NIS2 compliance in Sweden — what the Cybersecurity Act asks of you
NIS2 reached Sweden through the Cybersecurity Act, in force since January 2026. The directive sets the frame; the Swedish rules decide who supervises you, where you register and what you file. We help you work through both.
First hour’s on us. No commitment.
What you get
- A documented scope assessment — in scope or not, essential or important, with reasoning you can produce later
- Registration handled, with the right authority and the right information
- A gap analysis against the risk management measures the Act requires
- An incident procedure built around the 24-hour and 72-hour deadlines, with named decision-makers
- Board documentation — approval, training record, standing agenda item
How it works
- Intake, 45 minutes. Sector, size, what you actually do. Free.
- Scope and gap assessment, one to three weeks.
- The plan. Registration, prioritised measures, and the documentation behind both.
The Swedish framework
The Cybersecurity Act (2025:1506) entered into force on 15 January 2026, replacing the earlier Swedish NIS legislation. It implements the NIS2 Directive and reaches eighteen sectors, split into a highly critical group and an other-critical group.
Highly critical: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space.
Other critical: postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research.
The general size threshold is medium-sized enterprise or above — at least 50 employees, or annual turnover and balance sheet total above EUR 10 million. Certain entities are caught regardless of size, including where they are the sole provider of a service or where a disruption would have significant societal effects.
Who supervises you
Sweden divides supervision by sector rather than concentrating it in one authority. The Swedish Authority for Civil Defence (Myndigheten för civilt försvar, formerly MSB) coordinates and issues general regulations, while sector authorities supervise their own fields — Post- och telestyrelsen for digital infrastructure, Finansinspektionen for financial entities, Transportstyrelsen for transport, Energimyndigheten for energy, among others.
For financial entities there is an important carve-out: DORA takes precedence over the corresponding requirements in the Cybersecurity Act. If you are supervised by Finansinspektionen, work out early which regime governs which obligation, because the answer is not the same for every duty.
Registration
Entities in scope must register and keep their information current — contact details, sector, services provided and the member states where they operate. This is not a formality: registration is how the supervisory system finds you, and failing to register is itself an infringement.
Registration also forces the scope assessment to a conclusion. Companies that have been circling the question for a year usually find that filling in the form is what resolves it.
What the measures have to cover
The Act requires appropriate and proportionate technical, operational and organisational measures. The listed areas are: risk analysis and information security policies; incident handling; business continuity, backup and crisis management; supply chain security; security in acquisition, development and maintenance; policies for assessing the effectiveness of measures; basic cyber hygiene and training; cryptography and encryption; human resources security, access control and asset management; and multi-factor authentication and secured communications.
The word carrying the legal weight is proportionate. What is appropriate for a 60-person manufacturer is not what is appropriate for a national grid operator, and the Act expects you to argue the difference against your own risk profile, size and exposure — and to write that argument down.
Incident reporting
Significant incidents follow three stages: an early warning within 24 hours of becoming aware, an incident notification with an initial assessment within 72 hours, and a final report within one month.
Twenty-four hours is short, and the clock starts at awareness rather than at resolution. The decisions worth making before you need them: who assesses whether an incident is significant, who has authority to file, what gets sent when the facts are incomplete, and who is told internally. A procedure written during an incident is a procedure written badly.
Management responsibility
The management body must approve the cybersecurity risk management measures and oversee their implementation, and its members must undergo training. Management can be held responsible for infringements. In practice this is the provision that changes how seriously a board treats the subject, and it is worth handling with a documented approval, a training record and a recurring agenda item rather than an assurance that it was discussed.
Frequently asked questions
We are below 50 employees. Are we out of scope?
Usually, but not always. Sole providers of a service, entities whose disruption would have significant societal effects, and certain named categories are caught regardless of size. Document the conclusion either way.
We are a supplier to an in-scope company. Does this affect us?
Indirectly, and increasingly. In-scope entities must manage supply chain security, and it arrives in your contracts as security requirements and audit rights. Suppliers who can answer well have an advantage in procurement.
We already report under DORA. Do we also report under the Cybersecurity Act?
For financial entities DORA takes precedence for ICT risk management and incident reporting. Serious ICT-related incidents are reported to Finansinspektionen under DORA. Where the two regimes overlap, establish the boundary in writing rather than reporting twice or not at all.
Does ISO 27001 make us compliant?
It covers much of the technical and organisational ground, but it does not by itself satisfy the incident reporting timelines, the management responsibility provisions or the supply chain requirements.
What happens if we get this wrong?
Supervision differs by classification — proactive for essential entities, primarily after the fact for important ones — and administrative fines are available in both cases. In our experience the operational argument moves a board further than the penalty one.
Where to start
With the scope question. It takes one conversation, it costs nothing, and everything else follows from the answer.
Who you’ll work with
Fidan Ibrahimzada, Legal Counsel for AI and technology law, leads this work. She advises companies on AI regulation, data protection and technology contracts, and previously led the legal department of a commercial law firm. She holds an LL.M. in European Business Law from Lund University. Lawgent is Sweden’s first law firm dedicated to AI and EU regulation — meet the team.