LinkedInInstagramXTikTok

Sweden’s new Cybersecurity Act: what your business needs to know

Why Sweden’s Cybersecurity Act affects more businesses than many think

On 15 January 2026 the Swedish Cybersecurity Act (cybersäkerhetslagen, SFS 2025:1506) entered into force, bringing the EU’s NIS2 Directive, Directive (EU) 2022/2555, into Swedish law. Many business owners assume this is a matter for power companies, banks and large IT providers, and that a mid-sized firm has nothing to worry about. That is the misconception worth correcting early. The Act is expected to reach around 8,000 organisations across eighteen sectors, many of them ordinary companies that have never thought of themselves as critical infrastructure, and the first hard deadline, registration by 30 September 2026, is only a few months away.

What is the new Cybersecurity Act?

The Act is Sweden’s implementation of NIS2, the EU directive that sets a common baseline for cybersecurity across the Union. It replaces the earlier law on information security for essential and digital services (2018:1174) and widens both the range of companies covered and the obligations they carry. Sweden was the nineteenth member state to transpose the directive, well after the EU deadline of 18 October 2024, which is part of why the timetable now feels compressed. Alongside the Act sits the Cybersecurity Ordinance (SFS 2025:1507) and a set of detailed regulations from the supervisory authorities that fill in the practical requirements.

Which businesses are covered?

The Act divides organisations into essential entities and important entities across eighteen sectors, including energy, transport, banking and financial market infrastructure, health, drinking and waste water, digital infrastructure, public administration, space, postal services, waste management, chemicals, food, manufacturing, digital providers and research. In most cases a company is caught if it operates in one of these sectors and is at least medium-sized, meaning roughly fifty or more employees or an annual turnover or balance sheet above ten million euros, though some providers are covered regardless of size.

The whole-entity approach

One feature of the Swedish implementation catches many companies off guard. Once an organisation falls within scope because of one activity, the Act’s requirements apply to the entire entity, not only the specific service that triggered coverage. A manufacturer with a small in-scope logistics or digital arm can therefore find its whole operation subject to the rules, which makes an early scoping assessment more valuable than many expect.

What does the Act require?

At its core the Act asks covered entities to manage cybersecurity risk in a structured way and to report serious incidents quickly. Risk management measures include, among other things, policies, incident handling, business continuity, supply chain security, access control and staff training. The regulations on incident reporting and information duties take effect on 1 July 2026, and the rules on security measures and management training follow on 1 October 2026. Reporting follows the NIS2 pattern of an early warning within twenty-four hours, a fuller notification within seventy-two hours and a final report within one month.

Management is personally responsible

The Act pulls cybersecurity firmly into the boardroom. Management bodies must approve the risk measures, oversee their implementation and take part in training, and they can be held accountable if the organisation falls short. Cybersecurity is no longer something that can be quietly delegated to the IT department and forgotten.

A worked example

Consider a Swedish food producer with about ninety employees that runs its own logistics platform and sells to retailers across the Nordics. Food production is one of the eighteen sectors, and the company is above the size threshold, so it is likely an important entity under the Act. It must register through the national portal before 30 September 2026, put structured risk management measures in place, and be ready to report a serious incident within twenty-four and seventy-two hours. Because of the whole-entity approach, the requirements cover not just the logistics platform but the business as a whole, and its board, not only its IT manager, carries the responsibility.

Common mistakes

The most common mistake is assuming the law is only for critical infrastructure or technology companies, when in practice it reaches manufacturers, food producers, waste operators and many others. A second is believing that a smaller company is automatically exempt, when the size threshold is lower than many think and some providers are covered regardless. A third is treating registration as the finish line rather than the start, since the substantive security and reporting duties phase in through 2026. Finally, some companies assume that because Sweden implemented late, enforcement is a distant prospect, when the Act is already in force and the supervisory authorities are building their oversight now.

Recommended actions

Start by working out whether you are in scope, by checking your sector against the eighteen listed and your size against the thresholds, and remember the whole-entity effect when you do. If you are covered, register through the national notification service well before the 30 September 2026 deadline rather than leaving it to the last weeks. Map your current cybersecurity measures against the risk management requirements and close the obvious gaps first, giving particular attention to incident detection and reporting so you can meet the twenty-four and seventy-two hour clocks. Bring your management body into the process early, since the law now expects directors to understand and approve the approach. And keep an eye on the detailed regulations taking effect on 1 July and 1 October 2026, because that is where the specific expectations become concrete.

Frequently asked questions

Does the Cybersecurity Act only apply to critical infrastructure?

No. It applies to essential and important entities across eighteen broad sectors, including food, manufacturing, waste and digital services. Many ordinary companies are covered, and the whole-entity approach means the rules can reach an entire business, not just one in-scope activity.

When does my company have to register?

Organisations that fall within scope must register through the national notification service by 30 September 2026. The service opened on 2 February 2026, so it is available now, and registering early leaves time to address the security and reporting obligations that phase in during 2026.

What happens if we do not comply?

Supervisory authorities can order corrective measures and impose administrative fines, which under the directive can reach up to ten million euros or two percent of global annual turnover for essential entities. Management can also be held personally accountable for serious failures.

Conclusion

Sweden’s Cybersecurity Act turns cybersecurity from a technical preference into a legal duty for thousands of companies that may not yet see themselves as covered. The law is in force, the registration deadline of 30 September 2026 is close, and the detailed obligations arrive through the second half of the year. At Lawgent, we help companies work out whether they are in scope, register on time, and build cybersecurity governance that satisfies the Act without overwhelming the business. Get in touch for a free first hour and we will help you find out exactly where you stand.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop