Home
Finance
Travel
Academic
Library
Create a Thread
Home
Discover
Spaces
 
 
  • Introduction
  • Key Changes from NIS1 to NIS2
  • Sector-Specific Requirements under NIS2
  • Penalties for Non-Compliance
  • CapaSystems NIS2 Webinar
NIS2 Implementation in Denmark

According to the Danish Ministry of Defense, the implementation of the EU cybersecurity directive NIS2 in Denmark has been delayed, with the new expected start date set for October 2024, pushing the compliance deadline to late 2024 or early 2025.

User avatar
Curated by
capasystems_denmark
3 min read
Published
cfcs.dk favicon
cfcs
Status på NIS2 - Center for Cybersikkerhed
linkedin.com favicon
linkedin
ComplyCloud on LinkedIn: Announcement on NIS2 law in Denmark
amcham.dk favicon
amcham
Implementation of NIS2 Directive is Delayed - AmCham Denmark
digital-strategy.ec.europa.eu favicon
digital-strategy.ec.europa
Implementation of the NIS Directive in Denmark
nis2directive.eu
nis2directive.eu
Key Changes from NIS1 to NIS2

NIS2 introduces significant changes compared to its predecessor, NIS1. The new directive expands the scope of covered sectors and entities, including more industries such as digital services, manufacturing of critical products, and public administration13. It also imposes stricter cybersecurity requirements, mandating a holistic, risk-based approach to cyber and information security4. NIS2 emphasizes the responsibility of management teams to approve and oversee security measures, and introduces more severe penalties for non-compliance, with fines potentially reaching up to 10 million euros or 2% of a company's global turnover4. Additionally, NIS2 extends requirements to subcontractors working for covered companies, effectively broadening its impact throughout supply chains4. The directive aims to standardize cybersecurity practices across EU member states, addressing the vague formulation of NIS1 that led to inconsistent implementation4.

changegroup.dk favicon
linkedin.com favicon
cfcs.dk favicon
5 sources
Sector-Specific Requirements under NIS2

NIS2 introduces a nuanced approach to sector-specific requirements, recognizing that certain industries may already have equivalent cybersecurity measures in place. According to Article 4 of the directive, if sector-specific Union legal acts require entities to adopt cybersecurity risk-management measures or incident reporting obligations that are at least equivalent to NIS2 requirements, those entities may be exempt from the relevant NIS2 provisions4. Currently, the Digital Operational Resilience Act (DORA) for the financial sector is the only recognized equivalent sector-specific legislation2. For sectors not covered by equivalent legislation, NIS2 provisions will continue to apply3. This approach aims to prevent fragmentation of cybersecurity provisions across the EU while ensuring a high level of cybersecurity across all critical sectors15.

nis2directive.eu favicon
easa.europa.eu favicon
nis-2-directive.com favicon
5 sources
Penalties for Non-Compliance

NIS2 introduces significant penalties for non-compliance, distinguishing between essential and important entities. For essential entities, the maximum fine is set at €10,000,000 or 2% of the global annual revenue, whichever is higher. Important entities face penalties of up to €7,000,000 or 1.4% of the global annual revenue, whichever is greater.12 Beyond financial penalties, NIS2 grants national authorities additional enforcement powers, including issuing compliance orders, mandating security audits, and temporarily banning individuals from holding management positions in cases of repeated violations.24 The directive also introduces personal liability for top management in cases of gross negligence, aiming to elevate cybersecurity as an organization-wide strategic priority.13

threatscape.com favicon
nis2directive.eu favicon
logpoint.com favicon
5 sources
CapaSystems NIS2 Webinar
capasystems.dk
capasystems.dk
capasystems.dk

CapaSystems, a Danish IT company, is offering a webinar to help organizations understand and prepare for the NIS2 directive. The webinar, scheduled for Wednesday, August 21st at 10:00 AM, aims to provide clarity on the complex world of NIS223. Participants will have the opportunity to learn about the directive, which is set to take effect at the turn of the year, and gain insights into its implications for businesses1. This educational initiative reflects the growing importance of cybersecurity awareness and compliance in light of the upcoming NIS2 implementation in Denmark.

capasystems.dk favicon
capasystems.dk favicon
dk.linkedin.com favicon
5 sources
Related
Hvornår starter webinaret om NIS2-direktivet
Hvordan kan jeg tilmelde mig webinaret på CapaSystems.dk
Er webinaret om NIS2-direktivet på engelsk
Er der en præsentation tilgængelig efter webinaret
Kan jeg stille spørgsmål live under webinaret
Discover more
Major AI labs must comply with New York's transparency standards
Major AI labs must comply with New York's transparency standards
New York state lawmakers have passed the Responsible AI Safety and Education (RAISE) Act, a landmark bill aimed at preventing frontier AI models from contributing to disaster scenarios that could cause significant harm or damage. As reported by TechCrunch, the legislation would establish America's first set of legally mandated transparency standards for AI labs developing powerful models,...
2,216
EU invests €145.5M to boost cybersecurity across Europe
EU invests €145.5M to boost cybersecurity across Europe
The European Commission is investing €145.5 million to strengthen cybersecurity across the EU, with €30 million specifically allocated to protect hospitals and healthcare providers from cyber threats, particularly ransomware attacks, as part of a broader initiative to enhance the resilience of European digital infrastructure in an increasingly hostile cyber landscape.
1,204
European Commission pushes FRTB to 2027
European Commission pushes FRTB to 2027
The European Commission has adopted a delegated act to postpone the implementation of the Fundamental Review of the Trading Book (FRTB), the final component of Basel III international standards, by an additional year to January 1, 2027, citing concerns about maintaining a level playing field for EU banks as other major global jurisdictions continue to delay their own implementation of these...
535
Switzerland to share crypto data with 74 countries by 2027
Switzerland to share crypto data with 74 countries by 2027
Switzerland moved closer to ending its reputation as a haven for undisclosed cryptocurrency holdings, with the Federal Council adopting legislation that would automatically share crypto asset data with 74 partner countries beginning in 2027. The bill, approved during a June 6 meeting, represents Switzerland's entry into the global Crypto-Asset Reporting Framework, a transparency initiative that...
5,140