NIS2-krav til virksomheder

Make sure your organization complies with the NIS2 requirements.
We offer everything from comprehensive programs to ongoing consulting on an hourly basis. 
Purchase a preliminary analysis starting at 15,000 DKK
Oversigt over seks centrale NIS2-krav til virksomheder

NIS2 sets out comprehensive requirements for cybersecurity, risk management, and management responsibility. For many organizations, the challenge lies in translating these requirements into concrete and effective measures that both support compliance and create real value for the organization.

With our specialized NIS2 consulting services, you’ll gain a clear overview of your obligations, the key risks, and the necessary measures. We’ll help you develop a structured and documented approach that strengthens your organization’s resilience and ensures a solid foundation for protecting your operations, data, and business.

Guide til NIS2 implementering

Step 1

Mapping and analysis   

Assessment and analysis provide an overview of the organization’s current level of cybersecurity in relation to NIS2.

We identify which requirements are relevant to your organization, where there may be gaps, and which specific actions should be prioritized. The result is a solid foundation for working in a focused, effective, and well-documented manner toward NIS2 compliance.

Læs mere om vores NIS2-rådgivning her
Example of Documentation of NIS2 Compliance

Step 2

Action plan and strategy    

The assessment is translated into a clear, prioritized plan for how the organization will continue working toward NIS2 compliance.

We help you identify the necessary steps, assign responsibilities, and establish a structured approach to the work. The result is an action plan that supports effective implementation, strengthens security, and ensures progress by focusing on the activities that create the most value.

Example of an action plan developed for organizations covered by NIS2

Step 3

Consulting   

We offer flexible consulting services that can be tailored to your needs—from hourly consultations on specific topics to comprehensive programs where we guide you every step of the way toward NIS2 compliance.

Our goal is to ensure that the organization not only meets the NIS2 requirements but also emerges stronger as a result. That is why we prioritize ongoing knowledge transfer, so that you have the necessary skills to maintain these efforts, sustain the security level, and further develop your initiatives over time.

Illustration of the options customers have for receiving advice at Nesp.ONE

Step 4

Implementation

During the implementation phase, the action plan is translated into specific security measures. These may include, among other things, updating policies, establishing access controls, backup procedures, contingency plans, incident response, and awareness activities.

We help you implement these measures in practice and ensure that they can be documented, applied, and maintained in day-to-day operations. The result is a more operational security approach, in which the NIS2 requirements are translated into specific workflows, controls, and responsibilities.

Example of Documentation Requirements for NIS2 Compliance

Step 5

Awareness training and workshops 

NIS2 sets requirements for management, employees, and the processes that support the organization’s cybersecurity. That is why we offer awareness training and workshops that enable employees and relevant key personnel to understand their role in cybersecurity efforts.

The content is tailored to your organization, and the result is greater security awareness and a stronger foundation for sustaining NIS2 efforts in practice.

Illustration of awareness training for employees in organizations seeking ISO 27001 certification

Step 6

Full Compliance 

Once the necessary measures and relevant documentation are in place, the organization will have a solid foundation for complying with the NIS2 requirements and strengthening its security efforts going forward.

Compliance with NIS2 requires ongoing monitoring, updating, and documentation. We can therefore help you establish an annual cycle that ensures policies, processes, and controls are reviewed and maintained over time. This not only creates a stronger foundation for compliance but also enhances resilience, improves risk management, and builds greater trust among customers, business partners, and management.
Annual cycle illustrating the work on NIS2 compliance in organizations

Get help with NIS2

If you’re unsure how close you are to meeting the NIS2 requirements, we can help you get a clear picture of the situation and translate the requirements into concrete security measures.

Consulting

Are you unsure about where you stand with NIS2?

If you’re unsure how close you are to meeting the NIS2 requirements, we can help you get a clear picture of the situation and translate the requirements into concrete security measures. Many organizations are unsure whether they are subject to NIS2, how close they are to meeting the requirements, and which measures should be prioritized first.

Consultation with a specialist

One of our experienced specialists will review your challenges, answer your questions, and provide specific recommendations based on your organization, risks, and business. If you need further assistance, we can support you throughout the entire process—from the initial discussions to the subsequent implementation, depending on your needs.

Preliminary Analysis / GAP Analysis

Maturity Assessment

Getting Started

We’ll start by getting to know your organization and assessing your current level of security in relation to NIS2.

Scope

Review

We identify which NIS2 requirements apply to you and review your organization, critical systems, and key processes.

Risk Assessment

Mapping

We identify the most significant shortcomings and risks and compile the results into a concise report with clear priorities.

Action Plan

Clarification

You will receive a concrete action plan with recommendations, priority actions, and next steps toward NIS2 compliance.

Learn more about NIS2 requirements

Start with a no-obligation consultation with one of our experts, or purchase a preliminary analysis starting at 15,000 DKK

Preliminary analysis starting at 15,000 DKK. ContactStill unsure? Read all about the preliminary analysis here
Why Conduct a Preliminary Analysis?

Get the big picture before you invest

A NIS2 preliminary analysis will give you a clear picture of where you stand today, which requirements apply to you, and which initiatives should be prioritized first. The result is a solid basis for decision-making that makes it easier to plan investments and work in a structured manner toward NIS2 compliance.

Get a quote for a full NIS2 review

Includes, among other things,

WorkshopAnalysisReportReviewAction PlanConsultingAnnual Cycle
Book a free consultation

The conversation is non-binding

If you're interested, please send an email

First Step Toward NIS2 Certification

Download our white paper on the NIS2 legislation here and learn more about its scope
By submitting your email address, you agree to our privacy policy and consent to being contacted by nesp.ONE.

Sektorer som er underlagt NIS2

Drinking Water

Waterworks and utility companies responsible for supplying clean drinking water.

Communication

Providers of public electronic communications networks or services.

Energy

Entities that produce, transport, and distribute electricity and gas.

Offentlige myndigheder

Public entities that perform missions critical to society.

Finance

Handling money, investments, and financial services.

Health

Provision of health care, medical treatment, and equipment to patients.

Waste

Collection, sorting, and disposal of waste and hazardous substances.

Data

Data centers, internet hubs, and DNS services that ensure stable digital systems.

Online

Providers of cloud services, search engines, software, and platforms for digital commerce and communication.

View upcoming courses and webinars

Learn how your company can strengthen cybersecurity and achieve compliance with standards such as ISO 27001, NIS2, and CRA.

NIS2 for management 

Copenhagen / August 26, 26

ISO 27001: Certificate Course

Copenhagen / September 2–3, 2026

NIS 2 in Practice

Odense / September 10–11, 2026

ISO 27001: Certificate Course

Copenhagen / Oct. 7–8, 2025

Guides and articles about NIS2

View all blog posts

NIS 2-krav i praksis

28 august, 2026

NIS 2-krav i praksis: Kan I dokumentere, at sikkerheden virker?

NIS 2-tilsyn er i gang. Se, hvordan ledelsen dokumenterer risici, sikkerhedsforanstaltninger og hændelsesberedskab i praksis.

What is NIS2?

March 6, 2026

What is NIS2?

Denmark has implemented the EU’s NIS2 Directive through the Folketing with the Act on Measures to Ensure a High Level of Cybersecurity (the NIS2 Act)

Frequently Asked Questions About NIS2 Implementation

Do you still have questions that weren't answered? Schedule a free 15-minute consultation with a cybersecurity expert.

Book a free consultation

NIS2 is an EU directive designed to strengthen cybersecurity and resilience in sectors vital to society and critical infrastructure. In Denmark, the directive has been implemented through the NIS2 Act, which sets requirements for, among other things, risk management, security measures, incident reporting, supplier management, management responsibility, and documentation.

NIS2 may cover both private and public organizations. Whether an organization is covered depends, among other things, on its sector, size, and the specific role it plays in the supply chain. Relevant sectors include, among others, energy, transportation, healthcare, drinking water, digital infrastructure, IT services, public administration, food, waste management, and manufacturing.

Nesp.ONE helps determine whether an organization is subject to NIS2, which requirements apply, and how these requirements can be translated into specific security measures, documentation, and ongoing monitoring.

Read more about NIS2 here: EUR.lex, Samsik.dk, Europa.eu,Retsinformation.dk

NIS2 requires that covered organizations adopt a risk-based approach using appropriate technical, organizational, and operational security measures. This means that security measures must be based on the organization’s specific risks, systems, suppliers, and critical services.

The requirements include, among other things, incident management, emergency preparedness and business continuity, supplier management, access control, asset management, encryption where applicable, awareness, cyber hygiene, and documentation. The purpose is not only to protect data, but also to reduce the risk of operational disruptions, service interruptions, and incidents that could affect customers, citizens, business partners, or critical societal functions.

Nesp.ONE helps identify relevant requirements, prioritize necessary actions, and establish a structured approach that supports both compliance and a higher level of security.

A risk-based approach means that the organization must prioritize its security efforts based on where the consequences of an incident would be greatest (Learn more about the risk-based approach here). This requires a comprehensive overview of systems, data, processes, suppliers, dependencies, and the services the organization must be able to deliver.

This also means that not all security measures need to be implemented in the same way everywhere. Critical systems, business-critical processes, and key suppliers may require a higher level of security than less critical areas. A risk-based approach makes it possible to allocate resources in a more targeted manner and to document why certain measures are prioritized.

Nesp.ONE assists with risk assessment, gap analysis, and action plans, providing the organization with a concrete foundation for working toward NIS2 compliance.

NIS2 places senior management at the center of cybersecurity efforts. Senior management must be able to approve, monitor, and ensure the implementation of relevant cybersecurity measures. This does not require detailed technical knowledge, but rather a clear basis for decision-making regarding risks, responsibilities, priorities, and necessary actions.

For the organization, this means that cybersecurity must be treated as part of its overall risk management. Management must be able to document that it takes a structured approach to security, emergency preparedness, supplier management, and incident response.

Nesp.ONE helps make management responsibilities concrete through risk profiles, prioritized action plans, reporting, and documentation that can be used by management, the board of directors, and supervisory bodies.

NIS2 requires that significant security incidents be reported within specified timeframes. As a general rule, an initial notification must be submitted within 24 hours, an incident report within 72 hours, and a final report no later than one month after the incident report (Read more about the incident reporting requirements here).

This requires clear procedures for detecting, assessing, escalating, and documenting incidents. The organization must be able to assess the severity of the incident, collect relevant information, and ensure timely reporting to the appropriate authorities.

Nesp.ONE helps establish IT contingency plans, reporting procedures, and action cards so that the organization can respond quickly, minimize the impact, and document incident management.

NIS2 requires that covered organizations actively address supply chain security. This means that the organization must assess relevant suppliers, set appropriate security requirements, and monitor compliance with those requirements.

Supplier management includes, among other things, risk assessment, contractual requirements, access to systems and data, subcontractors, contingency planning, and documentation of security measures. For suppliers, NIS2 also means that they may face stricter requirements from customers covered by NIS2, even if they themselves are not necessarily directly covered.

Nesp.ONE helps provide an overview of supplier risks, define relevant security requirements, and establish a practical process for follow-up and documentation.

Failure to comply with NIS2 may result in oversight, injunctions, and significant penalties. For substantial entities, fines can amount to up to 10 million euros or 2 percent of global annual revenue. For important entities, fines can amount to up to 7 million euros or 1.4 percent of global annual revenue, whichever is higher.

However, the overall risk extends beyond sanctions. A lack of control over cybersecurity can also lead to operational disruptions, delayed deliveries, data loss, increased costs, contractual consequences, and a loss of trust among customers, citizens, and business partners.

Nesp.ONE helps establish a structured and documented approach to NIS2, enabling the organization to reduce the risk of both regulatory and operational consequences.

Preliminary Analysis – NIS2

Formålet med en foranalyse er at vurdere organisationens nuværende praksis i forhold til kravene i NIS2-loven. Analysen giver et samlet overblik over organisationens modenhed inden for informationssikkerhed og identificerer de områder, hvor sikkerhedsforanstaltninger, processer eller dokumentation skal styrkes for at understøtte overholdelse af loven. Foranalysen tager udgangspunkt i følgende ti områder, som NIS2-loven stiller krav om, at omfattede organisationer arbejder med:

1. Policies for Risk Analysis and Information System Security

Der foretages en vurdering af, om organisationen har etableret politikker og processer for risikoanalyse og informationssystemsikkerhed. Dette omfatter blandt andet identifikation af kritiske aktiver, risikovurderinger, ledelsens involvering samt implementering af passende organisatoriske og tekniske sikkerhedsforanstaltninger.

2. Incident Management

Der foretages en vurdering af organisationens processer for håndtering af cybersikkerhedshændelser. Analysen omfatter blandt andet organisationens evne til at identificere, registrere, analysere, håndtere og rapportere sikkerhedshændelser samt sikre, at erfaringer fra hændelser anvendes til løbende forbedringer.

3. Business continuity, including backup management, disaster recovery, and crisis management

Der vurderes, om organisationen har etableret beredskabs- og kontinuitetsplaner, som understøtter opretholdelse af kritiske forretningsfunktioner under sikkerhedshændelser. Analysen omfatter blandt andet backupstrategier, disaster recovery, krisestyring, beredskabsøvelser og planer for genetablering af driften.

4. Supply chain security, including security-related aspects concerning the relationships between an individual entity and its direct suppliers or service providers

Der foretages en vurdering af organisationens processer for styring af cybersikkerhedsrisici i forsyningskæden. Det omfatter blandt andet risikovurdering af leverandører, kontraktuelle sikkerhedskrav, løbende leverandøropfølgning samt dokumentation af leverandørernes sikkerhedsniveau.

5. Security in connection with the acquisition, development, and maintenance of network and information systems, including the handling and disclosure of vulnerabilities

Der vurderes, om organisationen har etableret processer, der sikrer, at cybersikkerhed indgår ved anskaffelse, udvikling og vedligeholdelse af net- og informationssystemer. Analysen omfatter blandt andet ændringsstyring, patch management, sårbarhedshåndtering, sikker udvikling samt processer for håndtering og offentliggørelse af sårbarheder.

6. Policies and procedures for assessing the effectiveness of measures to manage cybersecurity risks

Der foretages en vurdering af, hvordan organisationen løbende evaluerer effektiviteten af sine cybersikkerhedsforanstaltninger. Dette kan blandt andet omfatte interne kontroller, sikkerhedsscanninger, penetrationstest, audits, ledelsesrapportering og opfølgning på identificerede forbedringsområder.

7. Basic Cybersecurity Hygiene Practices and Cybersecurity Training

Der vurderes, om organisationen har etableret processer, der understøtter en høj grad af cyberhygiejne blandt medarbejdere og ledelse. Analysen omfatter blandt andet awareness-programmer, phishing-træning, sikker anvendelse af IT, password-politikker samt løbende uddannelse i cybersikkerhed.

8. Policies and procedures regarding the use of cryptography and, where applicable, encryption

Der foretages en vurdering af organisationens anvendelse af kryptografi og kryptering til beskyttelse af informationer. Det omfatter blandt andet kryptering af data under lagring og transmission, styring af kryptografiske nøgler samt retningslinjer for anvendelse af kryptografiske løsninger.

9. Personnel Security, Access Control Policies, and Asset Management

Der vurderes, om organisationen har etableret passende procedurer for personalesikkerhed, adgangskontrol og forvaltning af informationsaktiver. Det omfatter blandt andet onboarding og offboarding, rollebaseret adgangsstyring, periodisk gennemgang af brugerrettigheder, klassificering af aktiver samt beskyttelse af virksomhedens informationsaktiver gennem hele deres livscyklus.

10. Use of solutions involving multi-factor authentication or continuous authentication, secure voice, video, and text communications, and secure emergency communication systems within the unit, where applicable

Der foretages en vurdering af organisationens anvendelse af stærke autentificeringsmekanismer, herunder multifaktorautentificering (MFA) eller kontinuerlig autentificering, hvor det er relevant. Derudover vurderes anvendelsen af sikre kommunikationsløsninger til tale-, video- og tekstkommunikation samt etablering af sikre interne nødkommunikationssystemer.

NIS2 Preliminary Analysis Report

På baggrund af foranalysen modtager organisationen en rapport med en samlet vurdering af dens nuværende modenhed inden for cybersikkerhed og informationssikkerhed.
Rapporten identificerer forskellen mellem virksomhedens eksisterende praksis og de relevante krav i NIS2-loven. Den indeholder en prioriteret handlingsplan med anbefalinger til organisatoriske og tekniske sikkerhedsforanstaltninger, dokumentation og ansvarsfordeling. Organisationen får dermed et klart beslutningsgrundlag for det videre arbejde med NIS2-compliance og styrkelse af sin modstandsdygtighed.
Preliminary analysis starting at 15,000 DKK. Contact us

Strengthen your cybersecurity with the right guidance on NIS2

 Enter your email address here, and we'll contact you personally with the best possible solution for your business—we look forward to hearing from you.

Preliminary analysis starting at 15,000 DKK – price subject to the size of the company.

By submitting your email address, you agree to our privacy policy and consent to being contacted by nesp.ONE.