Event details
Webinar on NIS2, the Danish Implementation, and Regulatory Supervision
Description
The NIS2 Directive was implemented into Danish law on July 1, 2025, through the Danish NIS2 Act and a number of sector-specific laws. The NIS2 framework applies to essential and important entities operating in 18 critical sectors.
In the healthcare sector, the rules apply to entities that manufacture medical devices, pharmaceutical ingredients and medicinal products, entities conducting research and development activities relating to medicinal products, as well as EU reference laboratories and healthcare providers.
For life sciences companies covered by NIS2, cybersecurity becomes a regulated core area on par with quality management and patient safety. Companies must take a systematic approach to risk management, documentation, and incident reporting, and they will be subject to supervision by the Danish Health Data Authority (Sundhedsdatastyrelsen).
At the same time, the NIS2 rules increase companies' responsibility for managing cybersecurity risks throughout their supplier and supply chains. In practice, this means that many subcontractors and suppliers will face heightened cybersecurity requirements from their customers.
Additional details
Virtual participation only via MS Teams (link will be provided to registered participants prior to the event)
Meet the speakers
https://www.linkedin.com/in/kasper-bilde-nielsen-497b1459/
https://www.linkedin.com/in/louise-bertelsen-forman/
Program
Welcome
Presented by Louise Bertelsen and Lene Laursen, Board Members of Life Science Law.dk
The Supervisory Authority's Perspective Danish Health Data Authority (Sundhedsdatastyrelsen) (TBC)
- The authority's supervisory role
- Typical findings
- Q&A
Implications of NIS2 for Life Sciences Companies
Presented by Kasper Bilde Nielsen, Bech-Bruun
Q&A
Closing Remarks
Louise Bertelsen and Lene Laursen