Digitalsikkerhetsloven Applies Today. NIS2 Has No Date Yet., audio
Listen to this guide, voiced by Andrew.
Law and forskrift text checked against Lovdata on [date of sign-off]. EEA status checked on [date of sign-off]. This is the part that will go stale first.
Search for NIS2 in Norwegian and you will find consultancies, certification bodies and law firms explaining how to prepare. Most of them are accurate about its status. The risk sits with the reader who skims a headline about NIS2 and takes it for the law that applies in Norway today.
NIS2 is not Norwegian law today. The directive is marked as EEA relevant and is under scrutiny for incorporation into the EEA Agreement, and we found no Joint Committee decision, no consultation paper and no bill. The Storting’s own EU/EEA bulletin of 28 January 2026 says the government is working on how NIS2 should be implemented. No date has been set.
This changes what you are obliged to do, which deadlines are real, and which authority you answer to. If you have been assessed against NIS2 and told you are compliant, check that the assessment also covered the law that binds you now.
What is actually in force
The binding instrument is digitalsikkerhetsloven, Lov 2023-12-20 nr. 108, together with digitalsikkerhetsforskriften, FOR-2025-06-20 nr. 1131. Both entered into force on 1 October 2025.
NSM states it plainly: “1. oktober 2025 trer loven om digital sikkerhet og forskriften om digital sikkerhet i kraft i Norge”, and “Loven innfører NIS-direktivet fra EU i norsk rett.”
That is the first NIS directive, which predates NIS2.
On NIS2, the same source says only that it “skal etter hvert innføres i norsk rett sammen med CER-direktivet”. Eventually, alongside the Critical Entities Resilience directive. That is expected to happen in a new law; official sources speak of a need to revise or replace the current one.
NIS2 must be incorporated into the EEA Agreement before it binds Norway, though Norwegian preparation can run in parallel. So there is a law you are subject to today, and a directive that creates no obligation under Norwegian law yet. Parts of it are already mirrored in the forskrift, and EU transpositions or your contracts may bind you separately if you operate or sell in the EU.
Are you in scope
Digitalsikkerhetsloven covers providers of services important to society, in seven sectors:
- energy
- transport
- health
- water supply
- banking
- financial market infrastructure
- digital infrastructure
Being in a sector is not enough. Section 1 of the forskrift is a closed list of 28 service categories with thresholds, such as train-kilometres per year or cubic metres of water per day, and banks designated by the Finance Ministry. Check the list, then the threshold.
Digital service providers (online marketplaces, search engines and cloud services, defined through the e-commerce law) are not a sector. They sit under Chapter 3 with their own, lighter duties, and the registration duty below does not apply to them. NSM’s guidance says so directly.
The law separates the groups, and the requirements differ:
- Chapter 2, §§ 6 to 8: providers of services important to society
- Chapter 3, §§ 9 to 12: digital service providers
- Chapter 4, §§ 13 to 17: supervision and administrative measures
Read which chapter applies to you before reading anything else. People routinely prepare against the wrong one.
Registration
If you provide a service listed in section 1 of the forskrift, you must register snarest (promptly) with NSM and your supervisory authority (forskriften § 5). The registration gives the organisation’s name, organisation number and contact details, the service, the sector, other countries where the service is offered, the affected geographic area, and any later change to these. The supervisory authority is your sector authority, or NSM where none exists. No incident or audit triggers the duty. It starts when you are in scope. NSM’s guidance says missing registration can lead to an order under § 15.
The two clocks
Both are shorter than most incident processes assume.
24 hours. The law itself says only that notification must happen without undue delay (§§ 8 and 11). The numbers come from the forskrift. Under § 17, the notification goes to the supervisory authority, with a copy to the national contact point, no later than 24 hours after the provider became aware of the incident. The notification is updated within 72 hours.
The 24-hour sentence in § 17 names providers of services important to society. Forskrift § 2 exempts digital service providers with fewer than 50 employees and an annual turnover or balance sheet of no more than 10 million euro from the notification duty in § 17. Whether the 24 hours also reaches larger digital service providers is, in our reading, not settled by the text. Ask your supervisory authority.
One month. Within a month of the notification, the supervisory authority gets an incident report with updated information and the remedial measures taken.
In our reading, awareness is what starts the 24 hours, so waiting until you have confirmed or scoped the incident is a risk. That is our interpretation and not a quote from the law.
A 24-hour duty is an operational requirement. Someone must be able to reach the right authority out of hours, on a weekend, without first locating a person who knows how. If that path exists only in one person’s head, you do not have it.
What NIS2 will change, when it arrives
When NIS2 is implemented, the scope widens considerably. A figure of about 5,000 Norwegian entities is commonly cited, against a much smaller population today, but we found no primary source for it. Expected additions include public administration, waste management, postal and delivery services, food production, and manufacturers of critical technology.
NIS2’s own size test for medium and large entities is at least 50 employees or turnover above 10 million euro, within a covered sector. Treat that as a planning assumption, because the Norwegian implementation has not been written, and until it exists the thresholds that matter are the ones in the law you are already under.
The likely sequence is EEA incorporation, a Norwegian law, entry into force, then transition. None of those steps has a date.
What to do now
The useful position is neither “NIS2 does not apply so there is nothing to do” nor “buy a NIS2 readiness assessment”. Both are wrong, one expensively.
1. Establish which chapter you are under, if any. Sector first, then the service in the forskrift’s list, then the threshold. This is a half-day of reading and not a consulting engagement, and an error here undermines everything downstream.
2. Register, if you provide a listed service. With NSM and your supervisory authority, promptly. It is the one obligation with no technical component.
3. Do the risk assessment the law requires. Scope it to the networks and information systems used to deliver the service in scope (law § 7).
4. Build the 24-hour path and test it. Write down who notifies, to whom, through which channel, with what information, and run it on a Saturday against a fictional incident. A notification path that has never been walked is a document and not a capability.
5. Prepare the one-month report format in advance. Writing a regulatory report for the first time during an incident is how deadlines get missed.
6. Cover the management duties in the forskrift. Sections 6, 13 and 14 add a management system reviewed annually and signed off by the head of the business, contingency plans with exercises, and supplier follow-up.
7. Build to the measures and ignore the acronym. Risk assessment, incident handling, business continuity, supply chain, access control, multi-factor authentication, encryption, logging and training are common ground between NIS1 and NIS2. Work you do there survives the transition. NIS2-specific paperwork may not, because the Norwegian text does not exist yet.
Why this article exists
An obligation with a dull name draws less attention than a future obligation with a familiar one. The cost lands on the organisation that prepared for a directive it is not yet subject to and missed a registration duty it was.
Sources
- NSM, Ny digitalsikkerhetslov i Norge, entry into force and which directive is implemented
- Lovdata, Lov om digital sikkerhet (digitalsikkerhetsloven), LOV-2023-12-20-108
- Lovdata, Forskrift om digital sikkerhet (digitalsikkerhetsforskriften), FOR-2025-06-20-1131
- NSM, Veileder i digitalsikkerhetsloven og -forskriften, U-25-132
- EFTA, EEA-Lex factsheet for Directive (EU) 2022/2555
- Stortinget, EU/EØS-nytt, 28 January 2026
Statutory text governs. Where this article and the law disagree, the law is right and we want to hear about it. We have not had this reviewed by a lawyer, so treat it as a reading guide and confirm anything you will act on with your supervisory authority or counsel.