Article content
In briefShow moreShow lessOn 20 December 2023, Norway adopted the Digital Security Act, its first cross-sector statute setting baseline digital security requirements for organisations of particular importance to society.
- On 20 December 2023, Norway adopted the Digital Security Act, its first cross-sector statute setting baseline digital security requirements for organisations of particular importance to society.
- The framework addresses services in energy, transport, health, water supply, banking, financial market infrastructure and digital infrastructure, among other sectors.
- Adopted as Norwegian law on 20 December 2023 but not yet in force; it later commenced on 1 October 2025. It implements NIS1, not NIS2.
What happened
On 20 December 2023, Norway adopted the Digital Security Act, its first cross-sector statute setting baseline digital security requirements for organisations of particular importance to society. The Act implements the EU's first NIS Directive and covers designated essential and digital services.
The framework addresses services in energy, transport, health, water supply, banking, financial market infrastructure and digital infrastructure, among other sectors. Online marketplaces, cloud computing services and search engines are also among the digital service categories. Detailed thresholds and categories still needed to be specified in regulations.
What this means for organisations
At its core is risk-based accountability. Organisations within scope must implement appropriate and proportionate technical and organisational security measures. They must also report serious incidents. For senior management, this means integrating digital security into governance, assigning clear roles, maintaining current risk assessments, controlling supplier dependencies, and establishing plans to detect, manage and report incidents.
Adoption did not equal application. When the Act was promulgated, supplementary regulations and a commencement decision were still outstanding. Organisations could use that period to determine whether they were likely to be in scope, map critical systems and suppliers, and compare existing management systems with the anticipated requirements.
It is also essential to distinguish NIS1 from NIS2. The Norwegian Act implemented NIS1. The EU's NIS2 Directive expanded both scope and obligations, but required a separate EEA and Norwegian process. Adoption of the Digital Security Act therefore did not mean that NIS2 had already become Norwegian law.
Sources
Lovdata: “Lov om digital sikkerhet,” 20 December 2023.
Norwegian Government: “Prop. 109 LS (2022–2023),” 5 May 2023.
For discussion
Which decisions, defaults or supplier dependencies in our organisation should we examine first in light of this development?

