Alessandro AleddaInsider Threat and Risk

ITER/NONorway

What the record establishes for Norway: the bodies an insider event is reported to, the channel each takes, and the act that transposes the NIS2 Directive, Directive (EU) 2022/2555.

Recipients
4 of 4
Reporting address
None recorded
NIS2
In force 1 October 2025
Terms moved
Yes
Sources cited
5
Last read
3 SEPTEMBER 2026

Recipients

Reached underBodyChannelSource
Data protection authorityGDPR, article 33Datatilsynet reportededpb members
CSIRT or competent authorityNIS2, article 23The sectoral supervisory authority, with a copy to the National Contact Point, under section 17 of the regulation reported

Not set by the regulation, and there is no portal. The Authority publishes a form to be filled in and sent to beredskap@nsm.no, marked «varsel digitalsikkerhetsloven». The notification goes to the entity's own sector supervisory authority, and the National Security Authority takes a copy where another body supervises.

no digitalsikkerhetsforskriften · nsm varsle
Financial supervisorDORA, article 19Finanstilsynet reportedeba competent authorities
Market authorityMAR, article 17Finanstilsynet reportedesma mar nca

Transposition of NIS2 binding

ActDigitalsikkerhetsloven, with the digitalsikkerhetsforskriften of 20 June 2025
In force1 October 2025
RecipientThe sectoral supervisory authority, with a copy to the National Contact Point, under section 17 of the regulation
Moves a termYes. Norway is not running the same cascade. The law implements the first NIS Directive, not NIS2. Neither the regulation nor the authority's guidance page mentions NIS2 at all. The final report is measured from the first warning, not from the second stage. Section 17 reads «Innen en måned fra varsel som nevnt i første ledd er sendt, skal tilbyderen gi tilsynsmyndigheten en hendelsesrapport»: one month from the first warning, where the Directive measures its final report from the incident notification. The seventy-two hours have no anchor in the regulation: it says only «Informasjonen i varselet skal oppdateres innen 72 timer». And the regulation and the guidance use different words for the moment. The regulation runs the twenty-four hours «etter at en tilbyder ... fikk kjennskap til hendelsen», from obtaining knowledge; the authority's own page says «innen 24 timer etter at dere oppdaget hendelsen», after the incident was discovered.
StandingRead in the regulation on Lovdata and in the National Security Authority's guidance, which is where the second wording comes from. The recipient also differs in kind: the warning goes to the sectoral supervisory authority with a copy to the National Contact Point, not to a CSIRT.
Sourceno digitalsikkerhetsforskriften

An event in Norway

The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.