Denmark transposed the NIS2 Directive through Lov nr 434 af 6. maj 2025 (Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau, styled NIS 2-loven), signed 6 May 2025, published in Lovtidende A on 7 May 2025, and in force since 1 July 2025 under its own Section 33(1).
The Act binds an essential entity (Section 4) or an important entity (Section 5) drawn from its Annex 1 (sectors of particular critical importance) or Annex 2 (other critical sectors), except an entity the Act itself routes to a separate regime: Section 1(2) excludes an entity covered by Denmark's Act on strengthened preparedness in the energy sector, an entity covered by its Act on security and preparedness in the telecommunications sector, and a financial entity the Financial Business Act's Section 333(1) designates, each of which runs under its own parallel security regime rather than being folded into this one.
Annex 1's digital-infrastructure entry (item 8) names an internet-exchange-point provider, a DNS provider other than a root-server operator, a top-level-domain registry, a cloud-computing-service provider, a data-centre-service provider, a content-delivery-network provider, a trust-service provider, and a provider of a public electronic-communications network or service, reached as essential entities by the general size test (250 employees, or annual turnover over EUR 50 million and a balance sheet over EUR 43 million), except that a qualified trust-service provider, a top-level-domain registry and a DNS provider are essential entities regardless of size (Section 4(3)(1)).
Annex 2's digital-provider entry (item 6) separately names an online marketplace, an online search engine, and a social-networking-services-platform provider, reached as important entities at the smaller size test (50 employees, or turnover and balance sheet each over EUR 10 million) once they clear that bar (Section 5(1)).
The wider sector classes both Annexes list by industry (energy, transport, drinking water, health, waste, chemicals, food, manufacturing, space, postal and courier services, and the rest) are a designation and size class no activity in this vocabulary expresses, and none is flagged on that account; nor is a row filed for the energy-sector, telecom-sector or financial-entity regimes Section 1(2) excludes, since no activity in the vocabulary expresses a financial entity, an energy operator, or a telecommunications operator either.
This Act repeals, on the date it took effect, all four of Denmark's 2018 NIS1-era security laws: Lov nr 436 (domain-name-system and digital-service security), Lov nr 437 (internet-exchange-point-operator security), Lov nr 440 (healthcare-sector security), and Lov nr 441 (transport-sector security), each af 8. maj 2018 (Section 33(4) to (7)), so none of those four survives alongside the general Act the way a predecessor NIS1 regime does in some other Member States.
No instrument here imposes a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.
Denmark has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and the Databeskyttelsesloven's own breach-notification duties to Datatilsynet, both of which sit in the privacy topic rather than here.
A violation of the risk-management, registration, incident-notification or recipient-notice duties below (Sections 6, 9, 10, 11, 12(1), 13 or 15) is punished with a criminal fine (bøde) under Section 32, not an administrative fine the competent authority itself may impose, a departure from the EUR 10 million/2 percent (essential entity) and EUR 7 million/1.4 percent (important entity) administrative-fine ceilings most other Member States' own NIS2 transpositions enact; the Act states no fixed monetary maximum or turnover percentage of its own, leaving the amount to Denmark's ordinary criminal-sentencing process, and corporate (legal-person) liability attaches under Chapter 5 of the Criminal Code (straffeloven).