What security requirements and reporting deadlines follow from NIS2?
Entities in scope must have risk-based security management measures, including risk analysis, incident handling, business continuity, supply chain security, access control and cryptography, and management is accountable for putting them in place. A significant incident is notified to the authority within 24 hours, reported with an updated assessment within 72 hours and finally reported within one month. Norway implements the requirements through the Digital Security Act and its regulation, building on the NIS framework in the EEA.
Source
- Reference
- Directive (EU) 2022/2555 Articles 21 and 23, implemented in the Digital Security Act
- Acts
- —
- Area
- Data protection and trust services
- Read date
- 2026-09-09
Other acts in the same area
- Personal Data Act · LOV-2018-06-15-38
- Act on electronic trust services · LOV-2018-06-15-44
Questions and answers
Ready-made pack
GDPR incident pack
total 98.75 € (about 107 USD)
The basis for what you just read, ready for the file.
What you need once a personal data breach has happened: the notification articles, the risk profile and a ready evidence chain.
Evidence chain, hash and read date per row. One-time purchase, delivered instantly.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.