← Back to the regulatory map
Act and Regulation on Digital Security – Implementing NIS1 Norway and the EU

The Digital Security Act and the Digital Security Regulations

Valid in Norway

Last peer-reviewed July 16, 2026

Brief overview

The Digital Security Act and the Digital Security Regulations entered into force on October 1, 2025. The regulations implement the EU's first Directive on Security of Network and Information Systems, NIS1, and set fundamental requirements for digital security for specified providers of socially critical and digital services.

Covered entities shall work systematically and risk-based with security, preparedness, and incident management. For providers of vital societal services, this includes, among other things, documented security management, risk assessments, organizational, technological, physical, and personnel measures, contingency plans, and follow-up of suppliers. Serious incidents that significantly affect service delivery must be reported to the authorities.

The regulations are not AI-specific. When AI systems, cloud services, automated translation, or other language tools are part of the delivery of a covered service, they may still be systems, dependencies, or supplier services that must be included in security efforts. The use of AI does not in itself expand the scope of the law.

Keep an eye on NIS2: As of July 18, 2026, the NIS2 Directive is still under review for incorporation into the EEA Agreement. It has not entered into force in Norway, and there is no verified Norwegian entry-into-force date. For the time being, it is the Digital Security Act and Regulations, based on NIS1, that apply in Norway.

What regulates this

The regulations shall prevent, uncover, and counteract undesirable incidents in network and information systems used to provide critical societal and digital services.

The regulations specify the scope through categories and thresholds for providers of essential services. They also set out detailed requirements regarding, among other things, security management, risk assessments, security measures, emergency preparedness, supply chain follow-up, registration, and incident notification.

Digital service providers are covered by a separate regime for security and notification. It is therefore important to clarify which provider category the business belongs to, and not assume that all requirements apply equally to both categories.

Who is affected

Public sector

Private sector

Why it has practical significance

Failures in digital systems can affect services such as health, water, energy, transport, finance, and digital infrastructure. The regulations clearly place responsibility for digital security with the company's management and make security work a part of ordinary governance.

For businesses that use AI, automated translation, or other language tools in a covered service, relevant risks and dependencies must be assessed in the same way as for other digital systems. This may include, among other things, unauthorized access, data leakage, manipulation, unavailability, inadequate recovery, and failure of a cloud or system provider.

The use of AI is nevertheless only indirectly relevant: The decisive factor is whether the business and the service fall within the scope of the law, and whether the system can affect the security or delivery of the service in question.

Key Requirements and Obligations

  • Clarify and document whether the business is a provider of essential services or a provider of digital services; the scope, thresholds, and obligations differ.
  • Providers of socially critical services must report the business and the relevant services to NSM and the relevant sectoral supervisory authority as soon as possible, and report changes.
  • Providers of essential services shall have a documented security management system that is part of the enterprise's overall management, is approved by the head of the enterprise, and is reviewed at least annually.
  • Risk assessments of the network and information systems used in the provision of services shall be prepared, documented, maintained, and updated upon relevant changes.
  • The security measures shall be appropriate and proportionate to the risk and cover relevant organizational, technological, physical, and personnel-related aspects.
  • Providers of socially critical services must have documented plans for incident management and emergency preparedness and carry out relevant exercises.
  • Providers of vital societal services must impose necessary security requirements on suppliers and others who can affect security, make the requirements binding and follow them up.
  • Both supplier categories must notify without undue delay of incidents that have a significant impact on the service delivery.
  • For critical services, phased deadlines apply: first notification within 24 hours, update within 72 hours, and incident report within one month.
  • The phased deadlines in the digital security regulations do not apply in the same way to providers of digital services; these follow the statutory requirement for notification without undue delay and the specific rules for digital services.

What the business may consider documenting

  • Conduct a documented scope analysis against the categories, criteria, thresholds, and exemptions in the act and regulations.
  • Map systems, data flows, operating environments, vendors, and other dependencies necessary to deliver the scoped service.
  • Include relevant AI systems, language tools, and cloud services in risk assessments, contingency plans, and overviews of critical dependencies.
  • Allocate and document responsibility for safety management, risk management, supplier follow-up and incident reporting.
  • Set specific requirements for security, notification, auditability, continuity, recovery, and service termination in relevant supplier agreements.
  • Test that the organization can detect, assess, escalate, and report serious incidents within the deadlines applicable to the organization's provider category.
  • Coordinate incident response procedures with any notification obligations under privacy regulations, the Security Act, and sector-specific rules.
  • Follow the NIS2 process in the EEA and consider a voluntary gap analysis, but clearly note that the NIS2 requirements are not yet applicable Norwegian law.

Sources and Further Reading

The links point to external sources. Check the current text and status before using them in your own work.

The information is general information and not legal advice. The applicable requirements must be assessed based on the enterprise's sector, role, information, and specific use of technology.