← Back to insights

Enterprise IT · 19 August 2026 · 7 min

No, NIS2 does not yet apply in Norway

What Norwegian law actually requires of access management as of August 2026 — and why it is stricter than you think

A great deal is sold on NIS2 in the Norwegian market. Most of it is wrong on one precise point, and that point is worth clearing up — not because the requirements are milder than the marketing claims, but because the actual requirements are more concrete, already in force, and easier to work toward.

NIS2 is not Norwegian law

As of August 2026, Directive (EU) 2022/2555 (NIS2) has not been incorporated into the EEA Agreement. EFTA's own EEA-Lex register classifies the act as "under scrutiny for incorporation into the EEA Agreement", the draft EEA Joint Committee Decision is "under consideration", and the entry into force of the decision is "pending". The Norwegian government's EEA notice on NIS2 was last updated in August 2023.

Nor has any Norwegian proposition, consultation or legislative decision on the implementation of NIS2 been found. Because implementation requires a statutory amendment, the Storting must also consent to the incorporation.

Consequence: a vendor claiming that "NIS2 imposes requirements on your organization as of now" is wrong about Norwegian law. The requirements may reach you through contract — Norwegian companies supplying into EU value chains encounter NIS2 through their customers' requirements, not through Norwegian law — but that is an entirely different mechanism, and it should be described as such.

What actually applies: the Norwegian Digital Security Act

The Norwegian Digital Security Act (digitalsikkerhetsloven, LOV-2023-12-20-108) and the Digital Security Regulations (digitalsikkerhetsforskriften, FOR-2025-06-20-1131) entered into force on 1 October 2025. The Act implements NIS1 and applies to providers of essential services in seven sectors: energy, transport, health, water supply, banking, financial market infrastructure and digital infrastructure — as well as to digital service providers (online marketplaces, search engines, cloud computing services).

Norway does not have a general size threshold for essential services. Section 1 of the Regulations instead lists 28 specific categories of undertakings with quantitative thresholds — passenger transport above 375,000 train kilometers per year, ports handling more than 100,000 tonnes of goods, water supply systems treating at least 2,000 m³ per day, systemically important banks under the CRR/CRD Regulations, and so on. For digital services, by contrast, an exemption applies to undertakings with fewer than 50 employees and under EUR 10 million in turnover or balance sheet total.

And here is what makes this Act more interesting than NIS2 for Norwegian IT managers right now: the requirements for access management are formulated concretely, and they already apply.

Section 10, Technological security measures: the measures «skal minst omfatte a. sterk autentisering for adgang til nettverk og informasjonssystemer b. styring av og kontroll med tilganger til virksomhetens nettverk og informasjonssystemer c. tiltak for segmentering av nettverk og tjenester basert på minste privilegiums prinsipp» [Unofficial translation: "shall as a minimum comprise a. strong authentication for access to networks and information systems b. management of and control over access rights to the undertaking's networks and information systems c. measures for segmentation of networks and services based on the principle of least privilege"].

Section 12, Security measures for personnel: access shall be granted «basert på roller, oppgaver, ansvar og tjenstlig behov» [Unofficial translation: "based on roles, tasks, responsibilities and legitimate business need"], and the undertaking shall «følge opp at personell ikke har flere tilganger enn nødvendig» [Unofficial translation: "follow up that personnel do not have more access rights than necessary"]. Then, verbatim: «Når et arbeidsforhold eller en tjeneste avsluttes, skal en tilbyder av en samfunnsviktig tjeneste sikre at den som slutter ikke lenger har tilgang til virksomhetens nettverk og informasjonssystemer.» [Unofficial translation: "When an employment relationship or a service is terminated, a provider of an essential service shall ensure that the person leaving no longer has access to the undertaking's networks and information systems."] The provision expressly covers employees, suppliers and contractors.

This is an explicit Norwegian offboarding obligation. It does not exist in the NIS2 text in a correspondingly precise form — NIS2 Article 21(2)(i) requires "human resources security, access control policies and asset management", which is vaguer.

Sanction: an administrative fine under Section 24 of the Regulations of up to 25 times the National Insurance basic amount (grunnbeløpet) or four percent of annual turnover, with an absolute ceiling of NOK 50 million.

For financial undertakings: DORA is already Norwegian law

Here the picture is the exact opposite of NIS2. Regulation (EU) 2022/2554 (DORA) has applied in the EU since 17 January 2025, was incorporated into the EEA Agreement by Decision 040/2025 with effect from 1 July 2025, and applies as Norwegian law through the Norwegian DORA Act (DORA-loven, LOV-2025-05-27-18), in force 1 July 2025. The Financial Supervisory Authority of Norway (Finanstilsynet) is the supervisory authority. Administrative fines up to NOK 50 million, and the Act explicitly allows fines to be imposed on natural persons, not only on undertakings.

DORA Article 9(4)(c) is the direct legal basis for access management: financial entities shall "implement policies that limit the physical or logical access to information assets and ICT assets to what is required for legitimate and approved functions and activities only, and establish to that end a set of policies, procedures and controls that address access rights and ensure a sound administration thereof". Article 9(4)(d) requires "strong authentication mechanisms".

"Sound administration" of access rights covers both granting and removal. A departed employee does not satisfy "legitimate and approved functions".

Note the scope as well: DORA covers not only the financial undertakings themselves, but also ICT third-party service providers, and critical ones among them are designated by the European Supervisory Authorities under Article 31 with a dedicated "Lead Overseer". If you deliver IT services to the Norwegian financial sector, this is your regulatory framework too.

GDPR applies to everyone, with no threshold

Article 32(4) is the most direct: the controller shall ensure that "any natural person acting under the authority of the controller ... who has access to personal data does not process them except on instructions from the controller". A former employee no longer acts under your authority. Continued technical access is therefore a breach regardless of whether it has been used.

Add Article 5(1)(f) on "protection against unauthorised or unlawful processing", 5(1)(c) on data minimization, 32(1)(d) on "a process for regularly testing, assessing and evaluating the effectiveness" of the measures — and 5(2), which requires that you be able to demonstrate compliance. Missing documentation is a deviation in its own right.

Norwegian enforcement practice exists. In September 2024, the Norwegian Data Protection Authority (Datatilsynet) fined the University of Agder NOK 150,000 because employees had had access to personal data without a legitimate business need, in open Teams folders, since 2018 — around 16,000 data subjects affected. In March 2024, the authority fined NAV NOK 20 million following an inspection of «tilgangsstyring og loggkontroll» [Unofficial translation: "access management and log control"]; that decision was partly set aside by the Privacy Appeals Board (Personvernnemnda) in December 2024 and taken up for renewed consideration, so it should not be cited as a standing fine — but the supervisory priority is clear enough.

And one claim that does not hold

It is often claimed that cyber insurers ask about offboarding routines in their underwriting questionnaires. A review of published application forms from Beazley, Corvus and Tokio Marine HCC shows specific questions about MFA for remote access, webmail and privileged accounts — but no explicit questions about the removal of access rights upon termination of employment. The claim appears in broker blogs, not in the forms. Use the MFA and privileged-account argument, which is documented. Leave the offboarding claim alone until someone can put a form on the table.

What this means for Entra Logic

The regulatory framework asks for three things: that access be granted according to legitimate business need, that superfluous access be followed up, and that access actually ceases upon termination. All three are formulated as process requirements that must be documentable, not as technology requirements.

That is exactly the shape of what Entra Logic produces: every change has a justification, an approver and an execution in the same record, and no one has standing administrator privileges that bypass the flow. The offboarding sequence is run as a single approved order rather than as a manual checklist.

Two things we should not claim. Entra Logic is not an attestation or certification product and does not run periodic recertification campaigns. And no vendor can make a customer "NIS2-compliant" in Norway in August 2026, for the simple reason that NIS2 does not apply here yet. What does apply, on the other hand, applies now.

Sources

RELEVANT SOLUTION

See how this is handled in practice:

Norwegian version: Les artikkelen på norsk