NIS2-krav til virksomheder
We offer everything from comprehensive programs to ongoing consulting on an hourly basis.

NIS2 sets out comprehensive requirements for cybersecurity, risk management, and management responsibility. For many organizations, the challenge lies in translating these requirements into concrete and effective measures that both support compliance and create real value for the organization.
With our specialized NIS2 consulting services, you’ll gain a clear overview of your obligations, the key risks, and the necessary measures. We’ll help you develop a structured and documented approach that strengthens your organization’s resilience and ensures a solid foundation for protecting your operations, data, and business.
Guide til NIS2 implementering
Step 1
Mapping and analysis
Assessment and analysis provide an overview of the organization’s current level of cybersecurity in relation to NIS2.
We identify which requirements are relevant to your organization, where there may be gaps, and which specific actions should be prioritized. The result is a solid foundation for working in a focused, effective, and well-documented manner toward NIS2 compliance.

Step 2
Action plan and strategy
The assessment is translated into a clear, prioritized plan for how the organization will continue working toward NIS2 compliance.
We help you identify the necessary steps, assign responsibilities, and establish a structured approach to the work. The result is an action plan that supports effective implementation, strengthens security, and ensures progress by focusing on the activities that create the most value.

Step 3
Consulting
We offer flexible consulting services that can be tailored to your needs—from hourly consultations on specific topics to comprehensive programs where we guide you every step of the way toward NIS2 compliance.
Our goal is to ensure that the organization not only meets the NIS2 requirements but also emerges stronger as a result. That is why we prioritize ongoing knowledge transfer, so that you have the necessary skills to maintain these efforts, sustain the security level, and further develop your initiatives over time.

Step 4
Implementation
During the implementation phase, the action plan is translated into specific security measures. These may include, among other things, updating policies, establishing access controls, backup procedures, contingency plans, incident response, and awareness activities.
We help you implement these measures in practice and ensure that they can be documented, applied, and maintained in day-to-day operations. The result is a more operational security approach, in which the NIS2 requirements are translated into specific workflows, controls, and responsibilities.

Step 5
Awareness training and workshops
NIS2 sets requirements for management, employees, and the processes that support the organization’s cybersecurity. That is why we offer awareness training and workshops that enable employees and relevant key personnel to understand their role in cybersecurity efforts.
The content is tailored to your organization, and the result is greater security awareness and a stronger foundation for sustaining NIS2 efforts in practice.

Step 6
Full Compliance
Once the necessary measures and relevant documentation are in place, the organization will have a solid foundation for complying with the NIS2 requirements and strengthening its security efforts going forward.

Get help with NIS2
If you’re unsure how close you are to meeting the NIS2 requirements, we can help you get a clear picture of the situation and translate the requirements into concrete security measures.
Are you unsure about where you stand with NIS2?
If you’re unsure how close you are to meeting the NIS2 requirements, we can help you get a clear picture of the situation and translate the requirements into concrete security measures. Many organizations are unsure whether they are subject to NIS2, how close they are to meeting the requirements, and which measures should be prioritized first.
Consultation with a specialist
One of our experienced specialists will review your challenges, answer your questions, and provide specific recommendations based on your organization, risks, and business. If you need further assistance, we can support you throughout the entire process—from the initial discussions to the subsequent implementation, depending on your needs.
Maturity Assessment
Getting Started
We’ll start by getting to know your organization and assessing your current level of security in relation to NIS2.
Scope
Review
We identify which NIS2 requirements apply to you and review your organization, critical systems, and key processes.
Risk Assessment
Mapping
We identify the most significant shortcomings and risks and compile the results into a concise report with clear priorities.
Action Plan
Clarification
You will receive a concrete action plan with recommendations, priority actions, and next steps toward NIS2 compliance.
Start with a no-obligation consultation with one of our experts, or purchase a preliminary analysis starting at 15,000 DKK
Get the big picture before you invest
A NIS2 preliminary analysis will give you a clear picture of where you stand today, which requirements apply to you, and which initiatives should be prioritized first. The result is a solid basis for decision-making that makes it easier to plan investments and work in a structured manner toward NIS2 compliance.
Get a quote for a full NIS2 review
Includes, among other things,
The conversation is non-binding
If you're interested, please send an email
First Step Toward NIS2 Certification
View upcoming courses and webinars
Learn how your company can strengthen cybersecurity and achieve compliance with standards such as ISO 27001, NIS2, and CRA.
NIS2 for management
Copenhagen / August 26, 26
ISO 27001: Certificate Course
Copenhagen / September 2–3, 2026
NIS 2 in Practice
Odense / September 10–11, 2026
ISO 27001: Certificate Course
Copenhagen / Oct. 7–8, 2025
Guides and articles about NIS2
View all blog postsNIS 2-krav i praksis
28 august, 2026
NIS 2-krav i praksis: Kan I dokumentere, at sikkerheden virker?
NIS 2-tilsyn er i gang. Se, hvordan ledelsen dokumenterer risici, sikkerhedsforanstaltninger og hændelsesberedskab i praksis.
What is NIS2?
March 6, 2026
What is NIS2?
Denmark has implemented the EU’s NIS2 Directive through the Folketing with the Act on Measures to Ensure a High Level of Cybersecurity (the NIS2 Act)
Frequently Asked Questions About NIS2 Implementation
Do you still have questions that weren't answered? Schedule a free 15-minute consultation with a cybersecurity expert.
NIS2 is an EU directive designed to strengthen cybersecurity and resilience in sectors vital to society and critical infrastructure. In Denmark, the directive has been implemented through the NIS2 Act, which sets requirements for, among other things, risk management, security measures, incident reporting, supplier management, management responsibility, and documentation.
NIS2 may cover both private and public organizations. Whether an organization is covered depends, among other things, on its sector, size, and the specific role it plays in the supply chain. Relevant sectors include, among others, energy, transportation, healthcare, drinking water, digital infrastructure, IT services, public administration, food, waste management, and manufacturing.
Nesp.ONE helps determine whether an organization is subject to NIS2, which requirements apply, and how these requirements can be translated into specific security measures, documentation, and ongoing monitoring.
Read more about NIS2 here: EUR.lex, Samsik.dk, Europa.eu,Retsinformation.dk
What are the cybersecurity requirements under NIS2?
NIS2 requires that covered organizations adopt a risk-based approach using appropriate technical, organizational, and operational security measures. This means that security measures must be based on the organization’s specific risks, systems, suppliers, and critical services.
The requirements include, among other things, incident management, emergency preparedness and business continuity, supplier management, access control, asset management, encryption where applicable, awareness, cyber hygiene, and documentation. The purpose is not only to protect data, but also to reduce the risk of operational disruptions, service interruptions, and incidents that could affect customers, citizens, business partners, or critical societal functions.
Nesp.ONE helps identify relevant requirements, prioritize necessary actions, and establish a structured approach that supports both compliance and a higher level of security.
A risk-based approach means that the organization must prioritize its security efforts based on where the consequences of an incident would be greatest (Learn more about the risk-based approach here). This requires a comprehensive overview of systems, data, processes, suppliers, dependencies, and the services the organization must be able to deliver.
This also means that not all security measures need to be implemented in the same way everywhere. Critical systems, business-critical processes, and key suppliers may require a higher level of security than less critical areas. A risk-based approach makes it possible to allocate resources in a more targeted manner and to document why certain measures are prioritized.
Nesp.ONE assists with risk assessment, gap analysis, and action plans, providing the organization with a concrete foundation for working toward NIS2 compliance.
What are management's responsibilities under NIS2?
NIS2 places senior management at the center of cybersecurity efforts. Senior management must be able to approve, monitor, and ensure the implementation of relevant cybersecurity measures. This does not require detailed technical knowledge, but rather a clear basis for decision-making regarding risks, responsibilities, priorities, and necessary actions.
For the organization, this means that cybersecurity must be treated as part of its overall risk management. Management must be able to document that it takes a structured approach to security, emergency preparedness, supplier management, and incident response.
Nesp.ONE helps make management responsibilities concrete through risk profiles, prioritized action plans, reporting, and documentation that can be used by management, the board of directors, and supervisory bodies.
How should security incidents be reported under NIS2?
NIS2 requires that significant security incidents be reported within specified timeframes. As a general rule, an initial notification must be submitted within 24 hours, an incident report within 72 hours, and a final report no later than one month after the incident report (Read more about the incident reporting requirements here).
This requires clear procedures for detecting, assessing, escalating, and documenting incidents. The organization must be able to assess the severity of the incident, collect relevant information, and ensure timely reporting to the appropriate authorities.
Nesp.ONE helps establish IT contingency plans, reporting procedures, and action cards so that the organization can respond quickly, minimize the impact, and document incident management.
What does NIS2 mean for suppliers and the supply chain?
NIS2 requires that covered organizations actively address supply chain security. This means that the organization must assess relevant suppliers, set appropriate security requirements, and monitor compliance with those requirements.
Supplier management includes, among other things, risk assessment, contractual requirements, access to systems and data, subcontractors, contingency planning, and documentation of security measures. For suppliers, NIS2 also means that they may face stricter requirements from customers covered by NIS2, even if they themselves are not necessarily directly covered.
Nesp.ONE helps provide an overview of supplier risks, define relevant security requirements, and establish a practical process for follow-up and documentation.
What are the consequences of non-compliance with NIS2?
Failure to comply with NIS2 may result in oversight, injunctions, and significant penalties. For substantial entities, fines can amount to up to 10 million euros or 2 percent of global annual revenue. For important entities, fines can amount to up to 7 million euros or 1.4 percent of global annual revenue, whichever is higher.
However, the overall risk extends beyond sanctions. A lack of control over cybersecurity can also lead to operational disruptions, delayed deliveries, data loss, increased costs, contractual consequences, and a loss of trust among customers, citizens, and business partners.
Nesp.ONE helps establish a structured and documented approach to NIS2, enabling the organization to reduce the risk of both regulatory and operational consequences.