Defence Contracts 2026 Comparisons

Last Updated September 23, 2026

Law and Practice

Authors



Advokatfirmaet Thommessen AS was established in 1856 and is one of Norway's leading commercial law firms, with offices in Oslo, Bergen, Stavanger and London. The firm advises Norwegian and international companies across the public and private sectors, covering all business-related fields of law. Thommessen assists businesses with transactions, complex projects and contentious matters in all areas of commercial law, combining robust legal expertise with in-depth industry knowledge to provide advice that facilitates long-term value creation. It offers unique advisory services to defence industry suppliers, combining legal expertise in complex procurement contracts with extensive experience from the Norwegian Armed Forces and a deep understanding of national security issues. The team advises on defence and classified procurements, IT projects in the defence and security sector, complex defence contract negotiations, transactions involving defence sector entities – including FDI requirements and compliance with the Norwegian Security Act – and strategic guidance on evolving threat and risk landscapes.

The regulatory framework applicable to enterprises operating in the defence sector is composed of several overlapping statutes and regulations, among which the following are of particular relevance: the Security Act (sikkerhetsloven) and its key secondary legislation – the Enterprise Security Regulation (virksomhetsikkerhetsforskriften) and the Clearance Regulation (klareringsforskriften); the Public Procurement Act (anskaffelsesloven) and the Defence and Security Procurement Regulation (forskrift om forsvars- og sikkerhetsanskaffelser, FOSA), the Export Control Act (eksportkontrolloven) and the Export Control Regulation (forskrift om eksport av forsvarsmateriell, flerbruksvarer, teknologi og tjenester), supplemented by guidelines; the Sanctions Act (sanksjonsloven); the Emergency Preparedness Act (beredskapsloven), the Industrial Preparedness Act (næringsberedskapsloven); and the Digital Security Act (digitalsikkerhetsloven).

The regulatory landscape for the defence sector is administered by a range of authorities.

The Ministry of Defence has overarching responsibility for defence policy, capability planning, and the procurement regulatory framework. It issues the internal procurement rules (RAF), which govern all defence sector procurements including those exempted from the statutory framework.

The Norwegian Defence Materiel Agency (Forsvarsmateriell, FMA), a separate agency under the Ministry of Defence, is the principal contracting authority for defence procurement. FMA also administers industrial cooperation (offset) agreements on behalf of the Ministry of Defence.

The Defence Estates Agency (Forsvarsbygg) procures construction and works contracts related to defence real estate.

The National Security Authority (Nasjonal sikkerhetsmyndighet, NSM) holds the cross-sectoral supervisory mandate for preventive security work under the Security Act.

The sectoral ministries – particularly the Ministry of Justice and the Ministry of Defence – are responsible for identifying fundamental national functions, designating protectable objects and infrastructure, and processing FDI notifications under the Security Act.

The Civilian National Security Clearance Authority (Sivil klareringsmyndighet) and the Defence Security Agency (Forsvarets sikkerhetsavdeling) handle clearances of personnel in the civil and defence sectors, respectively.

The Directorate for Export Control and Sanctions (Direktoratet for eksportkontroll og sanksjoner, DEKSA) administrates export control and sanctions, and is the licensing authority for all exports of controlled goods, technology and services, and also handles enquiries under all Norwegian sanctions regimes.

The Ministry of Foreign Affairs retains high-level responsibility, mainly for foreign policy development and regulatory drafting.

The Complaint Board for Public Procurement (Klagenemnda for offentlige anskaffelser, KOFA) handles complaints on procurement procedures under the general procurement framework, as well as within the defence sectors. The general courts have jurisdiction over procurement disputes under the procurement regulations, including FOSA, with powers to set aside decisions before contract signing and to award damages.

For regulatory purposes, defence goods, services and technology, and dual-use items, are defined through the export control legislation. The Export Control Regulation provides the operative definitions by reference to two control lists: a “defence-related product” is any product listed in List I (Appendix I to the Regulation), while a “dual-use item” is any product listed in List II (Appendix II). The distinction is accordingly list-based rather than conceptual.

There are no distinct or separate statutory definitions of these terms under other legislation.

Norway’s defence regulatory framework rests on both national legislation and international commitments. The Defence Act and Security Act – including the FDI regime – are based on national legislation.

As a founding member of NATO, Norway’s defence policy and capability planning are aligned with NATO’s deterrence and defence posture. Through the EEA Agreement, Norway is party to the EU’s procurement directives – including EU Directive 2009/81, implemented through FOSA – as well as the general procurement directives (2014/23, 2014/24, 2014/25).

EEA Agreement Article 123 – corresponding to TFEU Article 346 – provides the essential security interest exemption. The Intra-Community Transfers Directive (2009/43) is implemented through the export control framework. Norway participates in the Wassenaar Arrangement, and its dual-use control lists directly reflect the Wassenaar and other multilateral regime lists.

Norway is a state party to the Arms Trade Treaty.

UN Security Council arms embargoes and sanctions are implemented through dedicated national regulations, administered by DEKSA.

All public procurements with a value of NOK500,000 or more are subject to the Public Procurement Act (LOA), unless exempted by specific exemptions (see below for further information).

The procurement regulations – including the general Regulation on Public Procurement (FOA) (implementing EU Directive 2014/24), the Regulation on Defence and Security Procurements (FOSA) (implementing EU Directive 2009/81), the Regulation on Procurements in the Supply Sector (FYF) (implementing EU Directive 2014/25) and the Regulation on Concession Contracts (implementing EU Directive 2014/23) – are sorted under LOA.

FOSA applies to contracts for defence materiel and components, classified material, works, goods and services directly related to such materiel and its life cycle, and classified works and services for defence purposes. FOSA requires restricted procedures or negotiated procedures with prior publication, and permits competitive dialogue for particularly complex contracts.

The most significant exemption is EEA Agreement Article 123 (TFEU, Article 346), permitting Norway to derogate from procurement rules entirely where necessary to protect essential security interests relating to arms, ammunition and war materiel, or where disclosure of information would be contrary to essential security interests. If invoked, the procurement is exempted from both LOA and the applicable regulation in whole. FOSA also excludes R&D cooperation projects between EEA states, contracts governed by international organisation rules, and contracts for stationing troops abroad where local supply is operationally necessary.

Additionally, the Security Act imposes supplementary requirements for classified procurements which overlay the procedural rules in FOSA (see 2.4 Restricted and Classified Procurement).

For all defence procurements, the internal Guidelines on Acquisitions in the Defence Sector (Retningslinjer for anskaffelser i forsvarssektoren (RAF)) also apply, including to procurements exempted under Article 123. RAF is an internal instrument and does not confer rights, nor impose obligations, on third parties.

The procurement legislation applies to all contracting authorities – whether central government ministries, subordinate agencies, county authorities or municipalities – and it is the nature of the procurement, not the identity of the contracting authority, that determines which regulatory regime applies. Any public body procuring defence materiel, classified goods or services for specific defence purposes will fall within the scope of FOSA, regardless of whether it is a defence entity.

In practice, the principal contracting authority in the defence sector is FMA, which also frequently conducts procurements on behalf of other government bodies, such as the Ministry of Defence, NSM and PST. The Defence Estates Agency procures construction and works contracts related to Armed Forces real estate (see 1.2 Competent Authorities).

All public procurements in Norway – whether goods, services or construction works – with a value of NOK500,000 or more (excl. VAT) are subject to LOA.

Procurements concerning defence materiel, classified material, works, goods and services directly related to such materiel and its life cycle, or classified works and services for defence purposes fall within FOSA. Contracts not meeting FOSA criteria are governed by general procurement regulations unless exempted (see 2.1 Defence Procurement Legislation).

FOSA covers supply of “defence materiel” (including weapon systems, ammunition, vehicles and sub-components), supply of “classified materiel”, maintenance, repair and support services through the life cycle, military construction works, classified construction works, classified services, and R&D services (provided the contracting authority fully funds and retains the results).

FOSA operates with a two-tier threshold structure:

  • Part I sets out fundamental principles such as competition, non-discrimination and proportionality, and applies to all defence and security procurements valued at NOK500,000 or above.
  • Part II implements EU Directive 2009/81, imposes the full procedural regime (see 2.5 Tender Procedures for Defence Contracts) and applies above the EEA thresholds of NOK5 million (excluding VAT) for supply and service contracts and NOK62.9 million (excluding VAT) for construction contracts.

A “classified procurement” (sikkerhetsgradert anskaffelse) is defined in Security Act Section 9-1 as any procurement where the supplier may gain access to, or will produce, classified information, or gain access to object or infrastructure considered as nationally critical under Security Act, Chapter 7. Therefore, when a procurement is classified, the requirements of the Security Act apply in addition to the procedural rules of FOSA.

Before a classified procurement is initiated, the contracting authority must enter into a security agreement (sikkerhetsavtale) with the supplier. Suppliers requiring access to information classified at CONFIDENTIAL level or above must hold a valid facility security clearance (leverandørklarering), which is granted only where there is no reasonable basis for doubting the supplier’s security suitability and must be re-evaluated if the supplier’s ownership structure, board composition or management changes (Section 9-3).

For foreign suppliers, the contracting authority must request that NSM arrange for the competent authority in the supplier’s home state verify that the supplier meets the relevant clearance requirements (FOSA, Section 3-16). Individual personnel who will access classified information must hold personal security clearances at the appropriate level.

  • FOSA Part II – above EEA thresholds: For defence and security procurements exceeding the EEA thresholds (see 2.3 Types of Contracts and Value Thresholds), FOSA Part II imposes the full procedural regime derived from EU Directive 2009/81. Contracting authorities must use either a restricted procedure or a negotiated procedure with prior publication; competitive dialogue may be used for particularly complex contracts. Contracts must be published in Doffin and TED. FOSA Part II also includes detailed rules on qualification criteria, technical specifications, supply security requirements, award criteria, standstill periods and remedies. RAF Parts I and II apply as additional internal procedural requirements (see 2.1 Defence Procurement Legislation).
  • FOSA Part I – between NOK500,000 and EEA thresholds: Below the EEA thresholds, FOSA Part I applies, according to the fundamental procurement principles – competition, non-discrimination, proportionality and documentation – supplemented by simplified procedural protocols in the FOSA annexes. RAF Parts I and II likewise apply.
  • Article 123 – exempted procurements: Where a procurement is wholly exempted under Article 123, the contracting authority is not bound by LOA, FOA or FOSA, but must comply with RAF Part III and ensure traceability throughout. Competition remains the default, and exceptions must be justified in writing (see 2.6 Direct Contract Awards and Single-Source Procurement). Open tendering is prohibited; the contracting authority selects qualified suppliers. RAF Part III also prescribes rules on qualification, tender documentation, evaluation criteria and negotiation procedures, but does not create enforceable third-party rights. Procurements in the defence sector that do not fall within FOSA’s scope – for instance, non-sensitive goods or services without a defence-specific character – are conducted under the general procurement regulations (FOA or the other applicable regulations).

Direct contract awards and single-source procurement are permitted, but only in defined circumstances and subject to specific controls.

FOSA permits negotiated procedure without prior publication – the closest equivalent to a direct award in FOSA – only in narrowly defined circumstances, including: where no suitable tenders have been received; where only one supplier can perform the contract for technical reasons or exclusive rights; where strictly necessary urgency caused by unforeseeable events precludes normal timescales; where additional deliveries from the original supplier are necessary for interchangeability or interoperability; and for repetition of similar works or services. These exceptions must be interpreted restrictively.

Procurements exempted under Article 123 are not subject to statutory restrictions on single-source procurement, but remain governed by RAF Part III. Competition is the default, with exceptions only where national security interests require it, where only one supplier can meet requirements, for minor supplementary orders to cover unforeseen needs, or where unforeseen circumstances prevent deferral. Every exemption must be documented.

Where procurement is conducted without competition – or where competition has failed (eg, only one tender received), the contracting authority must carry out a cost control review for contracts exceeding NOK5 million (excluding VAT), with full access to the supplier’s cost data and records.

Norway imposes industrial co-operation (offset) obligations on foreign defence contractors under the Regulations for Industrial Cooperation related to Defence Acquisitions from Abroad (BIF), Annex 6 to RAF. Industrial co-operation applies only to procurements justified under Article 123 – not to procurements under FOA or FOSA to the extent governed by EU/EEA-derived rules.

An industrial co-operation agreement must be concluded before the main contract is signed. The obligation applies to all foreign defence procurements exempted under Article 123 with a contract value of NOK100 million or above (excluding VAT). Where subsequent options bring the cumulative value above NOK100 million within five years, the obligation is triggered. For major acquisitions valued at NOK500 million or above, a dedicated industrial co-operation plan must be prepared early in the procurement.

The supplier must commit to industrial co-operation with a total value of up to 100% of the contract value. At least 50% of the obligation must be fulfilled in Category I (strategic projects – projects of strategic importance to the Armed Forces or national security). A maximum of 25% may be fulfilled in Category III (projects related to the protection of fundamental national functions outside the defence sector).

Qualifying industrial co-operation projects include technology collaboration and joint R&D; market development and access assistance; purchases of defence and security-related products from Norwegian industry; and transfer of technology and knowledge to a Norwegian partner. Direct offset (sub-contracting to Norwegian industry for the specific procurement) is not a default requirement, but may be imposed in specific cases.

Failure to meet milestones, or to fulfil the obligation by the end of the agreement period, triggers compensation of at least 10% of the outstanding value, secured by bank guarantee. Non-compliance is factored into evaluation of future bids and persistent default may result in exclusion. FMA administers all industrial cooperation agreements on behalf of the Ministry of Defence.

FOSA, Section 8-8 allows the contracting authority to impose security of supply requirements as qualification or contractual requirements, covering supply chain organisation and location, production capacity in a crisis, notification of changes, maintenance and modernisation, and the supplier’s export control status.

At a systemic level, the Security Act requires entities to assess whether a procurement to a protectable information system, object or infrastructure could entail a non-negligible risk that the asset is compromised, in which case the responsible ministry must be notified and the King in Council may prohibit or impose conditions (see 5.6 Supply Chain Security). Enforcement is primarily contractual, but suppliers breaching supply security obligations may be excluded for serious professional misconduct (see 2.10 Exclusion Grounds), and NSM supervises classified procurement suppliers.

In general, all public procurement, including defence procurements under FOSA, must award the contract based on the most economically advantageous tender. Hence, contracting authorities may award on the basis of either the best price-quality ratio or the lowest price, and must specify the applicable criteria and their weighting in the tender documentation.

FOSA Part II permits contracting authorities to set detailed qualification and award criteria relating to technical capability, supply security (including requirements for the supplier’s organisational and geographic supply chain resilience), and whole-life cost. The definition of “life cycle” in FOSA is broad, extending from R&D through to disposal, which enables whole-life costing as an evaluation methodology.

Climate and environmental considerations are mandatory across all public procurement, including defence. Under LOA Section 5b, such considerations must, as a main rule, be weighted at a minimum of 30% of the award criteria, although they may instead be built into technical specifications or deviated from where the impact is insignificant.

For procurements exempted under Article 123, RAF Part III requires the contracting authority to select the most economically advantageous tender or the lowest price, with climate and environment as award criteria. Where other factors should be given weight – eg, national industrial base considerations – this must be submitted to the Ministry of Defence for decision.

For procurements under FOSA, exclusion grounds largely mirror general public procurement, with certain defence-specific additions. Mandatory exclusion grounds in Section 11-12(1) include failure to meet qualification requirements, failure to submit tax certificates or self-declarations, and conviction for serious offences (criminal organisation participation, corruption, fraud, terrorism, money laundering or terrorist financing).

Discretionary exclusion grounds in Section 11-12(2) cover insolvency, criminal convictions relating to professional conduct (including Export Control Act violations), serious professional misconduct such as breach of classified information or supply security obligations, non-payment of taxes, and provision of misleading information. Importantly, FOSA includes a defence-specific discretionary ground: under Section 11-12(2)(h), a contracting authority may exclude a supplier not considered sufficiently reliable to rule out a security risk for Norway.

This provides a broad basis for excluding suppliers on national security grounds, including concerns related to foreign ownership or influence, without requiring a conviction. The rules apply correspondingly to sub-contractors (Section 11-12(4)).

FOSA also sets out rules on mandatory and discretionary rejection of tenders (Sections 11-13 and 11-14), covering late tenders, tenders with material reservations or deviations from specifications, and abnormally low tenders, which may only be rejected after examining a written explanation.

For procurements exempted under Article 123, the contracting authority has significantly greater discretion in selecting which suppliers to invite and exclude.

The transparency obligations in defence procurement depend on whether the procurement is conducted under the statutory rules or is exempted under Article 123.

For procurements under FOSA (above EEA thresholds), the full EU transparency regime applies. The contracting authority must publish in Doffin and TED, and issue a contract award notice. Upon award, all participating suppliers must be notified simultaneously with a written statement of reasons identifying the successful tenderer and explaining the relative advantages of its tender (FOSA, Section 13-3). A mandatory standstill period applies before contract signature. Rejected tenderers must receive prompt written reasons (Section 11-16).

However, the contracting authority may withhold information from its statement of reasons where disclosure would be contrary to defence or security interests, would harm legitimate commercial interests, or could undermine fair competition (FOSA, Section 11-16(5)). A general duty of confidentiality applies to the content of tenders and other commercially sensitive information received during the process (Section 3-4).

For procurements exempted under Article 123, no statutory publication or standstill obligations apply. Transparency is governed by RAF Part III, which requires traceability, a protocol recording all relevant information, and prompt notification to all tenderers with reasons. There is, however, no obligation to publish a prior notice – the contracting authority selects which suppliers receive the tender documentation.

Where a procurement is classified under Security Act, Chapter 9, the supplier cannot be given access to classified specifications or tender documentation until a security agreement has been concluded and, where required, the supplier and its personnel hold valid security clearances (see 2.4 Restricted and Classified Procurement).

As a general rule, procurement documents (including the tenders) held by public authorities are subject to the Freedom of Information Act, which entitles any person to request access. This right is limited by the confidentiality rules of the Public Administration Act, which protect business secrets, and by the Security Act which requires that classified information be withheld regardless of any general transparency obligations.

For procurements conducted under FOSA (and the other procurement regulations, such as FOA), post-award modifications are limited by the general EU/EEA procurement law principle that a material modification of an existing contract constitutes a new contract requiring a new procurement procedure.

A modification is material where it would have allowed admission of other tenderers or acceptance of a different tender, extends the scope considerably, or changes the economic balance in the contractor’s favour beyond the original terms. Non-material modifications are permissible.

For procurements exempted under Article 123, the prohibition on material modifications does not apply as a matter of procurement law, because the statutory procurement framework does not govern these contracts.

FOSA does not establish specific termination grounds. Termination rights are governed by contract terms supplemented by general contract law. Termination for convenience is not a statutory right, but is commonly provided for contractually. Defence contracts typically define specific breaches as material and entitle the government to terminate for convenience, subject to compensation for work performed and costs incurred.

Any supplier that has participated in or has been affected by a defence procurement process has standing to challenge a procurement decision. The available remedies and the forum for challenge depend on whether the procurement is subject to the statutory procurement rules or is exempted under Article 123.

For procurements conducted under FOSA, the enforcement regime is governed by LOA and its implementing provisions. The primary remedy mechanisms are as follows.

  • First, the contracting authority may set aside its own award decision before contract signature (FOSA, Section 13-3).
  • Second, before contract signing, a supplier may apply to the ordinary courts for an interim injunction. During the mandatory standstill period, such an application triggers automatic suspension of the contracting authority’s right to sign. The court may set aside the award decision, prohibit the contracting authority from proceeding, or order other appropriate measures.
  • Third, after signing, remedies are primarily monetary: damages for lost profit or tender costs, and courts may declare a contract without effect or shorten its duration.

There is no specialised procurement court in Norway; all disputes are heard by ordinary courts, with Oslo District Court (Oslo tingrett) as the default venue. KOFA may also issue advisory opinions under FOSA in faster, less costly proceedings, and may impose administrative fines for particularly serious violations such as unlawful direct awards.

There are no specific statutory limitations on challenging decisions on national security grounds. However, the contracting authority’s discretion is broad and subject to limited judicial review: courts will generally exercise restraint on the substance of security assessments, while examining whether the decision was procedurally correct, properly reasoned and not manifestly disproportionate.

Export control rests primarily on the Export Control Act and Export Control Regulation, covering the export of defence goods, military equipment and dual-use items, as well as brokering and certain transit situations.

DEKSA is the national licensing authority, subordinate to the Ministry of Foreign Affairs. The Ministry retains responsibility for policy and regulatory development and acts as the appeal body. For enforcement authorities, see 3.9 Enforcement, Penalties and Voluntary Disclosure.

The control lists are annexed to the Export Control Regulation. List I covers defence-related products, reflecting the Wassenaar Arrangement Munitions List as consolidated in the EU Common Military List. List II covers dual-use items, consolidating entries from the Wassenaar Arrangement, MTCR, Nuclear Suppliers Group, Australia Group and Chemical Weapons Convention. Norway applies the EU compilations and normally updates the annexes annually.

List I comprises 22 categories of military goods using the ML coding format. List II is organised into ten categories, from nuclear materials (Category 0) to aerospace and propulsion (Category 9). Both lists are highly technical, relying on detailed descriptions and control parameters.

The lists are not exhaustive. The Regulation contains “catch-all” clauses that may trigger a licensing requirement for unlisted goods, technology, and services, although the threshold for invoking these provisions is generally high.

Main Licence Types

There are mainly two types of licence, available for goods, technology, services and brokering, in respect of both defence-related products and dual-use items, as follows.

  • Individual licence – used for limited exports to a specified end user, typically for a single shipment or defined quantity, and where the goods, destination or risk level warrant case-by-case control. Generally valid for two years.
  • Global licence – used for repeated exports over time to one or more known recipients, potentially covering multiple destination countries and shipment types. Generally valid for three years, extendable to five where documented need exists.

Product Categories and Country Groups

The licensing assessment is partially structured around two product categories and four country groups, as follows.

  • Product categories:
    1. Category A – weapons, ammunition and certain military materiel with strategic capability that could materially affect the military balance beyond Norway’s immediate region.
    2. Category B – all other defence-related products, including dual-use items destined for military end use.
  • Country groups:
    1. Group 1 – the Nordic countries, NATO member states and certain particularly close partners.
    2. Group 2 – other countries approved by the Government as recipients of Category A items.
    3. Group 3 – countries that may receive Category B materiel, but not Category A weapons and ammunition.
    4. Group 4 – countries to which Norway sells neither category, due to conflict, sanctions or foreign policy considerations.

Special rules apply to intra-EEA transfers of defence-related products through general, global and individual transfer licences.

Process for Application and Relevant Authority

Applications are submitted to and determined by DEKSA. A licence must be in place before the export takes place. The system involves a two-step approach:

  • Self-classification – the exporter must assess whether its products, technology or services are caught by the control lists. An exporter who concludes that an item is not controlled must be able to document that conclusion. DEKSA may provide classification guidance where exporters are in doubt.
  • Written application – where the item is controlled, a written application must be submitted to DEKSA on the prescribed form. Submissions must be in Norwegian or English, and a Norwegian summary of the essential features must always be included.

Information and Documentation

The supplier must provide whatever information and documentation DEKSA considers necessary. All applications must include documentation confirming the information given, and the applicant must account for end use and end user. The goods, technology or service must be classified against the control lists.

For dual-use items, key documentation includes the commercial basis for the transaction (contract, invoice or similar) and a technical description enabling correct classification. Additional documentation may be required depending on the circumstances, such as end-user statements for certain destinations.

For defence-related products, specific documentation requirements – including end-user statements with re-export clauses and other supporting materials – are set out in the Ministry’s guidelines and are typically tied to the combination of product category and destination country group (see 3.3 Licence Requirements and 3.5 Criteria for Granting or Refusing Licences).

Processing Times

Published average processing times per September 2026 range from two to four weeks for exports to Ukraine, to six to 12 weeks for other defence-related product licences, up to 16 weeks for dual-use licences, and 18 weeks for general sanctions-related enquiries. Complex cases can take considerably longer.

Under the Government’s 1959 declaration and 1992 guidelines, together with the EU Common Position on arms exports (2008/944/CFSP) and the UN Arms Trade Treaty, the dominant principles are that Norway will not permit the sale of weapons to areas at war or threatened by war, or to countries in civil war, and that exports require careful assessment of foreign and domestic policy conditions, including human rights.

The international criteria give rise to specific grounds for refusal and further considerations. DEKSA may attach conditions to a licence, and strict documentation of the end user is typically required. Binding agreements or receipt of payment cannot form the basis for granting an export authorisation.

DEKSA may require end-user statements and attach conditions to licences. All applications must account for end use. DEKSA publishes standard templates for end-user and customer declarations.

The supplier must ensure exports are in accordance with the licence, go to the stated destination, do not deviate from approved descriptions or quantities, and are exported within the validity period. The supplier must inform recipients of licence conditions, including restrictions on end use or re-export. A valid licence must be presented to customs, and records must be retained for at least ten years.

Norway does not currently operate a formal post-shipment verification or end-use monitoring programme. The primary mechanism is the exporter’s own compliance obligations, reinforced by customs control and DEKSA’s power to revoke or suspend licences.

This is under development. The revised EU Common Position of April 2025 introduces a commitment for states to consider post-shipment controls in certain situations, and Norwegian authorities have indicated that they are monitoring this development. Further, DEKSA has from 2026 been tasked with carrying out ex-post controls where appropriate. The overall trajectory points towards increased use of post-shipment controls.

Brokering and intermediary activities for controlled defence and dual-use items are subject to licensing. Trading in or assisting the sale of List I items between foreign countries requires a DEKSA licence. The same applies to brokering of List II items where they may be intended for weapons of mass destruction.

Services related to items on the control lists are likewise subject to licensing, as are other services that may directly serve to develop the military capability of a country.

The wording of these provisions is deliberately broad, and the catch-all clauses provide a further basis for licensing requirements in defined circumstances. Authorisations follow the ordinary licensing framework (see 3.3 Licence Requirements).

A licence is required for intra-company and intra-group transfers where controlled items or technology cross borders. No exemption exists for intra-group transfers as such.

In practice, recurring transfers within a group can usually be accommodated through a global licence covering repeated exports to named group entities over time (see 3.3 Licence Requirements).

Breach of the export control rules may result in criminal penalties: fines and/or imprisonment for up to five years, or up to two years for negligent contravention.

PST is the national enforcement entity, handling investigations and prosecutions of export control breaches.

Norway has no formal voluntary disclosure mechanism. Self-reporting does not nullify criminal liability, but may serve as a mitigating circumstance.

The central statute is the Sanctions Act. Norway bases its sanctions on UN and EU decisions. UN sanctions are binding under international law and must be implemented nationally. EU sanctions are not binding on Norway but are generally implemented following assessment of whether political considerations indicate that Norway should support the EU’s foreign policy line. Norway has aligned with EU restrictive measures, with few exceptions, and currently operates more than 30 geographical sanctions regimes.

Individual regimes are implemented through regulations under the Sanctions Act. Certain measures are implemented under other legislation, such as travel restrictions under immigration rules and arms embargoes under export control legislation (see 3. Export Controls and Dual-Use Items).

The Ministry of Foreign Affairs drafts sanctions regulations. DEKSA handles enquiries and issues licences, and PST investigates and prosecutes breaches. The Financial Supervisory Authority transmits UN and EU designations to supervised financial institutions and supervises compliance with asset-freeze obligations.

An arms embargo prohibits the sale of arms, military equipment and dual-use materiel, and the provision of related services, to specified states or actors. Norway imposes sanctions based on UN Security Council resolutions and EU foreign policy (see 4.1 Sanctions Legislation and Regulatory Framework) and currently operates more than 20 arms embargoes.

Arms embargoes are predominantly implemented through export control legislation (see 3. Export Controls and Dual-Use Items), rather than sanctions regulations, and therefore only some sanctions regulations expressly mention an arms embargo.

There are no sector-specific screening obligations for defence sector participants. The general sanctions rules apply, and both wilful and negligent breaches may be punishable (see 4.7 Enforcement, Penalties and Voluntary Disclosure). Each operator must therefore carry out appropriate due diligence, adapted to its business, risk exposure and the concrete situation. Generally, the authorities expect a high degree of due diligence assessing sanctions risks.

Freeze obligations extend to everything belonging to, held or controlled by a listed person. The decisive ownership threshold is 50% or more, assessed cumulatively. Control may also be established where listed persons exercise de facto influence – eg, through the right to appoint a majority of the governing body.

Derogations and exceptions are granted only to a very limited extent. Provisions on exemptions may follow from the specific sanctions regulation. Applications are submitted to DEKSA with a substantiated explanation. Most sanctions regulations also allow DEKSA to grant a derogation in “particular cases”, to which conditions may be attached.

Asset-freeze provisions are typically coupled with exemptions for humanitarian actors and necessary payments, some applying automatically and others requiring DEKSA authorisation.

Operators must comply with sanctions implemented nationally. Norway does not impose extraterritorial sanctions and has not enacted blocking legislation to counteract the effect of extraterritorial sanctions imposed by third states.

Where a Norwegian operator falls within a foreign state’s jurisdictional reach, it must comply with that state’s sanctions – eg, where a sufficient US nexus exists.

There are no compliance programme requirements specific to defence sector operators. The general duty of care applies and must be assessed concretely in each case (see 4.3 Screening and Due Diligence Requirements).

A programme should generally include risk assessment, management commitment, training, counterparty due diligence, internal reviews, and record-keeping. For defence operators, continuous monitoring of embargoes, sectoral sanctions and designations will typically be central.

Both DEKSA and the EU publish guidance on specific sanctions regimes and categories of restriction, though most guidance does not directly address compliance programme structure.

Sanctions regulations typically refer back to the Sanctions Act for enforcement and penalties. Contraventions are punishable by fines and/or imprisonment for up to three years; negligent contraventions are punishable by fines and/or imprisonment for up to six months. Aiding and abetting is also within scope.

Where a person has acted on behalf of an undertaking, the penalty is usually corporate criminal liability in the form of a fine, in accordance with the corporate liability provisions of the Penal Code.

Norway has no formal voluntary disclosure mechanism under sanctions legislation. Self-reporting does not nullify criminal liability, but may serve as a mitigating circumstance. Other mitigating and aggravating circumstances follow from the Penal Code’s corporate liability provisions.

No significant sanctions enforcement actions involving defence sector participants have been made public in the past 12 months. Most cases are resolved by penalty notices, which are not made public unless the case proceeds to trial.

Notable recent changes relevant to the defence sector include:

  • the establishment of DEKSA on 1 January 2025 as the new national authority for export control and sanctions;
  • Norway’s continued alignment, with few exceptions, with the EU’s sanctions policy, including, in particular, the successive packages targeting Russia; and
  • the absorption of the national List III into List II in January 2026 (see 3.2 Scope of Controls: Military and Dual-Use Lists), together with the Ministry of Foreign Affairs’ announced comprehensive review of the export control legislation during 2026.

The principal legislation governing national security is the Security Act (sikkerhetsloven). The Security Act applies to all state, county and municipal bodies, including the defence sector, by default.

The Act provides a comprehensive framework for preventive security work across government and critical private-sector entities. Each sectoral ministry must identify entities of critical importance to fundamental national functions and may order by administrative decision that the Act apply – in whole or in part – to private-sector enterprises that process classified information, control assets of critical importance to national security, or carry out activities essential to fundamental national functions. The Act also applies to suppliers under classified procurements.

The Act is structured around the following principal subject areas.

  • Information Security (Chapter 5), including classified information and the access to such.
  • Information Systems Security (Chapter 6), including the handling and storage of classified information.
  • Object and Infrastructure Security (Chapter 7), including designation, classification and protection of such.
  • Personnel Security (Chapter 8), including the clearance of personnel requiring access to classified information, or critical objects or infrastructure.
  • Classified Procurements (Chapter 9), including the rules for conducting a procurement involving a supplier’s access to or production of classified information or access to critical objects or infrastructure.
  • Ownership Control and FDI Screening (Chapter 10), including the rules of acquisition of a qualifying ownership stake in an entity subject to the Act.

The Act is supplemented by regulations, of which the most important are the Enterprise Security Regulation (virksomhetsikkerhetsforskriften), setting out detailed security requirements including for classified procurements, and the Clearance Regulation (klareringsforskriften), governing clearance procedures.

The principal authorities responsible for administration and enforcement are as follows.

  • The sectoral ministries – each ministry is responsible for identifying fundamental national functions and critical entities within its sector, issuing designation orders, and classifying protectable objects and infrastructure.
  • NSM – a cross-sectoral supervisory body for preventive security work responsible for supervising Security Act compliance, approving information systems, and acting as the national clearance authority for facility security clearance.

Further, the Civilian National Security Clearance Authority is responsible for personnel clearances in the civilian sector, while the Defence Security Agency clears personnel within the defence sector.

Personnel security clearance is required for any person accessing information classified CONFIDENTIAL or above. The assessment is based on a background check considering factors relevant to the individual’s reliability, loyalty and judgment, as well as links to Norway.

Access clearance is a separate personal clearance which a sectoral ministry may require for access to all or parts of a protectable object or infrastructure classified under Chapter 7 of the Security Act. The process mirrors that for personnel security clearance, but is tied to physical access to designated sites.

Facility security clearance applies to entities and is required where a supplier to a classified procurement will have access to information classified CONFIDENTIAL or above in its own premises, will have electronic access from its own systems or premises to objects or infrastructure classified CRITICAL or above, or will have custody of such objects or infrastructure. Clearance may only be granted where there is no reasonable ground to doubt the entity’s security fitness, assessed based on its ability to carry out preventive security work, its financial position, ownership structure, and any other factors indicating a risk to national security.

For private entities, personnel security clearances and access clearances are issued by the Civilian National Security Clearance Authority, while personnel working within the defence sector are cleared by the Defence Security Agency. NSM is the clearance authority for facility security clearances. The same authority may downgrade or revoke a clearance where the conditions for granting it are no longer met.

Classified information is governed by the Security Act. Information must be classified where national security interests could be harmed if it becomes known to unauthorised persons. The Act establishes four classification levels – RESTRICTED, CONFIDENTIAL, SECRET and TOP SECRET – depending on the severity of potential harm.

Access to classified information is subject to a dual requirement: the individual must have a legitimate need to know and must be authorised for access to the relevant classification level.

Defence contractors are subject to obligations under Security Act, Chapter 9. Before a classified procurement commences, a security agreement must be concluded (see 2.4 Restricted and Classified Procurement), specifying the classification level for each contract phase, personnel with access, how classified information is to be transmitted, information systems to be used, security incident reporting, and return or destruction of classified information upon completion.

Breach of the duty of confidentiality regarding classified information may give rise to criminal liability under the Penal Code.

The Security Act establishes a regime for the designation and protection of critical objects and infrastructure. An object or infrastructure is protectable where it could harm fundamental national functions or national security interests if their functionality is reduced or they are subjected to vandalism, damage or unlawful seizure. The responsible sectoral ministry designates and classifies such assets; NSM does so for assets outside any ministry’s sector. Entities which control objects or infrastructure identified as such shall be notified of such designation. There is no publicly available information identifying designated assets.

Norway does not operate a single mandatory cybersecurity certification scheme equivalent to the US CMMC framework. Instead, cybersecurity requirements for defence contractors derive from security obligations under the Security Act and Enterprise Security Regulation, applied through the classified procurement regime.

Any information system processing classified information must be approved before use. The Enterprise Security Regulation specifies operational requirements, covering protection against unauthorised access, modification and disruption, identification and authentication, logging, and systematic verification of measures. For systems handling SECRET or TOP SECRET information, or systems connected to other entities’ networks, NSM is the approval authority; other systems may be approved by the entity itself, subject to notification.

For defence contractors specifically, the security agreement concluded under Section 9-2 must specify which information system will be used to process classified information, and who is responsible for its approval.

There are no blanket restrictions on components or software from specific countries. Supply chain security is addressed through procurement-level controls, security agreements and risk-based screening mechanisms.

The most direct instrument is the security agreement required before any classified procurement (see 2.4 Restricted and Classified Procurement and 5.3 Classified Information and Official Secrets). Its obligations flow down the supply chain: a contractor or sub-contractor handling classified information in its own premises must hold facility security clearance and conclude a separate security agreement.

FOSA gives contracting authorities broad powers to vet and reject sub-contractors: exclusion grounds applicable to prime contractors apply equally to sub-contractors, including the defence-specific ground that the entity is not sufficiently reliable (see 2.10 Exclusion Grounds). The contracting authority may require disclosure of intended sub-contractors and notification of changes.

FOSA also contains provisions on supply security, under which the contracting authority may require the supplier to demonstrate appropriate supply chain organisation and geographic location, notify changes in organisation or industrial strategy, and maintain production capacity for increased crisis demand.

The Security Act requires entities to assess whether a procurement to a protectable information system, object or infrastructure could entail a non-negligible risk of compromise. Where such a risk is identified, the responsible ministry must be notified, and the King in Council may prohibit the procurement or impose conditions.

Espionage and sabotage are criminal offences under the Penal Code. Every entity subject to the Security Act must establish a security management system, conduct regular risk assessments, and implement proportionate physical, electronic, human and organisational security measures. Management must review the system annually and ensure persons with access to protectable assets are identity-verified and adequately trained.

Entities subject to the Security Act must immediately notify NSM and the relevant supervisory authority where affected by security-threatening activity, where there is well-founded suspicion of such activity, or where a serious security breach has occurred.

These obligations extend to suppliers under classified procurements. A supplier entering into a security agreement assumes corresponding obligations to protect classified information for the contract duration. NSM supervises Norway-based suppliers directly.

The risks posed by foreign ownership, control and influence are addressed through the FDI screening mechanism in Chapter 10 of the Security Act (see 6.1 FDI Screening Legislation and Regulatory Framework), the facility security clearance regime, and clearance requirements described in 5.2 Security Vetting and Clearance Requirements. There are no proxy board arrangements, special security agreements or government-appointed security directors.

An entity holding facility security clearance must promptly notify NSM of any change in its board, management, ownership structure, premises or financial position. Foreign ownership changes affecting security fitness may lead to clearance revocation.

The Security Act does not operate in isolation. Each of the national security, export control, sanctions, FDI screening and procurement regimes is governed by separate legislation and administered by distinct authorities, but they apply concurrently.

The most direct interface is with defence procurement: FOSA sets procedural rules, while the Security Act imposes substantive security obligations through requirements for security agreements and, where relevant, facility security clearance (see 2.4 Restricted and Classified Procurement).

Export controls operate under a separate DEKSA-administered framework (see 3. Export Controls and Dual-Use Items) and apply independently of the Security Act. The Security Act’s prohibition on transferring classified information to foreign entities without clearance authority consent functions as a parallel restriction.

NSM holds the cross-sectoral supervisory mandate for preventive security work, while DEKSA co-operates operationally with PST, the Intelligence Service and the Customs Service on export control and sanctions (see 3.9 Enforcement, Penalties and Voluntary Disclosure). There is no single inter-agency body for co-ordinating the regimes.

The FDI filing regime is narrow in scope and only applies to entities formally subjected to the Security Act through individual administrative decisions.

The government through the King in Council also holds a broad “golden power” under Section 2-5 of the Security Act, enabling intervention in any “activity” that may pose a national security risk, including transactions not requiring FDI filing. This power may be exercised irrespective of the Public Administration Act’s limitations and regardless of whether the activity is otherwise permitted by law. A Section 2-5 decision constitutes a special enforcement title.

Under the current FDI regime, any person acquiring a “qualified ownership stake” in an entity subject to the Act must file with the responsible sectoral ministry. A qualified ownership stake means directly or indirectly reaching at least one-third of share capital, ownership interests or voting rights, or obtaining significant influence over management by other means.

Amendments to the Security Act (adopted but not yet in force) will lower the threshold to 10% of share capital/voting interests, introduce further notification triggers, and extend the FDI filing regime to entities holding facility security clearance.

For entities subject to the Security Act, an FDI filing is mandatory if the transaction meets the applicable notification threshold (see 6.2 Transactions Subject to FDI Screening).

Norway does not have a system for voluntary filings.

The acquirer must notify the responsible sectoral ministry before completing the acquisition. The Enterprise Security Regulation specifies required information: the acquirer’s ownership structure, foreign ownership interests, identity and nationality of board members and senior management, interests in other entities subject to the Security Act, and five years of financial statements.

The ministry may consult relevant bodies on the acquisition’s risk potential and the acquirer’s security reliability.

The review period is 60 working days from receipt; if additional information is requested within the first 50 working days, the deadline is suspended until the acquirer responds. There is no formal standstill obligation – the acquirer may complete the transaction before review concludes, though a prohibition may be imposed retroactively. If the acquisition could entail a non-negligible national security risk, the King in Council may prohibit the acquisition or impose conditions.

There is limited information on specific criteria applied in FDI assessments. Based on preparatory work and practical experience, a key consideration is whether the acquirer has links to countries with which Norway does not have established security co-operation.

Authorities may impose conditions that involve strict security measurements on the entity that may limit the owners’ ability to be informed of and involved in the business as well as affect exit strategies.

A transaction may potentially be prohibited or unwound if authorities assess that the buyer has links to high-risk countries and that the target is of critical importance to national security interests. The specific assessment, however, will be done on a case-by-case basis.

Norway does not make use of “golden shares” or equivalent special governmental rights in defence companies, nor are there any mechanism under Norwegian law whereby the Norwegian state holds special ownership or control rights in defence companies that are independent of the state’s equity ownership interest. Instead, the Norwegian state has, today and traditionally, maintained effective control over defence companies that are considered strategically important through direct and indirect majority state ownership, all of which are either Norwegian public or private limited liability companies.

There is no specific regulation restricting JV formation in the defence sector. There are no requirements for governmental pre-approval, mandatory state participation, or foreign ownership caps – unlike certain other sectors (such as hydropower and financial services). However, FDI screening and export control regimes will in practice affect JV structuring, particularly where foreign partners are involved.

Defence joint ventures have typically been structured through joint ownership in limited liability companies. The defence industry is characterised by a small, concentrated base of players with significant state ownership, resulting in limited JV experience. The regulatory framework for technology transfer and IP ownership is shaped primarily by defence procurement rules, export control, and bespoke contractual arrangements.

Under RAF, the public defence sector acquires non-exclusive user rights to IP generated under defence contracts rather than outright ownership, with certain exemptions. Where the state has funded R&D, it is typically entitled to a royalty. These retained government rights must be accommodated in JV structures.

In JV contracts, partners typically retain ownership of contributed (background) technology, with licensing arrangements enabling JV use. IP developed within the JV (foreground IP) generally vests in the JV entity, subject to license-back arrangements.

Technology sharing within a JV is subject to export control. The Security Act’s requirements for facility security clearance and handling classified information further constrain how technology may be shared within a JV group with foreign partners.

There are no formal co-ordination mechanisms between FDI assessments and merger control. These are assessed separately, with no joint processes. As noted in 6.1 FDI Screening Legislation and Regulatory Framework, the government’s “golden power” may be exercised regardless of whether the activity is otherwise permitted by law, thus overriding competition law outcomes.

General investigative and prosecutorial powers lie with the police. Espionage, sabotage and acts of terrorism are the responsibility of PST. PST is also responsible for sanctions and export control breaches. For procurement disputes, courts exercise judicial review under LOA and FOSA, with powers to set aside pre-contractual decisions, while KOFA acts as the complaints board and can issue advisory decisions on compliance with the procurement rules.

There are no particular triggers for publicly known regulatory investigations in the defence sector. As a starting point, there are no mandatory self-reporting obligations, but there are obligations on entities that are made subject to the Security Act on certain security threatening activities.

The police and the PST have regular law enforcement powers, including search and seizure and the freezing of assets.

The police and the PST have regular law enforcement powers, including dawn raids. As a main rule, on-site inspections under the Security Act must be notified in writing in advance. However, NSM and sectoral supervisory authorities may conduct inspections without notice where security considerations make it necessary.

Legal professional privilege applies without a national security carve-out. The privilege rests on evidentiary prohibitions in the Criminal Procedure Act, which prevents courts from receiving testimony from lawyers about matters confided to them in their professional capacity, unless the client consents. The corresponding civil law provision is in the Dispute Act. The Advocates Act establishes a comprehensive statutory duty of confidentiality for all information an advocate receives in connection with an engagement, and provides that the core privilege may be overridden only where expressly provided or clearly presupposed by statute. Neither the Security Act nor the Export Control Act contains an express override of the lawyer-client privilege.

Under FOSA, a contracting authority must exclude a supplier convicted of participation in a criminal organisation, corruption, fraud, terrorism, money laundering or terrorist financing. Discretionary exclusion is available where the supplier has been convicted of professional conduct offences, committed serious misconduct such as breach of classified information or supply security obligations, or is not considered sufficiently reliable. Unlike FOA, FOSA contains no self-cleaning provision. However, a narrow public interest exception permits proceeding with an excluded supplier where overriding public interests make it necessary.

Defence procurement disputes under FOSA are resolved through ordinary civil courts. KOFA handles complaints but its role is primarily advisory; its FOSA decisions are not legally binding except for administrative fines for unlawful direct awards. Courts may declare contracts without effect, but can refrain where this would threaten a major defence or security programme. Arbitration may be agreed contractually.

The Dispute Act prohibits evidence that is held secret in the interests of national security unless the King consents, and the court is able to order closed hearings where required by the state’s relations with a foreign power or where military operations are at stake. The Criminal Procedure Act imposes a corresponding evidentiary prohibition in regular criminal proceedings, but sets out a specific procedure for cases that include CLASSIFIED information.

Norway has no defence-specific whistle-blower legislation. The general framework in the Working Environment Act Chapter 2A applies to all employees, regardless of the sector. An employee has the right to report censurable conditions, which encompasses breaches of legislation, written ethical guidelines and broadly accepted ethical norms. Employees may always report internally – to the employer, through the entity’s whistle-blowing procedures, or via a safety representative, union representative or lawyer – and may always report externally to a public supervisory authority or other public authority.

Norwegian law provides for corporate criminal liability through the general regime in the Norwegian Penal Code. When a criminal offence has been committed by a person acting on behalf of an enterprise, the enterprise itself may be subjected to criminal sanctions. The available sanctions for enterprises are fines, forfeiture of the right to conduct business, and confiscation. This regime applies across all the principal defence-related offence categories: export control violations and sanctions breaches, breaches of the Security Act, and corruption in defence procurement.

Advokatfirmaet Thommessen AS

Ruseløkkveien 38
0251 Oslo
Postboks 1484 Vika
NO-0116 Oslo
Norway

+47 23 11 11 11

firmapost@thommessen.no www.thommessen.no
Author Business Card

Law and Practice in Norway

Authors



Advokatfirmaet Thommessen AS was established in 1856 and is one of Norway's leading commercial law firms, with offices in Oslo, Bergen, Stavanger and London. The firm advises Norwegian and international companies across the public and private sectors, covering all business-related fields of law. Thommessen assists businesses with transactions, complex projects and contentious matters in all areas of commercial law, combining robust legal expertise with in-depth industry knowledge to provide advice that facilitates long-term value creation. It offers unique advisory services to defence industry suppliers, combining legal expertise in complex procurement contracts with extensive experience from the Norwegian Armed Forces and a deep understanding of national security issues. The team advises on defence and classified procurements, IT projects in the defence and security sector, complex defence contract negotiations, transactions involving defence sector entities – including FDI requirements and compliance with the Norwegian Security Act – and strategic guidance on evolving threat and risk landscapes.