Operations
Norway's Digital Security Act: What does it mean if you're not in a critical sector?

Norway's Digital Security Act (digitalsikkerhetsloven) came into force on 1 October 2025 and applies to organisations that provide essential services. If you run an online shop, a non-profit or a school, you are probably not covered directly. The Act can still affect you, because the organisations it does cover must set security requirements for their suppliers. If you supply a power producer, a municipality with a waterworks or a hospital trust, or you depend on websites, integrations and hosting delivered by others, this is worth ten minutes. Here are the questions we hear most often, with answers.
Questions and answers on the Digital Security Act
What is the Digital Security Act?
The Act on Digital Security was passed on 20 December 2023 and came into force on 1 October 2025, together with the accompanying Digital Security Regulations. It implements the EU's first Network and Information Security Directive (NIS1) in Norwegian law. It sets requirements for security measures and for reporting serious incidents. The Norwegian National Security Authority (NSM) is the national point of contact and response centre, and supervises sectors that have no regulator of their own.
Who is covered directly?
Two groups. The first is providers of essential services in energy, transport, health, water supply, banking, financial market infrastructure and digital infrastructure. The second is providers of certain digital services: online marketplaces, search engines and cloud computing services. According to NSM (in Norwegian), covered organisations must register their services with NSM and the relevant sector authority.
If you are not in one of these groups, the Act places no direct obligations on you.
What does the Act require of those it covers?
Four things, in short:
- Governance. The organisation must have a management system for digital security, and senior management is responsible.
- Risk assessment. Threats and vulnerabilities must be mapped, including dependencies on others.
- Security measures. Measures must be proportionate to the risk and cover organisational, technical, physical and personnel security.
- Incident reporting. Serious incidents must be reported within 24 hours, according to NSM.
The Regulations also make the organisation responsible for security in its supply chain. This is the point that reaches you even if you are not covered.
I'm not in a critical sector. Why should I care?
Because responsibility follows the contracts. A covered organisation cannot simply pass the risk on to a supplier and leave it there. It must make sure that suppliers who affect its security work in a way that meets the requirements. In practice that means security clauses in contracts, questionnaires in tenders and the right to audit the supplier.
If you provide services, software or operations to a covered customer, you will get these requirements sooner or later. Many of them make sense for everyone, so it pays to have your answers ready before the customer asks.
Why are websites and integrations part of this?
A website is rarely just a brochure. For many organisations it connects to the CRM, ERP, payment provider, login services and line-of-business systems. An integration that reads or writes data to an internal system is a way in. A CMS with outdated plugins, a shared admin account or an API key that is never rotated are classic weak points.
So when a covered organisation maps its dependencies, the web agency, the hosting provider and the integration partner end up on the list. The same goes for you as a customer: your suppliers are part of your risk, whether or not the Act covers you.
[QA: legg inn eget eksempel fra PlatOps på hvordan sikkerhetskrav fra en kunde i regulert sektor har sett ut i praksis]
What about NIS2? Are stricter rules on the way?
Probably, but nobody knows when. NIS2 replaced NIS1 in the EU from October 2024 and applies to medium-sized and large organisations in 18 sectors, including waste and wastewater, postal services, manufacturing of critical products and public administration. The directive also makes top management more clearly accountable. According to the European Commission, supply chain security is one of the areas member states must cover.
In Norway, NIS2 has not been incorporated into the EEA Agreement or into Norwegian law. The Storting's EU/EEA news service wrote in January 2026 (in Norwegian) that the government is looking into how the directive should be implemented, and that it is awaiting assessment for EEA incorporation. Meanwhile, the Commission has proposed targeted amendments to NIS2 as part of a new cybersecurity package. As of September 2026 we have found no Norwegian bill or public consultation on NIS2.
Once NIS2 reaches Norway, far more organisations will be covered directly, and even more indirectly as suppliers.
Is it true that registration starts on 1 July 2026 and supervision in October 2026?
Some commercial websites claim that NSM will open a registration portal on 1 July 2026 and start supervision from October 2026, linked to an expansion of the Act. We have not found this confirmed by NSM, on regjeringen.no or in Lovdata. The registration duty that exists today applies to organisations already covered by the Digital Security Act. Check dates like these with the primary sources before you plan around them.
What are NSM's basic ICT security principles, and do I have to follow them?
The basic principles are NSM's recommended measures for securing ICT systems, grouped into four categories: identify and map, protect and maintain, detect, and respond and recover. The current version is 2.1. They are recommendations, not legal requirements, if you are not covered. Many organisations in regulated sectors still use them as the yardstick for suppliers, so they are a good place to start if you want to know what your customer is going to ask.
What does data protection law have to do with this?
Quite a lot. The Digital Security Act is about keeping services running, while the GDPR covers personal data and applies to everyone, whatever the sector. If a supplier processes personal data on your behalf, you need a data processing agreement. The Norwegian Data Protection Authority says the more extensive and risky the processing, the more specific the agreement must be. The information security requirements in the GDPR and the Digital Security Act overlap to a large degree, so work on one helps with the other.
Where should I start?
Make a list of the suppliers with access to your systems or data: hosting, website, integrations, cloud services, CRM. Start with those that have admin access or process personal data, since that is where an incident does the most damage. Ask each of them the same questions and write down the answers. If you are a supplier to a covered organisation yourself, do the same exercise for your own business, so you can answer when the customer asks.
What to have in place with your supplier
- Multi-factor authentication (MFA) on all administrative access, in the CMS, with the hosting provider and in cloud services.
- Patching routines on a fixed schedule for the core system, plugins and dependencies, plus a plan for critical vulnerabilities that must be closed the same day.
- Logging of logins, changes and errors, kept long enough to investigate an incident after the fact.
- Incident response with a named contact person, agreed notification times and a description of what the supplier does in the first hours.
- Backups taken automatically, stored separately from production and tested with regular restores.
- A data processing agreement that sets out which personal data is processed, where it is stored and which subprocessors are used.
In PlatOps at Frontkom, my team and I run and maintain websites and integrations for clients across several sectors, and these are the points we go through when clients send us security requirements.
Sources
- Lov om digital sikkerhet (digitalsikkerhetsloven), Lovdata, 20 December 2023
- Ny digitalsikkerhetslov i Norge, Norwegian National Security Authority, 2025
- Grunnprinsipper for IKT-sikkerhet 2.1, Norwegian National Security Authority, 2024
- Cybersikkerhetspakke lagt frem, Stortinget EU/EØS-nytt, 28 January 2026
- NIS2 Directive, European Commission
- Hvordan lage en databehandleravtale?, Datatilsynet
Transparency note: This article is based on the author's own analysis and experience. AI has been used as an editorial aid for language and structure.
