Danish Energy Law and Access Control – What Executive Order 260 Requires

Since 7 March 2025, Danish Executive Order 260 sets concrete access control requirements for energy sites. Requirements, deadlines and supervision in one place.
7 min
Danish Energy Law and Access Control – What Executive Order 260 Requires

Since 7 March 2025, the Danish requirements for physical security and access control in the energy sector have been set out in one place: Act no. 258 of 6 March 2025 on strengthened preparedness in the energy sector (lov om styrket beredskab i energisektoren) and Executive Order no. 260 of 6 March 2025 on resilience and preparedness in the energy sector (bekendtgørelse om modstandsdygtighed og beredskab i energisektoren, BEK 260).

The order covers electricity, gas, oil, hydrogen, district heating and district cooling. It implements parts of the NIS 2 Directive and the CER Directive on the resilience of critical entities, and it repealed the previous sector orders – including the 2021 orders on preparedness for the electricity sector and on IT preparedness for the electricity and natural gas sectors (§ 123(2)).

This article brings together the parts of BEK 260 that deal with access: who may enter, how it is documented, and when it has to be in place. Quotations and section numbers refer to the Danish original, which is the only legally binding text.


Who is covered?

The Danish Energy Agency (Energistyrelsen) places companies in five levels (Annex 1) and their sites in five classes (Annex 2).

  • Level 1 only has to comply with a small part of the rules (§ 5) and is not covered by the physical security requirements.
  • Levels 2–5 must comply with the whole order and are also critical entities (§ 115(3)). This includes, for example, every electricity distribution system operator, district heating companies selling at least 181 GWh or with at least 50 employees, and gas distribution.
  • Chapter 10 on physical security applies to sites the Agency has classified (§ 2(2)) – and under § 7 also to offices used to deliver the service.

The access requirements

§ Requirement Deadline
37 Controlled access to sites: only approved and verified persons; a decision per part of the site on which employees and suppliers may enter, including unaccompanied; visitors in the same system; access logs attributable to a person; a check at least every six months 1 March 2026
40 Control log: a plan for the checks and a record of where, when, how, deviations found and how they were remedied With each check
7 and 38(2)(1) Controlled access to offices used to deliver the service 1 March 2027
38 Preventing and detecting unauthorised access: controlled access, physical protection, electronic surveillance and perimeter security 1 March 2027
39 Intrusion alarms to a 24/7 control room or a monitoring centre approved by the Danish National Police Not on the transition list in § 123
43 Unclassified locations holding critical components or network equipment: detection and alarm 1 March 2027
52–53 Access to IT systems: personal accounts, removal of inactive accounts, logging of changes, and MFA Not on the transition list in § 123
66–67 Logs (levels 4–5) from equipment supporting site access control: time-synchronised, stored separately, protected against tampering, kept for 13 months Not on the transition list in § 123
30–32 Supplier agreements: security requirements, incident notification, support with reporting and supervision When agreements are entered into

The deadlines for §§ 36–38, 43, 48, 50 and 62 do not apply to companies already covered by the old orders for electricity, gas and oil where the requirements are equivalent (§ 123(5)) – they already had to comply. The transition period was for sectors new to the rules, such as district heating.


Supervision and penalties

The Danish Energy Agency supervises companies at levels 4 and 5 every year, level 3 every third year and level 2 every sixth year (§ 108). Supervision is by sampling (§ 109), and a physical inspection is announced 21 days in advance (§ 110). The inspection report must be presented to management (§ 112(3)).

Breaches of, among others, §§ 24–76 are punishable by fines, and the company can be held liable as a legal person (§ 122).


Where SnapKey fits

SnapKey covers the access part – not surveillance and alarms.

Requirement SnapKey
§ 37(1)–(3): approved, verified and controlled access – including suppliers and visitors A personal key on the phone for a named person, per door and time window. Supplier keys expire on their own
§ 37(4): access logs attributable to a person Each opening the lock system reports is logged with person, door and time, stored separately from the locks in the EU
§ 37(5) and § 40(3)–(5): six-monthly check and control log Access review per location: who can open what and who has been there, with deviations, remedies, plans and follow-up on deviations left unremedied at the previous check. Closes with a locked control log as a single bilingual PDF (Danish and English), whose SHA-256 checksum is published on a verification page. After the first closed review, the location's compliance contacts, if any are set, are reminded when the next check is due. Mechanical keys outside SnapKey are recorded as manual findings. Responsibility for the check stays with you
§ 36(3): sites must withstand failure of IT and public networks The iLOQ cylinder is powered by the phone and opens without a network connection
§ 38(3): perimeter Gates and barriers can be run on the same access rights. Detecting intrusion requires alarm equipment
§§ 38–39 and 43: surveillance and alarms Not SnapKey. Requires alarm equipment and a 24/7 control room
§ 40: the other chapter 10 checks (§§ 36, 38, 39 and 42–43) Not SnapKey. Kept in your own control plan and log
§§ 52–53: access to the system itself Two-factor authentication can be enforced; single sign-on over SAML/OIDC; every change of rights in an audit log kept for 24 months
§ 50 (levels 4–5): EU/EEA Data hosted in AWS eu-north-1 (Stockholm) and kept in the EU/EEA

Our security documentation – hosting, encryption, logging and incident handling – is public at snapkey.dk/trust.


FAQ

Which Danish law sets access control requirements for the energy sector?

Act no. 258 of 6 March 2025 on strengthened preparedness in the energy sector and Executive Order no. 260 of 6 March 2025 on resilience and preparedness in the energy sector. Access control to sites is in § 37.

When did controlled access have to be in place?

§ 37 had to be implemented by 1 March 2026. The requirements in § 38 and § 43 to detect and alarm intrusion have a deadline of 1 March 2027. Companies already covered by the old rules for electricity, gas and oil had to meet equivalent requirements from the start.

Does SnapKey make us compliant with Executive Order 260?

No – no single product does. SnapKey provides the access control and the evidence for § 37. Surveillance and alarms, risk assessment, preparedness plans and management approval remain yours.


Get started

Want to know where your access control stands against § 37? We will go through your sites, doors, staff and suppliers with you.


Read more

This article is based on Danish Executive Order no. 260 of 6 March 2025 on resilience and preparedness in the energy sector and is not legal advice.