Sage Nord
Research package · Fixed fee

NIS2 is already the law. Is your app?

Denmark's NIS2 law took effect on 1 July 2025. A fixed-fee, five-day technical review checks what a policy document cannot: your mobile app, your API, and the access sitting behind them.

Jump to: the evidence · price & scope · FAQ

3,2551 Danish companies estimated newly in scope
5 days fixed engagement, one written report
25-35k DKK, fixed fee, no retainer

351 days since the 1 October 2025 registration deadline1 — the clock did not stop.

Already in force

Not a future roadmap item.

Both key dates have already passed. If your company registered, or heard about this from a customer's procurement team, the clock is already running.

1 Jul 20252 Lov nr. 434, Denmark's NIS2 Act, took effect
1 Oct 20251 registration deadline for companies in scope
3,2551 companies, the government's own working estimate
Scope

Fifteen sectors. Two size tiers.

An "essential entity" generally means 250 or more employees, or turnover above EUR 50 million with a balance sheet above EUR 43 million.

An "important entity" means 50 or more employees, or turnover above EUR 10 million with a balance sheet above EUR 10 million. Some entity types are always essential, regardless of size.

General Act scope

15 sectors in scope
  • Transport · Health · Space
  • Drinking water · Wastewater
  • Digital infra · ICT service mgmt
  • Public admin · Postal/courier
  • Waste mgmt · Chemicals · Food
  • Manufacturing · Digital providers
  • Research
  • Separate laws: energy, telecom
  • Finance carve-out: few entities
  • Most banks stay in scope

Based on the Act's own sector annexes, retsinformation.dk.

What it requires

Ten measures. Three deadlines.

Section 6 requires essential and important entities to run a defined set of technical and organizational measures.

  • Risk analysis
  • Incident handling
  • Business continuity
  • Supply chain security
  • Secure development
  • Effectiveness checks
  • Cyber hygiene
  • Cryptography
  • Access control
  • MFA

Reporting clock

Sections 12-13

  1. Aware clock starts
  2. 24h Early warning
  3. 72h Fuller notification
  4. 1 month Final report

from becoming aware of a significant incident

Statute, §§ 12-13, retsinformation.dk.

Enforcement

The fines are real. So is board accountability.

The management body must formally approve and oversee cybersecurity risk measures and attend relevant training. That is a written duty under Section 7, not a courtesy.

For essential entities, if serious failures are not fixed after other enforcement steps, the supervisory authority can, as a last resort, temporarily bar a named senior manager from management functions. A suspension power, not an automatic personal fine.

Article 34

whichever is higher

Essential tier

EUR 10m fixed amount
or
2% global turnover

Important tier

EUR 7m fixed amount
or
1.4% global turnover

DK applies its ordinary criminal fine system.

Directive (EU) 2022/2555, Article 34, EUR-Lex.

Why this, why now

The gap isn't hypothetical. It's where breaches start.

Industry-wide breach data lines up with exactly what Section 6 asks for. Attackers keep going after the same two things: unpatched software and loosely managed third-party access.

That's not a reason to panic. It's a reason to check, in writing, whether your own vulnerability management and supply-chain security actually hold up.

Verizon 2025 DBIR

12,195 breaches

20% Exploited vulnerability — up 34% year over year, as an initial breach vector
30% Third party involved — roughly double the year before

Both map directly onto Section 6's required measures above.

Verizon 2025 Data Breach Investigations Report, verizon.com.

The gap

A policy can say it. The system still has to prove it.

Access is restricted.

Nobody can say if an old admin account still works.

Systems are secure by design.

Nobody has checked what the app writes to the device.

Incidents get detected and handled.

Nobody owns triage when it happens at 2 a.m.

Vulnerabilities are managed.

Nobody has opened the dependency backlog in a year.

Two minutes

Where do you actually stand?

Tick what's true right now. Not a scored test, just a fast read.

0 of 5 ticked. Two or more, and a focused review is worth it.

Fixed fee · fixed scope

Mobile/API NIS2 Technical Gap Check

25-35k DKK
3-5 business days
1 written report, no retainer

Exact price depends on how many apps and API endpoints are in scope, and how much documentation already exists to review.

Timeline

review window: Days 2-4

  1. Day 1 Kickoff — in scope, priorities
  2. Days 2-4 Review — mobile + API, NIS2 controls
  3. Day 5 Report — gap report, briefing

One engagement, one written report. No open-ended retainer.

Scope of work

Five areas covered. Nothing else pretended.

What it covers

  • Secure development practice: release hygiene, code review, dependency handling.
  • Access control: authentication flow, admin surfaces, service accounts.
  • Encryption in transit and at rest, and key handling weak points.
  • Vulnerability management: dependency exposure and patching discipline.
  • Incident-detection readiness: logs, alerts, ownership, audit trail.

What this isn't

  • Not a legal opinion on whether you're in NIS2 scope.
  • Not a full NIS2 compliance audit.
  • Not a certification, attestation, or GRC sign-off.
  • Not an ISO 27001 audit or a penetration test.
  • Doesn't replace your legal, compliance, or GRC work.

A mutual NDA is signed before any code, credentials, or system access changes hands — standard practice, available on request, no extra fee.

Is this for you

Built for one situation.

A good fit if you

  • Are a Danish mid-market company with a mobile app, device companion app, or external API.
  • Sit in a covered sector, or sell to customers already sending NIS2-style questionnaires.
  • Ship software but have no dedicated in-house security engineering function.
  • Want a fast, concrete, written answer before committing to a larger program.

Not a fit if you need

  • A formal legal scope opinion.
  • A full compliance audit or ISO 27001 certification work.
  • A penetration test or offensive security engagement.
Before you ask

Straight answers to the usual questions.

Why a fixed fee instead of billing by the hour?

So you know the cost before anything starts. The price only moves if the scope does — more apps, more API surface, less existing documentation to work from — never because the review runs long.

Is our code and data kept confidential?

Yes. A mutual NDA is signed before any access is given, and nothing about your systems or findings is used publicly without written permission.

We're not sure we're even in NIS2 scope. Can you still help?

Yes — that's a normal starting point. The kickoff call includes a quick read of your sector and size against the Act's criteria, so you know before the technical work begins. That's not a legal scope opinion; if you need one in writing, that stays with a lawyer.

Who actually does the review?

Yeskendir Salgara, personally — the same person named below. No outsourcing, and no junior analyst doing the work under someone else's name.

What if the review doesn't find anything serious?

Then the report says so. A short list of minor items and a clean bill on the rest is a legitimate outcome, not a reason to invent findings.

What happens after we get the report?

It's yours. Act on it internally, hand it to your own team, or bring it to a compliance partner. There's no obligation to buy anything further.

About Sage Nord

Narrow, on purpose.

Sage Nord is a Danish software and AI engineering practice run by Yeskendir Salgara, previously a senior mobile/iOS engineering lead at Trackman.

This offer is deliberately narrow: senior engineering review of the systems Article 21 style requirements actually land on, mobile clients, backend APIs, and the operational basics around them. No CISSP, OSCP, or ISO 27001 lead-auditor claim, and none is needed for this bounded piece of work.

1. Email hello@sagenord.com with "NIS2 Gap Check" and a short paragraph about your app or API.

2. A short call first is fine if you want to check fit before committing.

3. Get a written gap report and executive summary in 3-5 business days.