Why the new Cybersecurity Act concerns more companies than the old rules did
For years, cybersecurity regulation in Sweden was something that mainly occupied operators of clearly critical infrastructure and a defined set of digital service providers. The new Cybersecurity Act changes that picture. By implementing the EU’s NIS2 directive, Sweden has widened the circle of organisations that must take information security seriously as a legal obligation, not merely as good practice. Estimates suggest that around 8,000 organisations across some eighteen sectors now fall within scope, many of which never considered themselves regulated entities before.
The shift matters because the obligations are real and the deadlines are concrete. The Act entered into force in early 2026 and replaces the earlier law on information security for socially important and digital services. This article explains who is covered, what the rules actually require, the registration deadline you should not miss, and the risks of treating the new regime as someone else’s problem.
What the Cybersecurity Act is and where it comes from
The Cybersecurity Act is Sweden’s national implementation of the NIS2 directive, the EU’s updated framework for network and information security. NIS2 was designed to address weaknesses in the original NIS directive: too few sectors covered, uneven enforcement across member states and obligations that many organisations simply ignored. The Swedish Act translates that ambition into national law, with supervision and sanctions to match.
Rather than concentrating oversight in a single authority, Sweden has chosen a decentralised model. A coordinating national authority works alongside sector-specific supervisors, so that, for example, electronic communications, the financial sector and the energy sector are each overseen by the authority closest to them. For a company, the practical consequence is that you need to know which supervisor is responsible for your sector.
Is your company covered?
The first question every business should answer is whether it falls within scope at all. The Act applies to organisations active in a list of important and essential sectors, and as a main rule it reaches companies that reach a certain size, typically those with at least fifty employees or an annual turnover or balance-sheet total above a defined threshold in the region of ten million euros.
Sectors in scope
The sectors covered are broad. They include energy, transport, banking and financial market infrastructure, health, drinking and waste water, digital infrastructure, public administration and space, alongside sectors such as postal services, waste management, the manufacture of certain products, food production and distribution, and providers of digital services. The breadth is deliberate: NIS2 reflects a recognition that modern supply chains make many more organisations part of the security picture than the old rules acknowledged.
Size thresholds and the exceptions
The size thresholds matter, but they are not the whole story. Some organisations are covered regardless of size because of the critical role they play, for instance where they are the sole provider of a service essential to society. So a small company should not assume it is automatically outside scope simply because it has few employees. The safer approach is to check both the sector and the role the company plays before concluding either way.
What the Act requires
For covered entities the Act sets out duties that fall into a few broad areas. The first is risk management. Organisations must take appropriate and proportionate technical and organisational measures to manage the risks to their networks and information systems, covering matters such as access control, incident handling, business continuity, supply-chain security and the use of encryption where appropriate.
The second area is incident reporting. Significant incidents must be reported to the relevant authority within tight timeframes, typically an early notification within a day, followed by a fuller report shortly afterwards. The aim is to give authorities a real-time picture of threats and to ensure that serious incidents are not quietly absorbed and forgotten.
The third area, and one that is easy to underestimate, is management accountability. Under NIS2 the responsibility for cybersecurity is placed explicitly at board and senior-management level. Leadership is expected to approve and oversee the security measures and can be held responsible for failures. Cybersecurity is no longer something that can be delegated entirely to the IT function and forgotten in the boardroom.
The deadline you should not miss: registration
One concrete obligation deserves particular attention because it has an early and fixed date. Organisations that fall under the Cybersecurity Act are required to register themselves with the relevant authority, and the deadline for doing so falls in autumn 2026. Registration is not a formality to be left until later; it is how the supervisory system knows who is in scope, and missing it is itself a breach.
The practical difficulty is that a company first has to determine whether it is covered before it can register, and that determination is exactly the step many organisations have not yet taken. The result is a real risk that businesses discover, close to the deadline, both that they are in scope and that they are not ready. Starting the assessment in good time is therefore the single most useful thing a company can do.
Practical example: the supplier that became a target
Imagine a mid-sized company that manufactures components for the energy sector. It does not see itself as critical infrastructure; it makes parts and ships them. Its larger customers, however, are squarely within scope of the Cybersecurity Act, and NIS2 places real weight on supply-chain security.
As a result, the company finds its customers asking detailed questions about its own security measures, incident procedures and governance, and in some cases making contracts conditional on satisfactory answers. The company may also be in scope in its own right, depending on its size and role. Either way, the regulation reaches it: directly through its own obligations, or indirectly through the requirements its customers must now pass down the chain. The business that treated cybersecurity as a purely internal IT matter suddenly finds it is a commercial and legal condition of doing business.
Common mistakes companies make
The first mistake is assuming that the rules are only for large or obviously critical organisations. The widened scope of NIS2 is precisely the point; many mid-sized companies in unexpected sectors are now covered, and supply-chain pressure pulls in others that are not formally in scope.
The second mistake is treating compliance as a technical project for the IT department alone. The Act puts accountability on management, and a security programme that the board has never reviewed will not satisfy the governance expectations the law sets out.
The third mistake is leaving the assessment too late. Because registration and concrete security measures take time, and because determining scope is itself non-trivial, companies that wait risk missing the registration deadline and facing an authority with little to show.
Legal risks
Sweden has implemented the directive with sanctions at the upper end of what NIS2 allows. Essential entities can face administrative fines reaching into the millions of euros or a percentage of global annual turnover, whichever is higher, with somewhat lower ceilings for the category of important entities. Cybersecurity is, in other words, now framed as a top-tier financial risk rather than a discretionary cost.
Beyond fines, supervisory authorities have powers to issue binding instructions, conduct audits and, in serious cases, affect the ability of responsible individuals in management to carry out their duties. Add to that the commercial exposure already described, where customers in scope demand assurances from their suppliers, and the cost of inaction becomes both regulatory and commercial.
Recommended actions
Begin by determining whether you are in scope. Map your sector against the list of covered areas, check the size thresholds and consider whether your role makes you covered regardless of size. This single step resolves the most important uncertainty and tells you whether the registration deadline applies to you.
If you are covered, register in time and build the underlying programme in parallel: a documented risk-management approach, incident-handling and reporting routines that can meet the tight deadlines, and supply-chain security expectations for your own vendors. Bring management into the process rather than leaving it with IT, since the law requires leadership accountability. Even companies that conclude they are not directly in scope should prepare for customer due-diligence questions and document their security posture. Finally, treat this as an ongoing programme, not a one-off, because both threats and the supervisory expectations will continue to evolve.
Frequently asked questions about the Cybersecurity Act and NIS2
How do we know if our company is covered?
Check three things: whether you operate in one of the sectors the Act lists, whether you meet the size thresholds of roughly fifty employees or a turnover or balance sheet around ten million euros, and whether your role is critical enough to bring you in regardless of size. If any of these point to inclusion, you should treat yourself as in scope until a proper assessment says otherwise.
What is the registration deadline?
Covered organisations must register with the responsible authority during 2026, with the deadline falling in the autumn. Because you first have to confirm that you are in scope, it is wise to begin the assessment well ahead of that date rather than at the last moment.
Does this only affect the IT department?
No. A defining feature of NIS2 is that it places accountability for cybersecurity on management and the board. Leadership is expected to approve and oversee security measures, so the obligations reach well beyond the IT function into governance and decision-making at the top of the company.
We are a small supplier, not critical infrastructure. Are we affected?
Possibly in two ways. You may be in scope directly if your role is critical despite your size. Even if not, customers who are covered must manage supply-chain security, so they will increasingly ask you to demonstrate sound security practices as a condition of doing business.
What happens if we do nothing?
Non-compliance can lead to significant administrative fines, binding orders from supervisory authorities and consequences for responsible managers, alongside the commercial risk of losing customers who require assurances. The combination makes inaction an expensive choice.
Conclusion
The new Cybersecurity Act turns information security from a recommendation into a legal duty for a far wider range of Swedish companies than the old rules ever did. The challenge for most organisations is not unwillingness but uncertainty: many have simply not yet worked out whether they are covered, what the rules require of them and which deadline applies. Those who clarify their scope early, register in time and build a governed security programme will be well placed, and will avoid the scramble that comes when a deadline, an authority or a major customer starts asking pointed questions.
Lawgent helps companies determine whether they fall under the Cybersecurity Act, meet the registration and reporting obligations and build a security and governance structure that satisfies both regulators and customers. We combine experienced business-law advice with AI-driven efficiency, so that you reach secure and documented compliance faster and more cost-effectively than at a traditional firm. Unsure whether NIS2 applies to you? Contact Lawgent for an assessment of your obligations under the Cybersecurity Act.