5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

Norway

Why NIS2 does not apply in Norway — and what applies instead

NIS2 does not apply in Norway. Directive (EU) 2022/2555 is marked EEA-relevant, but it has not been incorporated into the EEA Agreement — there is no EEA Joint Committee decision, and Norway is therefore under no obligation to implement it. What applies instead is the digitalsikkerhetslov (Digital Security Act), in force 1 October 2025, and it implements NIS1. The difference is not academic. Scope, duties and sanctions are all different, and a group that plans its Norwegian entity against NIS2 is planning against the wrong instrument.

Also available in Norsk

How Barzel applies here Start free with BarzelVault

Why does NIS2 not apply in Norway?

Because an EU directive does not become Norwegian law by being marked EEA-relevant. The marking says only that the EU considers the act relevant to EEA cooperation. Two further things then have to happen, in order: the act must be incorporated into the EEA Agreement by a decision of the EEA Joint Committee, and it must then be implemented in Norwegian law. For NIS2 the first step has not happened.

This is the part that English-language coverage misses, and it is worth being exact about because the mechanics are unfamiliar to anyone whose mental model is a member state. There is no direct effect in the EEA EFTA states, and there is no automatic transposition deadline running against Norway. Until the Joint Committee acts, the directive is simply not part of the legal order. Stortinget's EU/EØS service recorded on 28 January 2026 that NIS2 remains under consideration for incorporation into the EEA — in the same note that reported the Commission's cybersecurity package of 20 January 2026, which proposes targeted amendments to NIS2 and a regulation replacing the 2019 Cybersecurity Act.

The formulation NIS2 applies in Norway via the EEA is wrong in both halves: the directive is not incorporated, and the EEA Agreement does not operate automatically. The consequence is practical rather than terminological. It makes organisations plan against the wrong scope, the wrong thresholds and the wrong enforcement apparatus.

What does the Digital Security Act actually require?

The Act covers seven sectors: energy, transport, health, water supply, banking, financial market infrastructure and digital infrastructure. That is the NIS1 perimeter. It is materially narrower than NIS2, which in the member states also reaches waste water, waste management, postal and courier services, food, chemicals, manufacturing, space and a range of digital services.

DutyContent
RegistrationThe entity registers with NSM (the National Security Authority) and with its sector authority.
Incident notificationSignificant incidents must be notified within 24 hours.
Security measuresSound technical and organisational measures, proportionate to the risk.

There is no separate statutory duty on the board to approve the measures of the kind the Danish and German transpositions impose. That absence is a design fact, not an oversight to be argued around: if a group wants board-level approval evidenced in its Norwegian entity, the requirement has to come from group policy.

Which entity in your group is actually caught?

This is the question the Norwegian-language material does not need to answer and a group does. The short version: scope attaches to the entity that provides the service, in the territory concerned — not to the group.

Three consequences follow, and they are the ones that get mishandled in practice.

A Norwegian entity is not pulled into NIS2 by its parent. If the ultimate parent is in Frankfurt and is squarely within the German BSIG regime, that does not extend NIS2 to the Norwegian subsidiary. The Norwegian entity is tested against the Norwegian Act and the seven sectors.

An EU-established subsidiary is not taken out of NIS2 by a Norwegian parent. The reverse error is more expensive. A group headquartered in Oslo with operating companies in Denmark, Germany and Estonia has three separate NIS2 regimes to satisfy, each with its own thresholds, its own deadlines and its own management duties — and a Norwegian head office changes none of that.

Establishment, not customer location, is the test for the EU entities. Selling into the EU from Norway does not by itself make a Norwegian entity subject to a member state's NIS2 law. What it does do is bring the second mechanism into play, below.

How does Norway compare with the EU transpositions?

CountryInstrumentIn forceManagement dutyStatus
Norway Digitalsikkerhetsloven 1 Oct 2025 No separate statutory approval duty for the board NIS1. NIS2 not incorporated into the EEA Agreement; no proposition
Denmark NIS 2-loven (LOV nr 434 af 06/05/2025) 1 Jul 2025 The management body must approve the measures NIS2 transposed
Germany BSIG, NIS2UmsuCG version 6 Dec 2025 Section 38: the Geschäftsleitung must implement and monitor NIS2 transposed
Belgium NIS2 law of 26 April 2024 18 Oct 2024 — NIS2 transposed
Estonia Cybersecurity Act amendment 1 Jan 2026 Approve, monitor, and mandatory training NIS2 transposed
Slovakia National NIS2 transposition 1 Jan 2025 — NIS2 transposed

The management column is filled in only where the duty is verified in the statutory text. Denmark and Germany show the direction of travel: responsibility is placed explicitly on the management body rather than on the security function. In Denmark the supervisory authority may, for væsentlige enheder (essential entities), temporarily prohibit an individual from exercising management functions. Norway currently has no equivalent, and nor does Estonia, which transposed NIS2 without adopting that measure.

Why do NIS2 requirements reach Norwegian entities anyway?

This is the most useful point on the page. A Norwegian entity is not subject to NIS2 as such — and the requirements arrive regardless, by contract.

  • Group structure. A subsidiary or affiliate established in an EU member state is directly within that state's NIS2 law, with its thresholds, its deadlines and its management liability. A Norwegian head office does not change this.
  • Supply chain. Entities within NIS2 must manage security in their supplier relationships. They discharge that duty by imposing requirements on their suppliers. A Norwegian supplier therefore meets NIS2-shaped requirements in procurement questionnaires, security annexes, audit clauses and notification deadlines — with no Norwegian provision requiring any of it.

The practical consequence for a group security function: Norwegian suppliers and Norwegian entities selling to EU customers should plan against NIS2 expectations even though no Norwegian rule imposes them. It is a commercial precondition rather than a legal requirement, and in practice equally binding. What it is not is a reason to write NIS2 applies to our Norwegian entity in a control description. State the source of the obligation correctly — statute for the EU entities, contract for the Norwegian one — because the two behave differently when something goes wrong, and only one of them can be renegotiated.

What must a group security function do differently for the Norwegian entity?

Four differences are worth designing for.

Keep the Norwegian entity out of the NIS2 scope register. Groups typically maintain one list of entities in scope of NIS2 with their categories and deadlines. Putting the Norwegian entity on it as essential or important imports categories that do not exist in Norwegian law and will not survive contact with a Norwegian regulator. Keep a separate line for the digitalsikkerhetslov, with the seven-sector test recorded against it.

Run one notification standard, not two. The Norwegian Act requires notification of significant incidents within 24 hours. NIS2 requires an early warning within 24 hours and further reporting after that. The deadlines are close enough that operating a single internal escalation standard against the tightest one is simpler than maintaining a per-country matrix — provided the external filings still go to the right authority in the right form.

Supply the board control by policy. Where a Danish or German entity has a statutory management duty and the Norwegian entity does not, a group that documents board approval only where a statute requires it ends up with an evidence gap in Norway. It is cheaper to run the same approval and training cycle everywhere than to explain the gap later.

Treat the contract stack as the live obligation. For most Norwegian entities in a multinational, the enforceable cyber requirements today sit in customer contracts, not in Norwegian statute. That is where the audit rights and the notification clocks actually are, and it is the stack that has to be inventoried.

What does the 24-hour deadline mean for automated processes?

The 24-hour deadline under the digitalsikkerhetslov is the operational point for any organisation running automated or agent-driven processes. One day is not long to establish what happened.

The difficulty appears when autonomous processes have carried out a series of actions. If you cannot determine within the first day which of them were authorised, the notification goes out on an uncertain basis — with caveats that have to be corrected later, and with a regulator whose first picture of the incident is an incomplete one. Reconstruction speed sets notification quality. For a group, add the hours the escalation path itself consumes between a Norwegian entity and the people who can answer.

What decides this is not log volume but whether the records answer one question quickly: who or what permitted this operation, and under which rule. The general requirements are set out under AI agent audit trails, and the approval side under approving AI actions.

What is still undecided?

The open items are themselves planning information.

  • NIS2 and the CER Directive in Norwegian law. The government has been assessing implementation since 2024. There is no proposition. The picture is complicated by the Commission's January 2026 proposal to amend NIS2 alongside a revised Cybersecurity Act — Norway risks implementing a directive that is under revision.
  • The AI Act. The EU AI Regulation is likewise not incorporated into the EEA Agreement and does not apply in Norway. A draft Norwegian AI act went to consultation on 30 June 2025, closing in autumn 2025 with about 150 responses. Nkom is proposed as coordinating supervisory authority and single point of contact, Digdir is to run the regulatory sandbox under the KI Norge arena, and Norsk akkreditering takes the technical accreditation role. No notifying authority has been designated. After Regulation (EU) 2026/1744, in force 27 July 2026, the government announced on 4 August 2026 a further consultation round in autumn 2026, with the ambition of a proposition in spring 2027. Until then AI use in Norway is governed by existing data protection, criminal and copyright law.
  • The e-invoicing regulations. The Act is passed; the forskrifter from the Directorate of Taxes were due by 15 December 2026. See the e-invoicing mandate for what that leaves open.

Which dates should be planned as one project?

DateWhatStatus
1 Jan 2027Duty to issue B2B e-invoices (LOV-2026-06-19-39, sanctioned 19 June 2026)Enacted; regulations outstanding
1 Jan 2027SAF-T version 1.40 mandatory (1.30 applies to 31 December 2026)Set; SAF-T still on request, not periodic
Spring 2027Norwegian AI act to the StortingAmbition, not a decision
Not setNIS2 and CER in Norwegian lawNo proposition
1 Jan 2030Duty to receive e-invoices and mandatory digital bookkeepingEnacted

How do you work out which regime binds each entity?

Seven steps, done once and diarised for review. Work from the legal entity register rather than the site list, because scope attaches to the entity providing the service. Test the Norwegian entity against the seven sectors rather than against the NIS2 annexes — testing it against the annexes produces false positives in waste, post, food and manufacturing. Test every EU-established entity against its own member state's law, country by country, because the transpositions differ. Then separate what the law requires from what the customer contracts require, and record both. If the Norwegian entity is in scope, record who registered it with NSM and the sector authority, when, and which services were declared — the declaration is what the 24-hour duty later attaches to. Set one internal escalation clock to the shortest deadline binding any entity. Finally, diarise a review: the incorporation question is open and the directive itself is being amended.

In practice

BarzelVault applies policy and approval thresholds before an operation executes and issues a signed receipt for each one, so the authorisation basis exists while the 24-hour clock is running rather than being reconstructed afterwards. BarzelOps runs governed cross-system workflows with durable state and approval checkpoints where the process spans several entities.

How Barzel applies here

Frequently asked questions

Does NIS2 apply in Norway?

No. Directive (EU) 2022/2555 has not been incorporated into the EEA Agreement, and there is no EEA Joint Committee decision. Stortinget's EU/EØS service recorded on 28 January 2026 that it remains under consideration. The digitalsikkerhetslov, in force 1 October 2025, implements NIS1.

What does the Digital Security Act require?

Seven sectors are covered: energy, transport, health, water supply, banking, financial market infrastructure and digital infrastructure. Entities register with NSM and their sector authority, notify significant incidents within 24 hours, and maintain measures proportionate to the risk.

Is our Norwegian subsidiary caught by NIS2 because the parent is?

No. Scope attaches to the entity providing the service in the territory concerned. Equally, a Norwegian parent does not take an EU-established subsidiary out of that member state's NIS2 law.

Why do NIS2 requirements still reach us in Norway?

Through group structure and through the supply chain. Entities within NIS2 must manage supplier security and do so by imposing requirements on suppliers, so the obligation arrives with the contract rather than with Norwegian law.

Does the Norwegian Act impose a board approval duty?

Not as a separate statutory duty comparable with the Danish or German provisions. A group wanting equivalent evidence in its Norwegian entity has to require it by policy.

When will NIS2 enter Norwegian law?

Unsettled. Assessment has run since 2024 with no proposition, and the Commission proposed amendments to NIS2 in January 2026 alongside a revised Cybersecurity Act.

Related reading

In practice

Contain the incident first, prove what happened second — inside the reporting window.

Reporting clocks run in hours, and management liability turns on whether controls were implemented and supervised, not merely approved. Barzel isolates credentials, cuts an agent off in one action and keeps signed receipts of what ran — the material a notification and a board report are written from.

In forceDigitalsikkerhetsloven in force since 1 October 2025

BarzelVault

The AI action firewall: decide what an agent may do before it does it.

  • Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
  • Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
  • Credential isolation, spend and action limits, and an emergency kill switch.

Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

BarzelOps

Governed workflow automation across the systems that run the business.

  • Durable, idempotent execution: a timeout is retried once, never filed twice.
  • Human approval checkpoints that pause the workflow and resume it.
  • Isolation per entity or client, signed evidence receipts and a portable manifest; HubSpot, Xero, Gmail, Google Drive and Slack.

Free tier: 100 calls a dayPaid plans from $19 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Enterprise: written quote by email within two business days. No sales call.


Sources

  1. Lov om digital sikkerhet (digitalsikkerhetsloven), LOV-2023-12-20-108 — lovdata.no.
  2. Ikraftsetting av lov 20. desember 2023 nr. 108 om digital sikkerhet (digitalsikkerhetsloven), FOR-2025-06-20-1088 — lovdata.no.
  3. Forskrift om digital sikkerhet (digitalsikkerhetsforskriften), FOR-2025-06-20-1131 — lovdata.no.
  4. Nasjonal sikkerhetsmyndighet, Veileder i digitalsikkerhetsloven og -forskriften.
  5. Stortingets EU/EØS-tjeneste, Cybersikkerhetspakke lagt frem, 28 January 2026 — NIS2 under consideration for incorporation into the EEA.
  6. Directive (EU) 2022/2555 (NIS2).
  7. Denmark: LOV nr 434 af 06/05/2025 (NIS 2-loven), in force 1 July 2025.
  8. Germany: BSIG section 38, NIS2UmsuCG version, in force 6 December 2025.
  9. Belgium: the NIS2 law of 26 April 2024, in force 18 October 2024. Estonia: transposed 1 January 2026 (RIA). Slovakia: in force 1 January 2025.
  10. Nkom, KI-forordningen og regulering av kunstig intelligens; Regulation (EU) 2026/1744; Regjeringen.no, 4 August 2026.
  11. LOV-2026-06-19-39, cf. Prop. 44 L (2025–2026); Skatteetaten, SAF-T Financial documentation.

This article is for information and does not constitute legal advice. The Norwegian text of the instruments cited is the binding one. Position as at 3 September 2026.