Order No. 260 on resilience and emergency preparedness in the energy sector.
Country
Type of law
Regulation
Abstract
This Order establishes a comprehensive framework for resilience, emergency preparedness, physical security, and cybersecurity in the Danish energy sector. It applies to operators in the electricity, gas, hydrogen, oil, district heating, and district cooling sectors that are considered important for energy supply and energy markets. The regulation classifies companies and facilities according to their importance, requires risk and vulnerability assessments, emergency preparedness plans, regular exercises, incident response capabilities, and governance arrangements involving senior management. Companies must maintain inventories of critical facilities and network systems, assess risks associated with projects and supply chains, ensure business continuity, and participate in sector-wide preparedness arrangements coordinated by the Danish Energy Agency and, for certain sectors, Energinet. The Order also incorporates requirements concerning climate resilience, protection of critical infrastructure, and organisational preparedness for disruptions affecting energy supplies.
A major feature of the instrument is its detailed cybersecurity and critical-infrastructure protection regime, implementing parts of the EU NIS 2 Directive and the Critical Entities Resilience (CER) Directive. Energy companies must secure network and information systems through measures such as access control, multi-factor authentication where appropriate, network segmentation, backup and recovery procedures, logging and monitoring, vulnerability management, incident reporting, and supplier-security requirements. Significant incidents must be reported rapidly to the Danish Energy Agency, and cyber incidents must also be reported through the designated CSIRT mechanisms. The Order further establishes rules on inspections, confidentiality of sensitive information, sectoral crisis management, identification of critical entities, and enforcement, while repealing previous separate preparedness regulations for the oil, natural gas, electricity, and energy-sector IT preparedness regimes.
A major feature of the instrument is its detailed cybersecurity and critical-infrastructure protection regime, implementing parts of the EU NIS 2 Directive and the Critical Entities Resilience (CER) Directive. Energy companies must secure network and information systems through measures such as access control, multi-factor authentication where appropriate, network segmentation, backup and recovery procedures, logging and monitoring, vulnerability management, incident reporting, and supplier-security requirements. Significant incidents must be reported rapidly to the Danish Energy Agency, and cyber incidents must also be reported through the designated CSIRT mechanisms. The Order further establishes rules on inspections, confidentiality of sensitive information, sectoral crisis management, identification of critical entities, and enforcement, while repealing previous separate preparedness regulations for the oil, natural gas, electricity, and energy-sector IT preparedness regimes.
Attached files
Web site
Date of text
Entry into force notes
7 March 2025.
Repealed
No
Source language
English
Legislation Amendment
No
Original title
BEK nr 326 af 28/03/2025: Bekendtgørelse om tilskud til minivådområder 2024 og 2025.