NIS2 legal advice — from scope to a plan you can act on

The Swedish Cybersecurity Act brought NIS2 into national law in January 2026. We help you establish whether you are in scope, what that means concretely, and which measures to take first.

The first question is almost always scope, and it is less obvious than it looks. NIS2 reaches further than the old NIS rules — into manufacturing, waste, food, digital services and public administration — and it can pull in companies that have never thought of themselves as critical infrastructure. It also reaches you indirectly, through the supply chain requirements your customers now have to apply to their suppliers.

First hour’s on us. No commitment.

What you get

  • A documented scope assessment — whether you are in scope, and whether as an essential or an important entity, with the reasoning written down
  • A gap analysis against the risk management measures the law requires, in the areas that carry legal weight
  • Incident reporting procedures that work against the 24-hour and 72-hour deadlines, including who decides and who signs
  • Supplier contract clauses so the supply chain requirements are handled in writing rather than in hope
  • Governance documentation showing that the management body has approved the measures and understands them — a personal responsibility under NIS2, not only a corporate one

How it works

  1. Intake, 45 minutes. What you do, where, and for whom. Free.
  2. Scope and gap assessment, one to three weeks.
  3. The plan. Prioritised measures, registration where required, and the documentation to support both.

Who you’ll work with

Fidan Ibrahimzada, Legal Counsel for AI and technology law, leads this work. She advises companies on AI regulation, data protection and technology contracts, and previously led the legal department of a commercial law firm. She holds an LL.M. in European Business Law from Lund University. Lawgent is Sweden’s first law firm dedicated to AI and EU regulation — meet the team.

The Swedish Cybersecurity Act in short

The Cybersecurity Act (2025:1506) entered into force on 15 January 2026 and replaced the earlier Swedish NIS legislation. It implements the NIS2 Directive and applies across eighteen sectors — energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration and space in the highly critical group, and postal services, waste management, chemicals, food, manufacturing, digital providers and research in the second.

The general threshold is medium-sized enterprise or larger: at least 50 employees, or annual turnover and balance sheet total above EUR 10 million. Smaller entities can still be caught where they play a critical societal role or are the sole provider of a service.

Supervision is divided by sector. The Swedish Authority for Civil Defence (Myndigheten för civilt försvar, formerly MSB) coordinates and issues general regulations, with sector supervisors including Post- och telestyrelsen for digital infrastructure and Finansinspektionen for financial entities. For financial entities, DORA takes precedence over the corresponding requirements in the Cybersecurity Act.

Essential or important — and why the distinction matters

Entities are classified as essential or important. The substantive security requirements are the same. What differs is supervision and sanction: essential entities are subject to proactive supervision, while important entities are supervised primarily after the fact. The upper limits for administrative fines are set at EUR 10 million or 2 % of global annual turnover for essential entities, and EUR 7 million or 1.4 % for important entities.

That is the frame the law sets. In our experience it is rarely what drives good decisions — the operational case for getting this right is stronger than the penalty case, and it lands better with a board.

What the risk management measures actually cover

The law requires appropriate and proportionate technical, operational and organisational measures. The listed areas include risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, security in acquisition and development, procedures for assessing effectiveness, cyber hygiene and training, cryptography, human resources security and access control, and multi-factor authentication.

The legal work is in three places: proportionality, since appropriate has to be argued and documented against your risk profile; supply chain, since the requirements have to be pushed into contracts to have any effect; and evidence, since a measure you cannot demonstrate is a measure you did not take.

Management responsibility is personal

NIS2 places the approval and oversight of cybersecurity risk management measures on the management body, and requires its members to undergo training. Management can be held responsible for infringements. This is the part that most often changes how a board engages with the subject, and it is worth handling explicitly: a documented approval, a documented training record, a standing item on the agenda.

Incident reporting on a 24-hour clock

Significant incidents follow a three-stage sequence: an early warning within 24 hours of becoming aware, an incident notification with an initial assessment within 72 hours, and a final report within one month. Twenty-four hours is short. The decisions that need to be made in advance are who assesses significance, who has authority to file, and what gets sent when the facts are still incomplete. We write that procedure with you before you need it.

Frequently asked questions

How do we know whether we are in scope?

Sector, size and role. The sectors are listed in the annexes to the Act, the general threshold is 50 employees or EUR 10 million, and there are exceptions in both directions. Document the assessment either way — including the conclusion that you are out of scope.

We are a supplier to a company that is in scope. Does that affect us?

Not directly, but in practice yes. In-scope entities must manage supply chain security, which arrives as security requirements in your contracts. Suppliers who can answer those questions well have a commercial advantage.

How does NIS2 relate to DORA?

For financial entities, DORA takes precedence as the more specific regime for ICT risk. The two overlap heavily, and the evidence base can largely be shared. Which one governs which obligation is worth establishing early.

What does registration involve?

In-scope entities must register with the relevant authority and keep contact and service information current. We handle this as part of the scope assessment.

We have ISO 27001. Are we compliant?

It is a strong foundation and covers much of the ground, but it is not the same thing. NIS2 adds specific requirements on incident reporting, management responsibility and supply chain that a certification does not by itself satisfy.

Can you help our board understand this?

Yes. We run board and management sessions in plain language, focused on decisions rather than terminology.

Start with the scope question

Everything else follows from the answer, and the first conversation costs you nothing.

Related