The NIS2 Directive now applies to designated IT suppliers to financial companies as appointed by the Danish FSA

Published 18 October 2024

PrintCategory: Financial Regulation

As of today, the NIS-2 Directive[1] (“NIS2”) applies to the most important IT suppliers to the financial sector.

While the implementation of NIS2 in general has been postponed to 2025 take effect in Denmark, the Danish Financial Supervisory Authority (the “Danish FSA”) was already in May 2024, with a new Chapter 19 c of the Financial Business Act, provided with the legal framework for supervision of the financial sector under the DORA Regulation[2] and NIS2.

The Danish FSA informs that they now have appointed a number of IT suppliers as operators of financial digital infrastructure to which NIS2 applies. The Danish FSA will publish which IT suppliers have been appointed when the appointments are final, i.e. when the companies’ appeal period has finally expired. The statement from the Danish FSA can be found here.

The purpose of NIS2 is to strengthen cybersecurity by setting requirements for financial companies’ IT security, their reporting of security incidents, and risk management. Find more information on the authority given to the Danish FSA pursuant to a new Chapter 19c of the Danish Financial Business Act on Mazanti Pulse.

NIS2 does not apply to financial undertakings covered by the DORA Regulation. For these companies, the DORA Regulation will instead apply from 17 January 2025.

 

[1] Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union.

[2] Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on Digital Operational Resilience for the financial sector, and

Tags:  DORANIS2


Also tagged ‘DORA’

27 Nov 2024 Updates

The Danish FSA has published the designated IT suppliers to financial companies subject to NIS2 and under the supervision of the Danish FSA

The Danish FSA has appointed a number of IT suppliers as operators of financial digital infrastructure to which NIS2 applies.

CybersecurityDORANIS2The Danish FSA
7 May 2024 Financial RegulationUpdates

The Danish implementation of a framework for supervision of the financial sector under The DORA Regulation and NIS2 Directive

On 2 May 2024, the Danish Parliament adopted an amendment to the Danish Financial Business Act to provide the Danish FSA with a legal framework for supervision of the financial sector under the DORA Regulation and the NIS-2 Directive.

DORANIS2

Other updates

12 May 2025 Impact and ESGUpdates

Main recommendations from the report on advancing sustainable finance

The work performed by the Platform on Sustainable Finance has focused on developing technical criteria for new economic activities and reviewing activities included in the Commission Delegated Regulation (EU) 2021/2139 of 4 June 2021 supplementing Regulation (EU) 2020/852.

Sustainability
12 May 2025 Impact and ESGUpdates

Thematic review of engagement information

The Danish Financial Supervisory Authority (the “DFSA”) has conducted a thematic review of six pension companies and investment managers and their engagement information (active ownership).

SFDRSustainability
6 May 2025 Impact and ESGUpdates

An update on the stop-the-clock proposal and the ESRS simplification mandate

On 29 April 2025, a majority of the Danish Parliament agreed on the “stop-the-clock” directive which will go to a formal vote in the fall to adopt the proposal into Danish legislation.

CSDDDCSRDSustainability
2 May 2025 AIFsUpdates

AIFMs: Marketing under increased regulatory focus

The Danish Financial Supervisory Authority (FSA) has published a thematic report on how managers of alternative investment funds and investment management companies market their investment funds.

KID / PRIIPSMarketingThe Danish FSA
2 May 2025 Financial RegulationUpdates

The European Commission has launched a targeted consultation on obstacles to capital markets integration across the EU

The European Commission has launched a targeted consultation to gather feedback on obstacles to capital markets integration across the EU.

ComplianceCross-Border
1 May 2025 Corporate RegulationOther Compliance RequirementsUpdates

The Danish Parliament has adopted regulation to implement the NIS2 Directive and the CER Directive

On April 29, 2025, on the day where major parts of France, Spain, and Portugal suffered severe utility breakdowns, the Danish Parliament adopted the bills for implementing the NIS2 Directive and the CER Directive.

CERCritical SectorsCybersecurityNIS2