
regulation and compliance consulting
From regulation and compliance in silos. To a coordinated approach embedded in senior management
There is a growing amount of regulation coming into force, and alongside it there follows an increasing compliance burden. We help organisations translate regulation and legal requirements into concrete reality. From the correct scoping and interpretation of legal requirements to a coordinated compliance effort that supports day-to-day operations.

Compliance is a management responsibility and requires a coordinated approach
Compliance can be approached in many different ways. The challenge lies in bringing these efforts together and embedding them across the organisation.
There is an increasing volume of legislation coming from Denmark and, even more so, the EU. As a consequence of this, the compliance burden faced by organisations is also growing. The GDPR, the NIS2 Directive, DORA and the AI Act are some of the regulations that organisations must now address, and in many cases comply with. This is no easy task. How does one assess whether an organisation is covered by the legislation, and to what extent? How does one translate the legal text into concrete reality, whilst ensuring that the company’s core operations remain a priority?
Compliance is a management responsibility, and responsibility for compliance must be embedded at executive and board level. It is at senior management level that one ensures compliance tasks are aligned with the rest of the organisation. The aim is for compliance work to support the security strategy that brings business processes, technology, risks and resources together into one single integrated security model.
At Vaern, we help to create coherence between the management level, governance, compliance and operational security. Ranging from interpreting and correctly scoping legal requirements to ensuring there is a coordinated implementation where strategic requirements are translated into concrete practices. This results in a more agile compliance process and a better foundation for continuous compliance.
Our compliance consultancy is based on a high level of professional expertise and specialised skills within security and regulation. The work is carried out by experienced consultants with relevant qualifications and certifications, who can translate complex requirements into solutions that work in practice.
Selected services within regulation and compliance
Scope and interpretation of requirements
We clarify whether and to what extent the organisation is covered by NIS2, DORA, GDPR, CRA, CER and the AI Act. We then translate the legal text into specific requirements. The risk assessment ensures that efforts are prioritised in relation to the organisation’s actual risks and core operations.
Assessments and gap analyses
We assess the organisation’s compliance with CER, CRA, GDPR, NIS2 and DORA and identify the gap between legal requirements and current practice through gap analyses and maturity assessments. The result is a prioritised overview of where efforts should be focused.
Implementation of requirements
We translate regulatory requirements into compliance processes, governance structures and documentation that are consistent across different regulatory frameworks. Existing security measures are reused to ensure that compliance does not result in new silos
Technical security controls
We establish the organisational and technical controls required by legislation, such as access control, logging and monitoring, network segmentation and cryptography, as well as vulnerability management, hardening and secure configuration. Backup, recovery and technical contingency planning ensure that the organisation can get back on its feet following an incident.
Managed compliance
We operate compliance and governance functions as an ongoing service or take on interim roles, including as DPO, CISO or the roles defined in the Act on Strengthened Preparedness in the Energy Sector (NIS2 and CER), when the organisation lacks the necessary expertise or capacity for a period of time.
how we work
Vaern's approach to regulation and compliance
Many regulations are written for management level but must be implemented in day-to-day operations. This applies, for example, to requirements regarding risk management, logging, monitoring, segmentation and security controls. As a result of this, we often see a gap between those working on governance and compliance and those responsible for technical security in day-to-day operations.
When we carry out tasks, we ensure that both dimensions work in a coordinated manner. The operational teams know which security legislation they are helping to underpin through the technical infrastructure. And the strategic level understands how operational security supports the organisation’s operational responsibilities.
The feedback we most often receive from clients is that they feel they are being guided safely and effectively through the compliance process. We assign senior staff to all compliance tasks, and clients work with the same specialists throughout the entire process. This ensures continuity, as well as a high level of expertise and a smoother implementation.
Many organisations are inundated with parallel compliance projects
Although not their intention, organisations often end up handling compliance with new regulations as a set of stand-alone projects. Working groups are set up, each operating in their own silos, working on separate documentation requirements and technical initiatives.
This silo approach persists even though there are in fact many common elements in compliance work that cut across both Danish and EU legislation, such as the requirement to carry out risk assessments systematically. Although the individual regulations have different protection objectives and risk focuses, the methodology, governance structure and parts of the data set can often be reused across compliance work.
Furthermore, interpreting a legal text and correctly scoping the subsequent compliance task is known to be very challenging. Some security providers attempt to address this by launching security products or designing predefined compliance programmes that are one-size-fits-all. This rarely leads to successful implementation or ongoing compliance. On the contrary, it often contributes to widespread frustration and a sense of ‘compliance fatigue,’ constructing so-called ‘paper tigers’ with no real value.
Regulation sets requirements. Standards help with compliance
Regulations are often confused with standards and frameworks for information security. However, there is a significant difference. Standards and frameworks such as ISO 27001, NIST CSF and CIS18 are something you can choose to work with. Regulations such as NIS2, DORA and the GDPR, on the other hand, are legislation that must be complied with if the organisation falls within their scope. The set of rules that may be applicable depend on the sector and type of organisation, and sector-specific legislation may even take precedence in some cases. For example, financial organisations are primarily regulated by DORA and financial sector legislation rather than NIS2.
In day-to-day operations, however, work on standards, frameworks and regulations can often be closely interlinked. Many organisations use standards and frameworks as the structure that helps to operationalise regulatory requirements. This applies, among other things, to risk assessments, the establishment of a governance structure and the implementation of access control, where the same security disciplines often appear multiple times across different regulatory frameworks.
Consequently, compliance work is rarely about building entirely new security measures from scratch, but rather about creating a comprehensive governance model in which existing security measures can be documented, adapted and reused across different regulatory requirements.

Integrated security brings everything and everyone together in a single model
As the world becomes more complex and unpredictable, there is a growing need for security services that can strengthen organisational resilience. We deliver integrated security because shared objectives, coherence and coordination increase our ability to act and provide the best protection against security incidents.
FAQ
This depends, among other things, on the organisation’s sector, size, activities and its role in the value chain. NIS2, DORA, CER, CRA and the AI Act have different scopes and requirements, and there may also be sector-specific legislation or roles in relation to the AI Act that need to be taken into account. Correct scoping is therefore an extremely important first step. An assessment of the organisation’s regulatory scope provides an overview of which requirements apply and where efforts should be prioritised.



