Digital security act and related regulation enters into force
On June 23, 2025, the Norwegian legislature signed into law the Digital Security Act (DSA) and its accompanying Regulation, both of which will enter into force on October 1, 2025.
The legislation marks a significant step in Norway’s efforts to modernize its cybersecurity framework and align with evolving European standards.
Is there a connection with NIS2?
The DSA was initially designed to implement the EU Network and Information Security Directive (NIS1) (EU Directive 2016/1148) that entered into force in the European Union in August 2016. However, the EU has passed the EU Network and Information Security Directive 2 (Directive (EU) 2022/2555), which aimed at strengthening cybersecurity across the European Union, replacing NIS1. NIS2 has not yet been incorporated into the EEA Agreement.
However, with the adoption of NIS2 at the EU level, the Norwegian Ministry of Justice and Public Security has taken a proactive approach by integrating select NIS2 requirements into the Regulation, despite NIS2 not yet being formally incorporated into the EEA framework. These requirements mainly include the duty to notify within specified timeframes.
Scope and classification
The DSA is applicable for “providers of essential services” and providers of “digital services”.
Providers of “digital services” are classified as “online marketplaces, online search engines or cloud services”. Entities falling under one of these categories should therefore assess whether they are in scope.
Entities are classified as “providers of essential services” if they meet all three of the following:
- Provide services critical to societal/economic functions
- Rely on network and information systems
- Are vulnerable to significant disruption from incidents
The Regulation (§ 1) lists entities and activities that automatically qualify. Authorities may also designate additional entities under Section 4. Examples of entities classified as “essential services” include air traffic control and related services, ports, the health sector and shipping companies to mention a few.
Obligations for Providers of Essential Services
There are different obligations for providers of essential services and digital services. Providers of Essential Services must:
- Implement Security Measures (DSA § 7; Regulation §§ 7–12);
- Register with authorities (Regulation § 5 – NSM and sector-specific authorities); and
- Report incidents (DSA §8; Regulation § 13).
Obligations of providers of Digital Services
Providers of Digital Servies shall implement appropriate and proportionate technical and organizational security measures in order to ensure a level of security appropriate to the risk.
When assessing what constitutes an acceptable level of security the Digital Service Provider shall take into account technological developments and
a. the security of systems, equipment and facilities
b. incident management
c. management of service continuity
d. monitoring, auditing and testing
e. recognized international standards
Providers of Digital Services should consider implementing an Information Security Management System (ISMS) to ensure compliance. If the Digital Service Provider already has an established ISMS, it should review and update the ISMS to verify that the requirements of the DSA are met.
Additionally, the DSA introduces requirements of notifying the relevant authorities in the event of any incidents that have a substantial impact on the provision of the service. This means updated notification procedures should be included in the ISIM.
When assessing whether the impact is significant, consideration shall be given to the number of users affected, the duration of the incident, the size of the geographical area affected, the extent of the service functionality failure and the extent of the impact on economic and societal activity.
Note that the Regulation implements the EU regulation 2018/151 which further specify elements to be considered by Digital Service Providers for managing the risks posed to the security of network and information systems and of the parameters for determining whether an incident has a substantial impact.
Supervision and oversight
The DSA introduces a new regime for supervision and oversight of the DSA and Regulation.
- Sector-specific authorities will oversee compliance within their domains.
- The Norwegian National Security Authority (NSM) will supervise entities without a designated sector authority (Regulation §20).
Sanctions for breach
The DSA and Regulation introduce strict sanctions for breach. The sanctions include the right to impose liquidated damages and administrative fines. Administrative fines may be set to an amount of up to 24 times the base amount (roughly 3 MNOK) or 4 percent of the total annual turnover in the preceding financial year, whichever amount is higher.
Key distinction from NIS2
Unlike NIS2, which differentiates between “essential” and “important” entities, the DSA maintains the NIS1 structure, distinguishing between:
- Providers of Essential Services
- Digital Service Providers
The scope of DSA is significantly narrower than NIS2.
Next steps for organizations
In order to prepare for the DSA and Regulation entering into force, we recommend that entities in scope:
- Assess classification under the DSA
- Prepare for registration with NSM or relevant authority
- Review and implement required security and reporting measures
- Consider consulting authorities for clarification on applicability
If you have questions regarding the DSA, NIS2 or other related areas, feel free to contact us.