Article content
In briefShow moreShow lessNorway's Digital Security Act and regulations entered into force on 1 October 2025 without a transitional period.
- Norway's Digital Security Act and regulations entered into force on 1 October 2025 without a transitional period.
- The regulations described 28 categories of essential services.
- Binding Norwegian law from 1 October 2025 with no transition period. It implements NIS1; NIS2 remained a separate future EEA/Norwegian process.
What happened
Norway's Digital Security Act and regulations entered into force on 1 October 2025 without a transitional period. Designated essential and digital service providers had to meet baseline security requirements and report serious incidents from day one.
The regulations described 28 categories of essential services. The framework placed digital security within ordinary management accountability and required proportionate measures based on organisational risk.
Legal status in Norway
Binding Norwegian law from 1 October 2025 with no transition period. It implements NIS1; NIS2 remained a separate future EEA/Norwegian process.
What the sources clarify
The regulations listed 28 categories of essential services, making scope depend on the actual service, size and organisational role. Covered providers could not rely on a later transition period. From day one they needed evidence of a management system, proportionate technical and organisational measures and a working notification process. The Act implemented the first NIS Directive. NIS2 work therefore could not be blended into documents as though it were already a Norwegian duty. Management needed to record which legal framework supported its scope assessment, incident threshold and supplier requirements.
The scope assessment should map each of the 28 service categories to the legal entity, size and service delivered in Norway. The organisation can then measure its management system, safeguards and notification route against duties that actually entered into force. A separate track may prepare for NIS2, but documents must identify the directive and Norwegian provision supporting each requirement.
Practical implications
The first management review should end with a signed scope decision, a list of critical services and proof that notification was exercised. Unsettled NIS2 expectations can remain in a separate future track. This prevents the organisation overlooking current duties while waiting for newer legislation.
Sources
Norwegian Government: “Ny lov om digital sikkerhet trer i kraft,” 1 October 2025.
Lovdata: “Lov om digital sikkerhet,” 20 December 2023.
For discussion
Which scenario should we exercise first?

