NIS2

Understand NIS2: directly or indirectly covered?

EU-flag med NIS2-logo – fokus på it sikkerhed, compliance, it drift, it rådgivning og NIS2 hos IT Forum Gruppen.

With the NIS2 directive coming into force on July 1, 2025, Danish companies face new requirements for IT security and risk management. Many are aware that the directive includes companies in critical sectors, but fewer know that it can also affect businesses indirectly. Here we give you an overview of what it means to be directly or indirectly affected by NIS2.

What is NIS2?

NIS2 is an update of the EU Network and Information Security Directive. It aims to strengthen IT security across member states by setting requirements for companies in sectors such as energy, health, transportation and finance. The directive also sets out sanctions for non-compliance, including fines and injunctions.

Directly covered: If you are a key player

Companies directly covered by NIS2 typically operate in critical sectors where their operations are important to the functioning of society. Examples include:

  • Energy suppliers
  • Water utilities
  • Financial Institutions
  • Healthcare sector

These companies must meet a number of requirements, such as risk assessments, implementing security measures and reporting security incidents.

Indirectly covered: An overlooked risk

Even if your business is not in a critical sector, you may still be indirectly affected. This is especially true if your company provides services or products to a company that is directly affected. Examples include:

  • Subcontractors of IT systems
  • Consulting companies
  • Logistics and transportation companies
  • Facility management

If your customers are subject to NIS2, they will often require their suppliers to comply with similar IT security standards. This means that you as a subcontractor may face certification, risk management and reporting requirements.

EU-flag og NIS2 – illustration af NIS2 direktiv, it sikkerhed, it drift, it rådgivning, it support erhverv, it outsourcing og compliance hos IT Forum Gruppen.

What does this mean for your business?

Being indirectly covered by NIS2 means that you should consider:

  1. The level of security in your organization - Are your systems and processes robust enough to meet requirements
  2. Customer demands - Prepare for major customers to ask questions and make demands on your IT security.
  3. Compliance - Consider implementing standards like ISO 27001 to strengthen your credibility as a supplier
How to get started 👇
  1. Map your customers and suppliers: Are you part of a critical value chain?
  2. Review your IT security: Do you have the necessary measures in place?
  3. Consider external advice: Many companies choose to get help navigating the requirements of NIS2.
What can you do now?

While your company may not be directly affected by NIS2, indirect impact can have a big impact on your business. By taking responsibility for your IT security now, you can not only ensure compliance, but also strengthen your position as a trusted business partner.

At IT Forum Gruppen, we offer advice to help your business navigate the requirements and opportunities that NIS2 brings.

We can help you with:

  • Mapping your business risk profile
  • Implementing the right IT security measures
  • Certification preparation
  • Ongoing advice and support to keep you ahead of the game

Want to know more about how we can help your business become compliant while strengthening your IT security? Contact us today for a no-obligation conversation about your needs.

Read more here or Contact us now

Scroll to Top