The Danish implementation of a framework for supervision of the financial sector under The DORA Regulation and NIS2 Directive

Published 7 May 2024

PrintCategory: Financial Regulation

On 2 May 2024, the Danish Parliament adopted an amendment to the Danish Financial Business Act (the “Act”) to provide the Danish FSA with a legal framework for supervision of the financial sector under the DORA Regulation (“DORA”) and the NIS-2 Directive (“NIS2”).

In January 2023, DORA and NIS2 entered into force and set standards for a modernization of the rules for IT and cybersecurity in the financial sector. NIS2 shall apply from 18 October 2024 and DORA from 17 January 2025.

The Act adopted on 2 May 2024, implements changes to the Danish Financial Act necessary to ensure an effective pan-European regulation on cybersecurity and supervision. The regulation will apply to financial entities subject to the supervision of the Danish FSA, including Funds of alternative investment funds (FAIFs).

The authority delegated to the Danish FSA

The Danish FSA as the designated authority

With the Act, the Danish FSA is designated as the competent authority to ensure financial entities’ compliance with the provisions of DORA and a legal basis is established to sanction infringements of the regulation. Further, the Act provides the Danish FSA with the framework to supervise IT and the cybersecurity of all relevant companies in the financial area providing digital infrastructure and management of IT services within the financial sector.

Covering the financial sector under DORA and NIS2 

DORA applies to financial entities, and it modernises and harmonises the rules within IT and cybersecurity across the financial sector; the regulation lays down rules to strengthen the resilience of enterprise IT technology, thereby reducing the risk of cyberattacks, and it aims to limit the damage and prioritize the resumption of activities in case of a cyberattack.

DORA does not regulate joint data centres and IT operators of retail payment systems which instead are covered by the NIS2 and its more general rules applicable to digital infrastructure and management of IT services. Therefore, the Act also implements rules of NIS2 for common data centres and IT operators of retail payment systems. When combining NIS2 with the requirement under DORA, the rules ensures that uniform requirement continue to apply to undertakings operating in the financial sector and, thereby, support companies that use the provision of IT services of operators of digital financial infrastructure in complying with DORA.

Authorisation to the Danish FSA to designate operators and set rules.

With the Act, the Danish FSA is authorized to designate common data centres and IT operators of retail payment systems as operators of financial digital infrastructures and the Danish FSA is authorized to set detailed rules for operation of financial digital infrastructure. With the authorization, the Danish FSA is able to ensure that the rules for digital financial infrastructure operators complies with requirements that may be established pursuant to delegated acts under NIS2 or that stem from DORA.

The Act also adopt amendment to incident reporting rules (as implemented with the first NIS directive) to be replaced by a requirement to report major IT-related incidents and voluntarily notify significant cyber threats to competent authorities under DORA. It is expected that the Centre for Cyber Security will be designated by the Danish FSA as the Danish national center for receipt of reporting within the financial sector.

The effective date

The Act will be effective from 1 Juli 2024. Certain provisions of the Act will have effect at later stages during 2024 and when the DORA applies on 17 January 2025.

Next steps

We still monitor the regulation issued by the Danish FSA to determine its impact on companies in the private equity market.

Tags:  DORANIS2


Also tagged ‘DORA’

27 Nov 2024 Updates

The Danish FSA has published the designated IT suppliers to financial companies subject to NIS2 and under the supervision of the Danish FSA

The Danish FSA has appointed a number of IT suppliers as operators of financial digital infrastructure to which NIS2 applies.

CybersecurityDORANIS2The Danish FSA
18 Oct 2024 Financial RegulationUpdates

The NIS2 Directive now applies to designated IT suppliers to financial companies as appointed by the Danish FSA

As of today, the NIS-2 Directive (“NIS2”) applies to the most important IT suppliers to the financial sector.

DORANIS2

Other updates

13 Jun 2025 AIFsUpdates

Danish implementation of AIFMD II adopted

On 11 June 2025, the Danish Parliament adopted the bill (L 193B) for implementing the AIFM Directive II into Danish law.

AIFMDAIFMD reviewCross-BorderDanish RegulationRisk Management
20 May 2025 AIFsUpdates

Proposal on Danish implementation of AIFMD II

On 9 April 2025, the Danish Government presented a proposal for amendments in the Danish financial regulation, including the Danish Alternative Investment Fund Managers (“AIFM”) Act.

AIFMDAIFMD reviewCross-BorderDanish RegulationRisk Management
12 May 2025 Impact and ESGUpdates

Main recommendations from the report on advancing sustainable finance

The work performed by the Platform on Sustainable Finance has focused on developing technical criteria for new economic activities and reviewing activities included in the Commission Delegated Regulation (EU) 2021/2139 of 4 June 2021 supplementing Regulation (EU) 2020/852.

Sustainability
12 May 2025 Impact and ESGUpdates

Thematic review of engagement information

The Danish Financial Supervisory Authority (the “DFSA”) has conducted a thematic review of six pension companies and investment managers and their engagement information (active ownership).

SFDRSustainability
6 May 2025 Impact and ESGUpdates

An update on the stop-the-clock proposal and the ESRS simplification mandate

On 29 April 2025, a majority of the Danish Parliament agreed on the “stop-the-clock” directive which will go to a formal vote in the fall to adopt the proposal into Danish legislation.

CSDDDCSRDSustainability
2 May 2025 AIFsUpdates

AIFMs: Marketing under increased regulatory focus

The Danish Financial Supervisory Authority (FSA) has published a thematic report on how managers of alternative investment funds and investment management companies market their investment funds.

KID / PRIIPSMarketingThe Danish FSA