The Danish FSA has published the designated IT suppliers to financial companies subject to NIS2 and under the supervision of the Danish FSA
Published 27 November 2024
Category: Updates
The Danish FSA has appointed a number of IT suppliers as operators of financial digital infrastructure to which NIS2 applies. The details are available here (in Danish).
As of 18 October 2024, the NIS-2 directive[1] (“NIS2”) applies to the most important IT suppliers to the financial sector.
While the implementation of NIS2 in general has been postponed to 2025 take effect in Denmark, the Danish Financial Supervisory Authority (the “Danish FSA”) already in May 2024, with a new Chapter 19 c of the Financial Business Act, was provided with the legal framework for supervision of the financial sector under the DORA Regulation[2] and NIS2.
The designated IT suppliers are set out below:
- JN Data A/S
- FORENINGEN BANKDATA
- SDC A/S
- Bec Financial Technologies A.M.B.A.
- e-nettet A/S
- Mastercard Payment Services Denmark A/S
The purpose of NIS2 is to strengthen cybersecurity by setting requirements for financial companies’ IT security, their reporting of security incidents, and risk management. Find more information on the authority given to the Danish FSA pursuant to a new Chapter 19c of the Danish Financial Business Act on Mazanti Pulse.
NIS2 does not apply to financial undertakings covered by the DORA Regulation. For these companies, the DORA Regulation will instead apply from 17 January 2025.
[1] Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union.
[2] Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on Digital Operational Resilience for the financial sector, and
Also tagged ‘Cybersecurity’
The Danish government has presented bills for implementing the NIS2 Directive and the CER Directive
On 6 February 2025, the bills for implementing the NIS2 Directive and the CER Directive were presented by the Danish government to the Danish Parliament.
CERCybersecurityNIS2Other updates
The Danish FSA has updated the report on fitness assessments
On 5 February 2025, the Danish FSA published a new and updated version of its report detailing its practice regarding the fitness assessment of board members, executive management members and key persons in financial businesses.
Danish RegulationGovernanceThe Danish FSAEU Commission calls for review of certain outbound investments
On 15 January 2025, the European Commission issued a recommendation urging EU Member States to review investments out of EU for risks of enabling technology transfers/leakage into third countries (‘outbound investments’).
Cross-BorderThe Danish government has presented bills for implementing the NIS2 Directive and the CER Directive
On 6 February 2025, the bills for implementing the NIS2 Directive and the CER Directive were presented by the Danish government to the Danish Parliament.
CERCybersecurityNIS2EU Competitiveness Compass – ESG takeaways
29 January 2025, the EU Commission published its Competitiveness Compass which sets out a compass that will guide the work in the coming five years and lists priority actions to reignite economic dynamics in Europe, according to the communication.
CSDDDCSRDDisclosure RequirementsSFDRSustainabilityNew advance tax rulings expand the scope of carried interest taxation
According to two new advance tax rulings from the Danish Tax Assessment Council (SKM2025.46.SR and SKM2025.47.SR), under certain circumstances, investments directly in portfolio companies owned by a private equity or venture capital fund may also be subject to taxation under the carried interest taxation scheme.
Venture CapitalThe Omnibus Simplification Package and how it may impact EU’s ESG regulation
In the end of 2024, the European Commission President Ursula von der Leyen indicated that existing and future EU ESG reporting obligations may be consolidated into an “omnibus” regulation with the purpose of reducing reporting requirements.
CSRDDisclosure RequirementsSustainability