This is an info Alert.
SnapKey Logo
  • Solutions
      • Solutions
      • SnapKey Residential
      • SnapKey Utility
      • SnapKey Public
      • SnapKey Logistics
      • SnapKey Sensors
      • Guest Check-in
      • Reactivatable Keys
      • Self-service Rentals
  • Industries
      • Industries
      • Utility companies
      • Residential buildings
      • Office buildings & Coworking spaces
      • Logistics
      • Holiday homes
      • Public restrooms
      • Construction sites
      • Unmanned stores
      • Temporary lockers
      • Virtual Keybox
  • Resources
      • Resources
      • Knowledge
      • Videos
      • API documentation
      • Trust & Security
      • System status
  • Partners
  • Company
      • Company
      • About us
      • Why SnapKey
      • Contact
auth.sign_inBook a demo

NIS2 in Denmark 2026 – 6,000 companies and active supervision

Denmark's NIS2 law has been in force since 1 July 2025, and supervision has begun. See how many companies are covered, what inspectors ask for, and which documentation you need to be able to produce.
16. September 2026
6 min

Denmark's NIS2 law entered into force on 1 July 2025. The first year was about working out who was covered. 2026 is about something else: supervision.

The Centre for Cyber Security began active supervision during the first half of 2026. That moves the question from "are we in scope?" to "can we prove we meet the requirements?"


The number is 6,000 – not 1,000

One of the most persistent misconceptions about NIS2 in Denmark is the number of companies affected.

Regime Danish organisations covered
NIS1 (previous) approx. 1,000
NIS2 (current) approx. 6,000

That is a sixfold increase. Many of the newly covered organisations have never been subject to cybersecurity regulation before — and are only now discovering that the requirements also reach the physical world: who can walk through which doors, and whether that can be evidenced.

A European survey from late 2025 found that only around 16% of respondents felt fully prepared. That is the situation supervision is walking into.


The problem: the requirements are met but cannot be shown

Most organisations we speak to are doing sensible things. There are locks on the doors, keys are not handed out to just anyone, and there is a tidy-up when someone leaves.

The problem starts when supervision asks for evidence. And evidence is not the same as practice:

❌ "We only grant access to those who need it"

Inspector: show me the list of who has access to the site, and when it was last reviewed.

❌ "We collect keys when people leave"

Inspector: show me that the keys from the last 12 departures were actually returned.

❌ "We'd notice a break-in"

Inspector: when did you detect your last incident, and how many hours passed before it was handled?

❌ "Contractors get access by arrangement"

Inspector: show me which external parties had access this year, and for which periods.

None of those four questions can be answered with a key cabinet and a spreadsheet.


The requirements that hit access control directly

NIS2 sets risk-management requirements across ten areas. Four of them are, in practice, about who can get in:

  1. Access control policies – documented rules for who gets access to what, and how access is granted and removed
  2. Asset management – an overview of assets, including the physical access points to them
  3. Human resources security – managing access across the whole employment lifecycle, especially at departure
  4. Supply chain security – managing the access of suppliers and contractors

On top of that comes incident handling, where access-related events – forced entries, repeated denied attempts, doors left standing open – are one of the categories that must be detectable and handled.


The reporting deadlines: 24 / 72 / 1 month

For a significant incident, three deadlines apply:

Incident detected  ← the clock starts here, not when you begin investigating
   │
   ├─ 24 hours ───► Early warning to the authority
   │
   ├─ 72 hours ───► Notification with severity assessment
   │                 and indicators of compromise
   │
   └─ 1 month ────► Final report

In Denmark, incidents are reported to the Centre for Cyber Security (CFCS), which acts as the national CSIRT. Certain sectors have their own supervisory authorities — for example the Danish Energy Agency for the energy sector and the Danish FSA for financial services.

The detail that costs organisations most is that the clock starts when you become aware of the incident. Not when the investigation concludes. If three days pass before anyone sees the event in a log, the deadline is blown before the work has begun.


Management liability and fines

NIS2 places responsibility on management personally. Management must approve the measures, supervise them, and be able to document having done so.

For essential entities, penalties can reach EUR 10 million or 2% of global turnover — whichever is higher.

In practice, management liability means "that sits with IT" is no longer a valid answer. There has to be an approved, dated and documented decision.


What to have ready for an inspection

Documentation Typical question from supervision
Current access overview Who has access to your critical sites today?
Access log for a chosen period Who was on site in March, and for what reason?
Key inventory How many keys are issued, and which have gone unused for 90 days?
Incident log with response times How long from detection to handling?
Offboarding trail Can you show that access was removed when employment ended?
Management approval When did management last approve your measures?

The point is not that it has to be beautiful. The point is that it has to exist, and that it has to be datable.


How SnapKey helps

Digital access control answers the NIS2 requirements because documentation becomes a by-product of daily operations instead of a project you start when supervision calls:

✅ Access is always named – every unlock ties to a person, not to a key that can be lent out
✅ Time limits by default – contractor access expires on its own
✅ Instant withdrawal – when someone leaves, access is gone the same minute
✅ Incidents recorded automatically – with a timestamp, so the 24-hour clock runs from a documented moment
✅ Signed reports – generated for a chosen period with a SHA-256 checksum, so the document can be verified

If you already run an iLOQ system, none of this requires new cylinders — see SnapKey for iLOQ.


FAQ

How many Danish companies are covered by NIS2?

Approximately 6,000 – a sixfold increase on the roughly 1,000 organisations covered by the previous NIS1 legislation.

When did supervision start in Denmark?

The NIS2 law entered into force on 1 July 2025, and the Centre for Cyber Security began active supervision during the first half of 2026.

When does the 24-hour deadline start?

When you become aware of the incident – not when the investigation is complete. This is why automatic incident recording matters: it establishes a documented moment of detection.

Is access control really in scope for NIS2?

Yes. Access control policies are explicitly named among the risk-management measures, and both human resources security and supply chain security concern who can physically get in.

What are the penalties?

For essential entities, up to EUR 10 million or 2% of global turnover – whichever is higher – plus personal management liability.


Contact us

Want to know how your access control measures up against NIS2? Contact SnapKey for a review.

Contact us
Related articles
Compliance documentation that exists before the auditor asks

Most organisations only produce reports when the authority calls – and then discover the data is missing. See how scheduled reports, signed PDFs with SHA-256 and fixed cadences make documentation an automatic part of operations.

NIS2 Directive – Access Control and Cybersecurity Requirements 2025

The NIS2 law introduces enhanced requirements for cybersecurity and access control for businesses in critical infrastructure. Learn about the new requirements and how to achieve compliance.

Energy Legislation and Access Control – Requirements for Critical Infrastructure

Understand energy legislation requirements for physical security and access control. Learn how SnapKey helps energy companies achieve compliance.


SnapKey Logo

SnapKey is your digital key for all types of locks. Easily open doors and locks directly from your smartphone, and enjoy fast, secure and flexible access without physical keys or extra apps. Perfect for private homes, businesses and shared spaces.

Solutions
SnapKey ResidentialSnapKey UtilitySnapKey PublicSnapKey LogisticsGuest Check-in
Developers
API documentationAPI referenceWebhooksChangelogSystem status
Company
About usWhy SnapKeyBecome a partnerKnowledgeVideosContact us
Legal
Terms & ConditionsPrivacy PolicyTrust & Security
Contact
SnapKey ApS+45 3242 9050info@snapkey.dk

© All rights reserved.