Updated July 2026 · Based on NSM, Lovdata and regjeringen.no

NIS2 and the Digital Security Act explained, for Norwegian maritime companies

A practical walkthrough of what the rules require, who they cover, and what maritime transport, ports, and the seafood industry should do now. Written for leaders, not lawyers.

Last updated: July 2026. We verify facts against NSM, Lovdata and regjeringen.no, but this is information, not legal advice.

What is NIS2?

NIS2 is EU Directive 2022/2555 on a common high level of cybersecurity across the Union. It expands the original 2016 NIS directive to many more sectors and imposes stricter requirements on risk management, incident reporting, and management accountability.

For EU countries, the deadline to transpose NIS2 into national law was 17 October 2024. The directive is marked EEA-relevant but has not yet been incorporated into the EEA Agreement. Norway therefore cannot bring it into national law until that incorporation is in place.

Important nuance: as of July 2026, NIS2 is not yet Norwegian law. The Ministry of Justice is preparing a consultation, and a new law is expected that implements NIS2 together with the CER directive, replacing today’s Digital Security Act. NSM has signalled a registration scheme and supervision during 2026, but the NIS2 law itself is not yet adopted. No official entry-into-force date is confirmed. Be cautious with anyone stating exact dates or entity counts as fact.

What is already binding in Norway today follows from the Digital Security Act (which implements the original NIS directive). NIS2 is the direction the requirements are moving, broader scope, shorter deadlines, clearer board accountability, and higher fines.

What is the Digital Security Act, and how does it relate to NIS2?

The Digital Security Act (digitalsikkerhetsloven, law of 20 December 2023 no. 108) implements the original NIS directive into Norwegian law and entered into force on 1 October 2025 together with its regulation. It is already applicable Norwegian law.

The Act sets requirements for providers of essential services in sectors such as energy, transport, health, water supply, banking, financial infrastructure, and digital infrastructure, plus certain digital service providers. The obligations concern adequate security and notifying serious incidents.

NIS2, once implemented, will significantly widen this circle and tighten the requirements. For the maritime industry the practical takeaway is: prepare for today’s Digital Security Act now, and build your documentation so you are ready for NIS2 without starting over.

Who is covered by NIS2?

NIS2 covers entities in designated sectors that are medium-sized or larger, in practice from around 50 employees, or more than €10M in turnover or balance sheet. Some types of entity are covered regardless of size.

Sectors are split into two annexes: Annex I (“high criticality”) and Annex II (“other critical sectors”). For maritime and coastal industry the most relevant are:

  • Maritime / water transport, Annex I (high criticality). Covers passenger and freight transport by sea and along the coast.
  • Ports and port facilities, Annex I. Covers managing bodies of ports and those operating equipment within ports.
  • Digital infrastructure, Annex I.
  • Food, production, processing and distribution, Annex II. Seafood production and processing fall under the food sector (the directive uses “food”, not “seafood”).
  • Postal and courier services, waste, chemicals, manufacturing, Annex II.

Requirements cascade downward: if you supply a covered entity, that customer will impose security requirements on you by contract, even if you are below the threshold yourself. In practice many small and medium suppliers are drawn in this way.

The threshold builds on the EU definition of small and medium enterprises (Commission Recommendation 2003/361/EC). “From ~50 employees or over €10M” is a simplification, for entities near the line, the concrete assessment should be made against the rules.

What is the difference between “essential” and “important” entities?

NIS2 splits covered entities into two: essential and important. Essential entities are the largest entities in the most critical sectors and face stricter supervision and higher fines; important entities face more reactive supervision and a lower fine ceiling.

  • Essential entities: typically large entities (250+ employees or over €50M turnover) in Annex I sectors, plus certain named entities regardless of size. Subject to proactive (ex ante) supervision.
  • Important entities: medium-sized entities in Annex I, and all covered entities in Annex II. Subject to reactive (ex post) supervision, triggered by indications of a breach.

For a typical mid-sized shipping company, port, or seafood exporter, “important entity” is the most likely outcome, but the category depends on sector and size, and should be assessed concretely.

What do the rules require concretely?

The core is four things: documented risk management, securing the supply chain, fast incident reporting, and management taking responsibility. NIS2 Article 21 lists at least ten security measures an entity must have in place.

Risk management and security measures (Art. 21)

  • Policies for risk analysis and information security
  • Incident handling
  • Business continuity and crisis management (backup, recovery)
  • Supply-chain security
  • Security in acquisition, development and maintenance, incl. vulnerability handling
  • Procedures to assess whether the measures work
  • Basic cyber hygiene and training
  • Cryptography and encryption
  • Access control, personnel security and asset management
  • Multi-factor authentication and secured communication

Incident reporting (Art. 23)

For a serious incident, a staged deadline applies: an early warning within 24 hours, a fuller incident notification within 72 hours, and a final report within one month. If the incident is still ongoing after a month, a progress report is submitted, then a final report within one month of resolution.

Management accountability (Art. 20)

Management must approve the security measures and oversee their implementation, and management itself must undergo training. Management can be held liable for breaches of its governance duties. For essential entities, the directive also allows a manager to be temporarily barred from managerial functions if breaches are not remedied.

What sanctions and fines apply?

NIS2 sets a common minimum level for maximum fines: for essential entities at least €10M or 2% of global annual turnover, and for important entities at least €7M or 1.4%. The higher figure applies.

Note: these are the EU directive’s minimum-maximum figures. The concrete Norwegian fine levels will be set in the forthcoming Norwegian law and regulation, and are not yet adopted. Do not assume the EU figures as the Norwegian rates.

Who supervises in Norway?

Under today’s Digital Security Act, supervision is sector-based: each sector ministry designates a supervisory authority, and NSM is the national authority for sectors without a designated one, as well as the national response body and EU/EEA contact point. The Norwegian Maritime Authority (Sjøfartsdirektoratet) has already issued guidance on how the Act applies to the maritime sector. How supervision is organised under NIS2 is not yet settled.

Checklist: 10 first steps toward compliance

You do not need everything in place before you start. These ten steps take you from “uncertain” to a documented baseline you can build on.

  • Clarify whether and how you are covered, directly by the rules, or via customers imposing requirements.
  • Map systems, networks and data flows, including OT/IoT and remote access.
  • Keep a supplier register: who can access what, and what you require of them.
  • Run a risk assessment based on NSM Basic Principles, prioritized by operational impact.
  • Establish an information-security management system with an owner in management.
  • Close the obvious gaps: default passwords, unnecessary remote access, flat networks, missing MFA.
  • Build an action plan with ownership, deadlines and prioritization.
  • Establish incident readiness with templates for 24-hour notification.
  • Ensure backups and a tested recovery routine.
  • Document everything, with dates, that is the evidence regulators, insurers and customers ask for.

Unsure whether you are covered? We clarify it for free in the first call.

Frequently asked questions about NIS2 and the Digital Security Act

Does NIS2 already apply in Norway?

No. As of July 2026, NIS2 is not yet Norwegian law. What applies today is the Digital Security Act, which implements the original NIS directive and entered into force on 1 October 2025. NIS2 is expected to be implemented later through a new law, with no confirmed date.

When does NIS2 enter into force in Norway?

It is not confirmed. NIS2 must first be incorporated into the EEA Agreement, then implemented into Norwegian law. A consultation is announced and a new law (NIS2 together with the CER directive) is expected, but no official entry-into-force date exists. Be skeptical of sources giving an exact date.

Are we covered if we have fewer than 50 employees?

Maybe. The threshold is roughly 50 employees or over €10M in turnover/balance, but some entities are covered regardless of size. In addition, requirements cascade through the supply chain: if you supply a covered entity, that customer may impose requirements regardless of your own size.

Is a shipping company or a port covered?

Maritime transport and ports sit in NIS2 Annex I (high criticality). Covered shipping companies and ports above the threshold will typically be “essential” or “important” entities. The final classification depends on size and activity and should be assessed concretely.

Are seafood producers covered?

The food sector, production, processing and distribution, sits in Annex II (important entities). Seafood production and processing fall under the food sector. The directive uses the term “food”, not “seafood” specifically.

What is the deadline for incident reporting?

NIS2 sets a staged deadline: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month. Today’s Digital Security Act has its own notification requirements; prepared readiness means you never start from a blank page during an incident.

Can management be held personally liable?

NIS2 makes management responsible for approving and following up the security measures, and management must undergo training. It can be held liable for breaches of its governance duties, and for essential entities a manager may ultimately be temporarily barred from managerial functions.

How large can the fines be?

NIS2 sets a minimum level for maximum fines: at least €10M or 2% of global turnover for essential entities, and at least €7M or 1.4% for important ones. These are the EU directive’s figures, the concrete Norwegian rates will be set in the forthcoming Norwegian law.

Who supervises?

Under the Digital Security Act, supervision is sector-based, with NSM as the national authority where no sector authority is designated, and as the national response body. The Norwegian Maritime Authority has issued guidance for the maritime sector. The supervision model under NIS2 is not yet settled.

What should we do now?

Start by mapping systems and suppliers, running a risk assessment based on NSM Basic Principles, and building your documentation. That satisfies today’s Digital Security Act and leaves you ready for NIS2 without doing the job twice. Havvakt does this as an ongoing service.