Skip to content
defend.gl

NIS2 · DORA · GDPR · ISO 27001

Compliance advisory

NIS2, DORA and GDPR are no longer something you can freely opt in or out of. For a growing range of sectors, they have become a prerequisite for doing business at all. We guide Greenlandic businesses and public authorities safely through the requirements, focusing on documentation and controls that are actually used — not just filed away for the occasion.

Regulation

NIS2, DORA and GDPR — are you covered?

NIS2, DORA and GDPR are legal requirements for a growing range of sectors — not something you can freely opt in or out of, if you are covered. ISO 27001, by contrast, is a voluntary standard you can choose to be certified against. Several of the requirements presuppose documented technical security testing, such as a penetration test.

Legal requirement

NIS2

EU directive on network and information security for essential and important sectors.

Legal requirement

DORA

EU regulation on digital operational resilience in the financial sector.

Legal requirement

GDPR

Requirements for lawful and secure processing of personal data.

Voluntary standard

ISO 27001

International standard for an information security management system, which can be certified by an accredited body.

Greenland and the EU

Do EU rules even apply in Greenland?

Greenland is not a member of the EU or the EEA, but holds status as one of the EU's Overseas Countries and Territories (OCT). This means EU rules such as GDPR, NIS2 and DORA do not automatically apply to a purely Greenlandic activity simply because the business is based in Greenland. Greenland has its own data protection legislation.

In practice, most Greenlandic businesses and public authorities are affected by the requirements anyway — typically through three channels:

Customers and partners in the EU

If you work with or sell to businesses in Denmark or the rest of the EU, they often pass on NIS2, DORA or GDPR requirements to you as a supplier.

Data about people in the EU

If you process personal data about people in the EU, GDPR can apply to that specific processing — and transferring data from the EU to Greenland counts as a third-country transfer.

Supply chains

If you are a subcontractor to an organisation covered by NIS2, the security requirements can reach you via the contract — regardless of where you are geographically located.

The above is a general introduction, not legal advice. If you are unsure which requirements apply to you, you should seek qualified legal advice. Regardless, documented technical security testing — such as a penetration test — provides a solid foundation to stand on.

The challenge

From requirement to documentation

Compliance requirements like NIS2, DORA and GDPR are extensive, and without experience it's hard to know where to start, or whether your efforts cover what's actually required. If you lack documentation and evidence when a regulator, a customer or an auditor asks, you are not meeting the requirements — no matter how well secured you actually are.

Services

How we help

We are advisors, not a certification body. We help you prepare, test and document your security so you stand strong in the face of an external audit — but the actual ISO 27001 certification is issued by an accredited certification body, not by us.

NIS2

Assessing whether you are covered, and preparing for the directive's requirements on risk management, incident reporting and supplier security.

DORA

Helping financial businesses and their critical IT suppliers meet DORA's requirements for digital operational resilience.

GDPR

Mapping and implementation, so your processing of personal data meets GDPR.

ISO 27001

Help achieving and maintaining ISO 27001 certification, from gap analysis to certification audit.

Policies and procedures

Development of security policies and procedures tailored to your organisation — documentation that actually gets used.

The process

The journey

  1. Initial assessment

    We map your current security level and which of NIS2, DORA, GDPR and ISO 27001 are actually relevant to you.

  2. Gap analysis

    We compare your current practice with the requirements and identify what is missing.

  3. Implementation

    We help develop and implement the necessary policies, procedures and technical controls.

  4. Documentation and evidence

    We compile the documentation and evidence you need to be able to show a regulator, an auditor or a customer.

  5. Verification

    We review the implementation and prepare you for a possible certification audit.

Delivery

Documentation you can show

What you receive

A gap analysis, an implementation plan, and the documentation and evidence you need to demonstrate compliance with NIS2, DORA, GDPR or ISO 27001 — tailored to your organisation.

Ongoing follow-up

We can follow up with a renewed assessment when new requirements take effect, or ahead of recertification.

FAQ

Questions about compliance

No, the requirements often overlap. We map out which are relevant to you and build a joint effort instead of several separate projects.

NIS2 covers a broad range of sectors, including critical infrastructure and public institutions. Contact us, and we'll assess your situation.

DORA targets financial businesses and their critical IT suppliers. Contact us if you're unsure whether your organisation is covered.

Because non-compliance is increasingly not just a risk — it can prevent you from operating in a sector, entering agreements, or keeping customers who themselves must document their supply chain.

It depends on your starting point, but typically six to twelve months from gap analysis to certification audit.

Book a compliance assessment

Contact us for a no-obligation quote tailored to your needs.