If you run online betting, an online casino, or supply games to licence holders in Denmark, the Danish Gambling Authority (Spillemyndigheden) has its own security testing rules on top of PCI DSS. The good news: they lean on the same kind of testing you already need for card compliance. Here's how the two line up.
Who This Applies To
These rules cover online and land-based betting, online casino, and supply of games under the Danish Gambling Act. As of 2025, game suppliers need this too, not just licence holders, so if you provide game platforms to Danish-licensed operators, this applies to you even if you don't hold the licence yourself.
Vulnerability Scanning Requirements (SCP.05.00)
The Danish Gambling Authority requires a vulnerability scan at least once every 3 months, the same quarterly cadence PCI DSS already asks for. A scan is also required before your licence can be issued in the first place.
The testing organisation has to be a PCI SSC-approved ASV or CREST accredited. ServerScan is ASV-certified, so we already meet this requirement. The scan needs to cover your base platform, game platform, and business systems, and the resulting report has to reach the Danish Gambling Authority within 1 month of the scan.
Penetration Testing Requirements (SCP.04.00)
A penetration test is required at least once every 12 months, and again before your licence is issued. You can postpone a renewal by up to 2 months with notice to the Danish Gambling Authority, but no more than 14 months can pass between tests either way. The report is due within 2 months of the test finishing.
Same as with scanning, a PCI SSC-approved ASV qualifies as a testing organisation here (CREST and certain ISO accreditations work too). Where this differs from a standard PCI pentest is scope: the Danish Gambling Authority requires testing to specifically cover things like manipulation of game results, fraud or theft of customer funds, and tampering with audit logs, on top of the usual access and data protection testing. That's broader than what a standard cardholder-data-focused pentest covers, so it needs to be scoped in up front.
Where This Overlaps With PCI DSS
A lot, which is why this is worth knowing about. Both frameworks run on the same quarterly scan and annual pentest schedule. One of your 4 required yearly vulnerability scans can even be the same scan completed alongside your penetration test. And since ServerScan is already a PCI-approved ASV, we meet the testing organisation requirement for both SCP.04.00 and SCP.05.00 without needing a separate vendor.
Where It Doesn't
The gaming-specific test scenarios, like result manipulation and audit log tampering, go beyond standard PCI scope, so your pentest needs to explicitly include them rather than assuming a card-data-focused test covers it. And only the Danish-language version of these requirements is legally binding. The English version is guidance only, so check exact wording with your compliance advisor or legal counsel before submitting anything to the Danish Gambling Authority.
What ServerScan Offers
ServerScan is a PCI SSC-approved ASV, which already satisfies the testing organisation requirement for both SCP.04.00 and SCP.05.00. Our PCI ASV scanning covers your quarterly requirement with unlimited scans included, and our penetration testing covers your annual requirement, with a free scoping call to make sure the gaming-specific scenarios are included where you need them.
Not sure how this maps to your specific licence type? Contact our support team. We're happy to walk through it.