Digital Security Act · NIS2 · Built in Tromsø

NIS2 compliance without the consultant bill

Havvakt helps Norwegian maritime and coastal companies, shipping lines, ferries, ports, terminals, and seafood exporters, meet the requirements of NIS2 and Norway’s Digital Security Act (Digitalsikkerhetsloven). Risk assessments, documentation, and 24-hour incident reporting. For your industry, with data that never leaves Norway.

Built in Tromsø · Based on NSM Basic Principles · Data stored in Norway

Havvakt Console
nord-rederi-01 · live
68/ 100
Compliance score
Documents
14
ready
Drafts
3
to review
Supplier risk
3
open
Requirement areas (NIS2)4 of 6 covered
  • Risk management
  • Supply chain
  • Incident readiness
  • Training
DRAFT READYIncident report draft · generated in 4 min · awaiting approval
Signed compliance report · Q3 2026Signed
Built in
Tromsø, Norway
Based on
NSM Basic Principles
Data stored
In Norway
Built for
Maritime industry

The requirements have landed

The law demands more than most have in place

The Digital Security Act is in force, and NIS2 pulls thousands of mid-sized Norwegian companies into the regulated zone, including maritime transport, ports, and suppliers to critical infrastructure. The requirements are concrete:

Risk management and security measuresdocumented and current

Continuous monitoringof your own systems and suppliers

Incident reporting within 24 hoursto the authorities

Management accountabilitythe board can be held personally liable

The big consultancies are priced for corporations. American compliance tools are in English, generic, and store data abroad. None of them speak maritime.

How it works

Map, document, report

01

Map

We map systems, suppliers, and data flows. On-site or remote.

02

Assess

A risk assessment based on NSM Basic Principles and the requirements of the Digital Security Act, prioritized by operational impact.

03

Document

All required documentation generated and maintained: management system, action plan, supplier register, and audit-ready exports for regulators, insurers, and customers auditing their suppliers.

04

Report

Ready-made templates and drafts for 24-hour incident reporting, so you never start from a blank page during an incident.

Services

Start simple. Grow into a platform.

Available now

Compliance as a service

We do the work: mapping, risk assessment, documentation, and reporting readiness, as an ongoing service. Fixed monthly price. No lock-in the first quarter.

Book a call
Waitlist

The Havvakt platform

A guided risk-assessment wizard, document generation anchored in the legal text itself, and incident-report drafts in minutes. Built on private language models operated in Norway.

Add me to the waitlist
Available now

Private AI for regulated companies

Local, air-gapped language-model deployments for companies that cannot send data to US clouds. Setup + operation.

Learn more

Why now

Three forces arriving at once

The rules are sharp

The rules are sharp

The Digital Security Act applies, supervision and fines are real, and requirements cascade down the supply chain. Your biggest customer could demand the documentation tomorrow.

Data sovereignty

Data sovereignty matters

More and more Norwegian companies cannot, or will not, send sensitive information to foreign cloud services. At Havvakt, the data never leaves Norway.

The coast is exposed

The coast is exposed

Maritime infrastructure in the north operates under elevated geopolitical pressure. Visibility and readiness are no longer optional.

Why Havvakt

Not a consultancy. Not generic software.

The big consultancies are priced for corporations and do not know maritime operations. American compliance software is generic, in English, and stores data abroad. Havvakt is built for the coast.

01

Industry-specific

Shipping, ports, terminals, seafood. Templates and risk models for maritime operations, not generic office IT.

02

Anchored in Norwegian law

Documentation, wizards, and reports anchored in Norwegian law and NSM Basic Principles.

03

Data in Norway

Private language models operated locally. No data to foreign clouds.

04

Priced right

Built for companies with 50–500 employees and no in-house security team. A fraction of the consultant bill.

Founder-led

Built in Tromsø, for the coast Norway lives on

Havvakt is founder-led, with a background in cloud infrastructure, large-scale network security, and private-AI development. We are early-stage, and honest about it. We start with one company at a time, do the thorough work properly, and build trust the way it is actually earned in a small industry: by being precise, present, and useful.

FAQ

Questions we get

Do NIS2 and the Digital Security Act apply to us?

Probably, if you operate in maritime transport, port operations, logistics, or seafood export, or supply companies in these sectors, and have more than roughly 50 employees or €10M in turnover. The requirements also cascade downward: if you supply a covered entity, that customer will impose requirements on you. We clarify it for free in the first call.

What does the law require concretely?

Documented risk management and security measures, handling of supplier risk, continuous improvement, and notification of serious incidents to the authorities within 24 hours, with follow-up reports. Management is accountable.

What does it cost?

Compliance as a service is delivered at a fixed monthly price, a fraction of a consulting project, with no hourly billing. You get a concrete quote after the first mapping call, tailored to your size and complexity.

Where is our data stored?

In Norway. Havvakt is built on private language models operated locally, no data is sent to American or other foreign cloud services.

Can AI-generated documentation be trusted?

Documents are generated with models anchored directly in the legal text, regulations, and NSM Basic Principles (RAG), and everything is quality-checked by humans before delivery. Nothing goes out unseen.

We already have an IT provider, do we need you?

Yes, as a complement. Your IT provider operates the systems; Havvakt covers the compliance layer, risk assessment, documentation, and reporting readiness, that most operations partners do not deliver.

How quickly can we get started?

The first mapping normally takes 2–3 weeks. Baseline documentation is typically in place within the first month.

How are you handling the new requirements?

That is the question we start every conversation with. 30 minutes, no obligation, in Norwegian or English. You get an honest assessment of where you stand, whether or not you proceed with us.