Intermediate Architecture

Norway — NSM Grunnprinsipper, Sikkerhetsloven, and the EEA Cloud Position

Norway is in the European Economic Area (EEA). The EEA Agreement extends most EU single-market regulation to Norway, including GDPR (directly applicable as Norwegian law via EEA incorporation), NIS1 through digitalsikkerhetsloven, and DORA, which has been in force in Norway since 1 July 2025. NIS2 has not yet been incorporated. On top of this EU-derived base, Norway runs a domestic layer: NSM Grunnprinsipper as ICT security guidance, Sikkerhetsloven for classified information, Finanstilsynet as financial-sector supervisor. For cloud providers operating in Norway — and Slovak organisations with Norwegian customers — the Norwegian regime is operationally close to EU expectations with some country-specific procedural plumbing. This article walks through the framework.

The system at a glance

The Norwegian framework operates on three layers:

  • EEA-derived EU regulation — GDPR directly applicable; NIS1 in force through digitalsikkerhetsloven, NIS2 still awaiting EEA incorporation; DORA in force since 1 July 2025.
  • Domestic legislation — Sikkerhetsloven (National Security Act) for classified information; sector-specific regulation for finance, healthcare, energy.
  • NSM guidance — Grunnprinsipper for IKT-sikkerhet plus NSM Cloud Strategy and Guidance, principle-based rather than prescriptive.

Like Switzerland and the UK, Norway has no central cloud certification scheme analogous to Slovak KsVC or Italian ACN. Cloud assessment happens at procurement time against the published principles and sector-specific obligations.

Key institutions:

  • NSM (Nasjonal sikkerhetsmyndighet, National Security Authority) — issues Grunnprinsipper, supervises Sikkerhetsloven, coordinates broader cybersecurity matters.
  • Datatilsynet — data protection supervisor (Norwegian DPA).
  • Finanstilsynet — financial sector supervisor.
  • NHN (Norsk Helsenett) — operates the Norwegian health network infrastructure, sets healthcare cloud expectations.

Legislative basis

The legislative stack:

  • Personopplysningsloven — Norwegian Personal Data Act, which incorporates GDPR as Norwegian law via the EEA Agreement. GDPR’s substantive content applies directly.
  • Sikkerhetsloven (National Security Act) — covers classified-information handling and security clearance for the public sector and identified critical infrastructure operators.
  • Forskrift om sikkerhetsadministrasjon — implementing regulation under Sikkerhetsloven.
  • Digitalsikkerhetsloven (LOV-2023-12-20-108) — the Norwegian implementation of the NIS1 Directive, sanctioned 20 December 2023 and in force since 1 October 2025. NIS2 transposition is a separate, still-unfinished exercise.
  • Finansforetaksloven — Financial Institutions Act, governing banking, insurance, and securities supervision under Finanstilsynet.
  • Helselovgivning — health sector legislation including specific provisions on health data processing.

The Norwegian model is principle-based regulation with sectoral overlays — broader than Switzerland’s bilateral integration but operationally similar in its non-catalogue, non-multi-tier approach to cloud.

Scope of obligation

Different parts of the framework apply to different actors:

  • GDPR (via Personopplysningsloven) — all personal data processing.
  • Sikkerhetsloven — public-sector entities and identified critical infrastructure operators handling classified information.
  • Digitalsikkerhetsloven — operators of essential services and digital service providers above size thresholds; NIS2 will widen this when transposed.
  • Finanstilsynet — banks, insurers, securities dealers, payment institutions.
  • NSM Grunnprinsipper — recommended for all public-sector entities and critical infrastructure; voluntary for commercial sector.

For cloud providers, the operative obligations flow through the customer’s regulatory status. A CSP serving Norwegian banks engages with Finanstilsynet expectations; a CSP serving Norwegian public sector engages with NSM Grunnprinsipper and (potentially) Sikkerhetsloven; a CSP serving Norwegian commercial customers engages primarily with GDPR via Personopplysningsloven.

Classification model

Norway uses the standard EU/NATO classification levels for classified information under Sikkerhetsloven:

LevelNorwegian designationEquivalent
BEGRENSETRestrictedEU RESTRICTED / NATO RESTRICTED
KONFIDENSIELTConfidentialEU CONFIDENTIAL / NATO CONFIDENTIAL
HEMMELIGSecretEU SECRET / NATO SECRET
STRENGT HEMMELIGStrictly SecretEU TOP SECRET / NATO COSMIC TOP SECRET

For commercial / non-classified information, the NSM Grunnprinsipper apply as guidance without formal classification levels. Cloud services for classified-information processing face strict requirements including sovereignty considerations; cloud services for non-classified information have a much lighter regime.

Evaluation criteria — NSM Grunnprinsipper

The Grunnprinsipper for IKT-sikkerhet are organised across four categories with 21 principles:

CategoryFocus
Identifisere og kartleggeIdentify and map systems, information, dependencies
Beskytte og opprettholdeProtect and maintain
OppdageDetect incidents and anomalies
Håndtere og gjenoppretteHandle and recover from incidents

Each principle has supporting recommended measures and implementation guidance. The principles map cleanly to ISO/IEC 27001/27017 and the NIST Cybersecurity Framework — Norwegian organisations holding NIST CSF or ISO 27001 alignment satisfy most of the Grunnprinsipper expectations.

NSM additionally publishes specific guidance for cloud services, addressing:

  • Risk assessment methodology for cloud adoption.
  • Supplier selection and due diligence criteria.
  • Jurisdictional and data-location considerations.
  • Continuity and exit strategy expectations.
  • Information classification mapping to cloud service tiers.

Evaluation criteria — Sikkerhetsloven

For classified information, Sikkerhetsloven imposes detailed requirements including:

  • Personnel security clearance for individuals with access.
  • Facility security clearance for entities handling classified information.
  • System security clearance for the IT infrastructure processing classified data.
  • Operational security plans with NSM review and approval.

Cloud services processing classified information must meet the Sikkerhetsloven requirements — which in practice means national cloud arrangements or accredited Norwegian-controlled providers rather than commercial hyperscaler regions. For BEGRENSET and below, some flexibility exists; for KONFIDENSIELT and above, strict requirements apply that exclude most commercial cloud arrangements.

The assessment process

The framework operates through customer-side assessment:

  1. Customer (data controller) assesses the cloud provider against NSM Grunnprinsipper, sectoral requirements, and GDPR expectations.
  2. Standard evidence requested: ISO 27001/27017/27018, SOC 2 Type 2, BSI C5, EU Cloud Code of Conduct Level 2.
  3. Finanstilsynet-supervised entities report material outsourcing arrangements; Finanstilsynet can inspect.
  4. NSM-supervised entities (classified-information handlers) require formal NSM approval of cloud arrangements above identified thresholds.
  5. Datatilsynet monitors compliance with Personopplysningsloven and can investigate complaints.

There is no Norwegian-specific cloud certification a CSP can obtain. The evidence base is the standard international portfolio plus Norwegian-context documentation.

Catalogue and recertification

There is no central public catalogue of approved cloud services. NSM does maintain internal records of formally approved arrangements for classified-information processing, but these are not publicly searchable.

Recertification cadence follows the underlying attestations (ISO 27001 3-year cycle, SOC 2 annual, BSI C5 annual). For Sikkerhetsloven-approved arrangements, periodic NSM reassessment applies on a case-by-case basis.

Sanctions and oversight

Sanctions vary by regime:

  • GDPR via Personopplysningsloven — Datatilsynet can impose GDPR-level fines, up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher.
  • Digitalsikkerhetsloven / NIS2 — when NIS2 is transposed, NIS2-level sanctions will apply (up to EUR 10 million or 2% of global turnover for essential entities, smaller amounts for important entities).
  • Sikkerhetsloven — supervisory measures by NSM; classified-information mishandling falls under Norwegian criminal law for serious cases.
  • Finanstilsynet — supervisory measures including licensing consequences for serious violations.

Norway and NIS2

As an EEA state, Norway is implementing NIS2 through the EEA Joint Committee incorporation process. Once complete, Norway will have NIS2-equivalent obligations for essential and important entities including digital infrastructure cloud providers. The Norwegian cybersecurity supervisor for NIS2 will be NSM working in coordination with sector regulators.

NIS2 transposition is still in progress. Interim coverage comes from digitalsikkerhetsloven, which implements NIS1 and only entered into force on 1 October 2025 — so Norway had no NIS implementation in force at all before that date. Its scope is narrower than NIS2. Cloud providers above the NIS2 size thresholds operating in Norway should expect the NIS2 essential-entities obligations to apply once transposition completes.

Norway and DORA

DORA is already in force in Norway. The regulation was taken into the EEA Agreement on 20 February 2025, and both the DORA Act (lov 27. mai 2025 nr. 18) and the DORA regulation (DORA-forskriften, FOR-2025-06-24-1296) took effect on 1 July 2025. Norwegian financial entities are subject to DORA obligations today. Finanstilsynet is the operative supervisor; the EEA arrangement creates coordination obligations with the EU ESAs for cross-border supervision.

For cloud providers serving Norwegian financial entities, the path of regulatory engagement runs through Finanstilsynet, and the ESA-led CTPP designations already reach their providers — the first 19 CTPPs were designated on 18 November 2025.

Sovereignty posture

Norway does not impose explicit sovereignty rules on commercial cloud providers — no ownership caps, no headquartering requirements, no immunity-from-extraterritorial-law clauses.

For classified information under Sikkerhetsloven, Norwegian-specific handling requirements effectively limit foreign-controlled providers from the most sensitive classified tiers. This functions as de facto sovereignty for that tier without the explicit ownership rules of SecNumCloud.

For personal data, EEA membership means GDPR’s transfer chapter applies directly. EU/EEA data flows are unrestricted; third-country transfers require SCCs or equivalent.

For financial sector data, Finanstilsynet’s supervisory expectations include geographic and jurisdictional risk assessment but do not categorically exclude foreign-controlled cloud providers. Major hyperscalers operate in the Norwegian financial market under Finanstilsynet-supervised arrangements.

Cross-border data flow patterns

Norway’s EEA position makes cross-border data flow with the EU operationally identical to intra-EU flow:

  • EU ↔ Norway: treated as intra-EEA. No SCCs or supplementary measures required.
  • Norway → US: covered by Norwegian Data Privacy Framework (EEA participation in EU-US DPF).
  • Norway → other third countries: SCCs or BCRs required with Datatilsynet supervision.

For Slovak organisations operating in Norway or with Norwegian customers, EEA membership makes data flow straightforward. The Norway-specific work is contractual (Norwegian DPA annex) and procedural (Datatilsynet, NSM awareness) rather than fresh substantive compliance.

Cloud provider posture for Norway

For a cloud provider serving Norway in addition to the EU:

  • NSM Grunnprinsipper alignment for public-sector and critical-infrastructure customers — typically demonstrated through ISO 27001/27017 mappings.
  • Datatilsynet awareness for personal-data processing — operationally similar to other EU DPAs.
  • Finanstilsynet engagement for financial-sector customers — outsourcing notification expectations.
  • Sikkerhetsloven compliance if processing classified information — typically requires Norwegian-controlled infrastructure for KONFIDENSIELT and above.
  • NIS2 readiness as the transposition completes through EEA incorporation.

The marginal Norwegian-specific work over a strong EU baseline is moderate. The ISO baselines, SOC 2, BSI C5, EU Cloud CoC, and NIS2 supply-chain work all carry forward; the country-specific additions are contractual and procedural rather than fresh substantive control work.

Architectural Pro Tip

For a CSP serving Norwegian financial-sector customers, the most efficient additional work over an EU baseline is a Finanstilsynet outsourcing notification template that maps existing audit rights, exit strategies, incident reporting commitments, and data location declarations to Norwegian supervisor expectations. DORA has applied in Norway since 1 July 2025 and the CTPP-designation process is live; cloud providers expecting designation should engage early with Finanstilsynet to align with the supervisory model. The substantive content overlaps heavily with DORA Article 30 contractual requirements.

Multicloud factor

Norway is operationally one of the simpler European markets to extend an EU compliance programme into:

  • EEA membership means EU rules apply directly. Most evidence is portable.
  • No Norwegian-specific cloud certification to obtain — principle-based regime.
  • Marginal additions: NSM Grunnprinsipper mapping document, Norwegian DPA annex, Finanstilsynet outsourcing notification template for financial-sector contracts.
  • For classified-information processing, Norwegian-controlled infrastructure is typically required — limited overlap with mainstream hyperscaler offerings.

Microsoft operates Norwegian regions (Azure Norway East/West) for customers with Norwegian data residency requirements. AWS has no announced Norwegian region — its published expansion plans name only Saudi Arabia and Chile — and serves Norwegian residency needs from eu-north-1 in Stockholm; EU-region services are commonly used for Norwegian customers under EEA-equivalent treatment. Google Cloud has no Norwegian region as of mid-2026; Norwegian customers consuming Google services use EU-region endpoints under EEA-equivalent treatment.

Reality Check

The “Norway is outside the EU” framing leads to misunderstandings. EEA membership means most EU rules apply directly to Norway, including GDPR, digitalsikkerhetsloven (NIS1, with NIS2 to follow), and the financial-sector regulations, DORA among them. For practical purposes, treat Norway as adjacent to the EU market requiring contractual and procedural additions, not a fundamentally separate regulatory environment. Cloud providers that scope Norway as a standalone compliance project consistently over-estimate the work; cloud providers that scope it as an “EU plus a Norwegian annex” estimate correctly.

Closing checklist

  • Norway operates a layered framework: EEA-incorporated EU regulation (GDPR, NIS1 via digitalsikkerhetsloven, DORA since July 2025) + domestic Sikkerhetsloven for classified information + sector-specific regulation + NSM Grunnprinsipper as guidance.
  • NSM Grunnprinsipper are 21 principles across 4 categories. Map cleanly to ISO 27001/27017 and NIST CSF.
  • Sikkerhetsloven governs classified-information handling under standard EU/NATO levels (BEGRENSET → STRENGT HEMMELIG). Effectively limits foreign providers for the higher tiers.
  • GDPR applies directly via EEA incorporation; Datatilsynet is the supervisor. EU↔Norway data flow is intra-EEA.
  • DORA has applied since 1 July 2025. NIS2 is still being prepared for EEA incorporation; digitalsikkerhetsloven (NIS1) has covered the gap since 1 October 2025.
  • Finanstilsynet is the financial supervisor. Outsourcing notification expectations align with broader European supervisory practice.
  • No central cloud catalogue, no multi-tier service classification. Procurement-flexible regime; assessment is customer-side.
  • For Slovak organisations: Norwegian customers are operationally similar to EU customers in cloud terms. EEA membership simplifies cross-border data flow.
  • For cloud providers: marginal additions to an EU baseline are contractual annexes (Norwegian DPA, Finanstilsynet template) and mapping documents (Grunnprinsipper → ISO 27001 mapping), not fresh substantive control implementation.
  • See Switzerland article for the parallel non-EEA adjacent jurisdiction, UK NCSC article for the post-Brexit adjacent regime, NIS2 supply chain article for the supply-chain expectations that flow through EEA incorporation, and DORA article for the financial-sector framework that has applied in Norway since July 2025.

References

NSM — National Security Authority of Norway The Norwegian National Security Authority (Nasjonal sikkerhetsmyndighet) — issues the Grunnprinsipper for IKT-sikkerhet and oversees critical-infrastructure cybersecurity. nsm.no NSM Grunnprinsipper for IKT-sikkerhet The Basic Principles for ICT Security published by NSM — the Norwegian government's recommended framework for ICT security including cloud. nsm.no Digitalsikkerhetsloven (LOV-2023-12-20-108) Norway's Act on digital security, sanctioned 20 December 2023 and in force from 1 October 2025 — the NIS1 implementation via EEA Agreement Annex XI no. 5cpa. lovdata.no DORA-forskriften (FOR-2025-06-24-1296) The Norwegian DORA regulation, in force 1 July 2025 under the DORA Act of 27 May 2025 no. 18 — the instrument that made DORA operative in Norway. lovdata.no Sikkerhetsloven (National Security Act) The Norwegian National Security Act covering classified-information handling, security clearance for personnel and entities, and supervisory powers for NSM. lovdata.no Datatilsynet — Norwegian Data Protection Authority The Norwegian data protection supervisor — administers GDPR as incorporated into Norwegian law through the EEA Agreement. datatilsynet.no Finanstilsynet — Financial Supervisory Authority of Norway The Norwegian financial supervisor, overseeing banks, insurers, and securities firms including their cloud and outsourcing arrangements. finanstilsynet.no NSM Cloud Strategy and Guidance NSM's specific guidance on cloud services for public sector and critical infrastructure, including risk assessment, supplier selection, and jurisdictional considerations. nsm.no