About the NIS2 Directive

What is the NIS2 Directive?

NIS2 (Network and Information Security Directive 2) is the EU directive on the security of network and information systems. It was implemented in Danish law by Act no. 434 of 06/05/2025 and enters into force on 1 July 2025.

The directive sets requirements for security measures and incident reporting for critical and important sectors, significantly expanding the scope and obligations compared to the previous NIS Directive.

Who is covered by NIS2?

NIS2 applies to medium and large entities (50+ employees or EUR 10M+ turnover) in 18 sectors:

· Critical sectors: Energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space
· Important sectors: Postal and courier services, waste management, chemicals, food, manufacturing, digital providers, research

Certain critical entities are covered regardless of size.

What are the key NIS2 requirements?

NIS2 defines 13 assessment areas, including 10 security measures (§ 6):

· Risk policy and risk assessment
· Incident management and reporting
· Business continuity and crisis management
· Supply chain security
· Access control and multi-factor authentication (MFA)
· Cryptography and encryption
· Cyber hygiene and staff training

Additionally there are requirements for management responsibility (§ 7) and registration with the sector authority (§ 10).

When do I need to register?

Entities covered by NIS2 must register with the relevant sector authority no later than 1 January 2026 pursuant to NIS2 Act § 10. Confirm the current deadline with the Danish Business Authority (Erhvervsstyrelsen) — regulatory deadlines may be adjusted.

Sector authorities vary by industry — e.g. the Danish Energy Agency for the energy sector, the Danish Health Authority for the health sector, and the Danish Agency for Digital Government for public administration and digital infrastructure.

DocLex NIS2 Report

How much does the NIS2 report cost?

A NIS2 compliance report costs EUR 1.699 excl. VAT. The price includes:

· Complete gap analysis across all 13 assessment areas
· Professional Word document with concrete recommendations
· Delivered directly to your email with invoice

What does the NIS2 report contain?

The report contains a structured gap analysis across all 13 assessment areas based on your uploaded documentation. For each area your current compliance level is assessed and concrete implementation recommendations are provided.

The report covers scope assessment, risk policy, incident management, business continuity, supply chain, access control, MFA and management responsibility with direct references to the law's paragraphs.

Can I use the report as documentation for the authorities?

The report is structured according to the NIS2 Act's requirements and can be used as a starting point for internal documentation and communication with authorities.

We recommend the report is reviewed by a legal advisor and CISO before being presented to supervisory authorities, as it is based on the information you have submitted and does not replace a professional security audit.

Does the compliance report replace a technical security audit?

No. The DocLex report is a compliance gap analysis — it identifies which NIS2 requirements are met, partially met, or lack documentation, based on the material you have uploaded.

A technical security audit (penetration testing, vulnerability scanning, on-site audit) is a separate and more technical undertaking typically conducted by an external security firm. Many organisations use the DocLex report as preparation for a formal audit — it provides an overview of the compliance gaps that should be addressed first.

What is the difference between NIS2 and GDPR?

GDPR regulates the processing of personal data and requires DPIA analyses among other things. Its focus is on privacy and personal data protection.

NIS2 focuses on cybersecurity and the resilience of network and information systems — regardless of whether personal data is involved. Many organisations are obligated under both frameworks. DocLex offers reports for both regulations.

What happens to my documents?

Your documents are automatically analysed to identify relevant NIS2 compliance information. The analysis is performed via Claude (Anthropic). Documents are used only for report generation and are not stored permanently.

All processing takes place within the EU on servers in Denmark. Upload only system descriptions and technical documentation — not documents containing personal data.

Ready to generate your NIS2 report?

Start here →