LinkedInInstagramXTikTok

Sweden’s Cybersecurity Act is here – what your business needs to know

Sweden’s Cybersecurity Act is here – what your business needs to know

On 15 January 2026, Sweden’s new Cybersecurity Act (2025:1506) entered into force. The Act transposes the EU’s NIS2 Directive into Swedish law and replaces the earlier framework for the security of essential and digital services. For many companies it creates an entirely new reality: concrete requirements on risk management, fast incident reporting, and clear accountability all the way up to the board and senior management. An estimated 8,000 Swedish organisations across 18 critical sectors are now in scope – considerably more than before.

This article explains what the law requires, who is affected, and the steps you should take now to avoid penalties and build sustainable cybersecurity.

What is the Cybersecurity Act and why was it introduced?

The Cybersecurity Act is Sweden’s implementation of NIS2, the EU’s updated framework for network and information security. Its purpose is to raise the level of protection across the services that society depends on – from energy and transport to healthcare, digital infrastructure, and public administration.

The reasoning is straightforward: cyber attacks have become more frequent, more professional, and more costly. When a provider of critical services is hit, the consequences rarely stay within that single organisation. NIS2 responds by widening the circle of regulated entities and imposing stricter, more harmonised requirements across the whole EU.

Who is covered – essential and important entities

The law divides regulated organisations into two categories: essential entities and important entities. The distinction mainly governs how supervision is carried out and how high the administrative fines can be. Essential entities are subject to more active, proactive supervision, while important entities are primarily reviewed after the fact, once something has occurred.

Which category an organisation falls into is determined largely by sector and size. The Act covers 18 sectors, including energy, transport, banking and finance, healthcare, drinking water, wastewater, digital infrastructure, postal services, food, manufacturing, and public administration. A common rule of thumb is that medium-sized and large companies in these sectors are in scope, but there are important exceptions – some smaller players are still covered because of their critical role. Simply assuming you are “too small” is therefore a risky conclusion.

Don’t forget the supply chain

Even if your own company is not directly covered, you may be affected indirectly. Regulated entities must impose security requirements on their suppliers and manage risk across the entire chain. If you are a subcontractor to an essential or important entity, those requirements will most likely reach you through contracts.

Concrete requirements: risk management, reporting, and management accountability

The law rests on three main pillars. The first is risk management. Covered entities must take appropriate and proportionate technical and organisational measures – for example risk assessments, incident handling, business continuity planning, secure supplier management, encryption, and access control.

The second pillar is incident reporting. For a significant incident, a multi-stage model applies: an early warning must be given within 24 hours, a fuller incident notification within 72 hours, and a final report within one month. These short timeframes mean your processes need to be in place beforehand – in the middle of an active attack, there is rarely time to build routines from scratch.

The third pillar, and perhaps the biggest change, is management accountability. The board and senior management must approve and oversee the security measures, and must themselves have sufficient knowledge to understand the risks. Cybersecurity can no longer be delegated entirely to the IT department.

Registration and supervision

One of the first practical obligations is registration. Covered entities must notify the central registration authority as soon as possible after the law takes effect. Supervision is organised by sector: different authorities are responsible for different industries – for example the Swedish Post and Telecom Authority (PTS) for parts of the digital infrastructure, and the Swedish Transport Agency for the transport sector. The first step for any organisation is therefore to determine whether it is in scope, which category it belongs to, and which supervisory authority applies.

Administrative fines and personal accountability

The consequences of non-compliance can be substantial. For essential entities, the administrative fine can reach the higher of EUR 10 million or 2 per cent of total global annual turnover. For important entities, the corresponding ceiling is the higher of EUR 7 million or 1.4 per cent of turnover.

In cases of repeated and serious failings, supervisory authorities can also impose measures directed at management. Taken together, this means cybersecurity is no longer just a technical question but a matter of compliance and accountability at the highest level.

Practical example: a mid-sized logistics company

Imagine a mid-sized logistics company that transports goods for several large customers. The company has long viewed IT security as a cost and relied on an external provider. When the Cybersecurity Act takes effect, management realises the business is covered as an important entity.

In practice, the company now needs to map its systems and risks, establish an incident-handling plan, make sure it can issue an early warning within 24 hours, and review its contracts with IT suppliers. Just as importantly, management must be trained so that it can make well-informed decisions. What used to be handled informally must now be documented and capable of being shown during supervision.

Common mistakes companies make

A recurring mistake is assuming the law does not apply without actually checking. Because the circle of covered entities has expanded considerably, more organisations are in scope than many expect. Another mistake is treating cybersecurity as a pure IT matter and leaving management out, even though the law explicitly places responsibility there.

Many also underestimate the supply chain and forget that requirements can reach them through contracts. Finally, some wait to prepare incident routines until something happens – but by then the clock is already running.

Recommended actions

Start with a scoping analysis: is your business covered, and if so, as an essential or important entity? Register with the right authority and identify your supervisory authority. Then carry out a risk assessment and address the most significant gaps in your technical and organisational safeguards.

Build an incident-handling process that meets the 24-hour, 72-hour, and one-month requirements, and test it. Review contracts with suppliers and customers so that security requirements are included. Ensure that the board and management receive training and ongoing reporting. And document everything – during supervision, it is the documentation that counts.

Frequently asked questions

When did the Cybersecurity Act take effect?

The Act (2025:1506) entered into force on 15 January 2026 and transposes the EU’s NIS2 Directive into Swedish law.

How do I know if my company is covered?

It is determined mainly by the sector you operate in and the size of your company, but there are exceptions. The assessment should be made carefully – even smaller players can be covered because of their critical role.

What is the difference between an essential and an important entity?

The difference lies primarily in the intensity of supervision and the maximum level of administrative fines. Essential entities are subject to more active supervision and a higher fine ceiling.

What happens if we do not comply?

Fines can reach EUR 10 million or 2 per cent of turnover for essential entities, and EUR 7 million or 1.4 per cent for important entities. In serious cases, measures can also be directed at management.

Conclusion

The Cybersecurity Act marks a clear shift: cybersecurity is now a compliance requirement with accountability reaching all the way to the top, not merely a technical concern. The companies that map their situation early, register, strengthen their risk management, and anchor the work in the board will both avoid penalties and stand stronger against real threats.

At Lawgent, we help companies understand how new legislation such as NIS2 affects their specific business and turn the requirements into practical, sustainable routines – supported by both legal expertise and AI. Want to know whether your business is in scope and what to prioritise first? Get in touch, and we’ll help you get started.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop