirements 2025
The NIS2 law introduces enhanced requirements for cybersecurity and access control for businesses in critical infrastructure. Learn about the new requirements and how to achieve compliance.
Energy Legislation and Access Control – Requirements for Critical Infrastructure
Understand energy legislation requirements for physical security and access control. Learn how SnapKey helps energy companies achieve compliance.