Once a company becomes aware of a significant incident, it must report the incident within the prescribed timeframes. This is done as follows:
Reports of significant incidents must be submitted via virk.dk. The report is automatically forwarded to the relevant sectoral authorities and the CSIRT (Computer Security and Incicent Response Team). The CSIRT handles IT-security incidents and reacts on as well as offers support for affected entities in the event of an incident.
The European Commission has adopted an implementing regulation that sets out specific requirements for incident reporting, including definitions of what constitutes a significant incident (Articles 3–14). These requirements are relevant for companies within the digital sector but vary depending on which services the company provides.
You can read more about the implementing regulation on the page NIS 2 – Regulatory Framework
The NIS 2 Law’s definition of a significant incident is supplemented by Implementing Regulation No. 2024/2690. Here, an incident is considered significant in relation to entities covered within the digital sector if one of the following criteria is met:
If the above-mentioned general criteria for the digital sector is not met, but the entity falls under one of the below categories, and the incident meets one of the specific criteria for the entity category, the incidents is seen as significant.
For inquiries regarding NIS 2 registration for entities in the digital sector, please contact the Agency for Digital Government at: NIS@digst.dk