Summary: The Swedish Cybersecurity Act makes cybersecurity a management responsibility. From 1 October 2026, regulations on security measures and management training also apply. Here are ten questions a management team or board should be able to get answers to, each with a short description of what a good answer contains. Use the list at your next management or board meeting and document the answers.
The Swedish Cybersecurity Act, which implements the EU NIS2 Directive, has applied since 15 January 2026. On 1 October 2026 the regulations on security measures and management training (MCFFS 2026:11) and on security audits and security scanning (MCFFS 2026:12) enter into force. They were issued by Myndigheten för civilt försvar, Sweden’s civil defence agency, but since 1 July 2026 the cyber remit and the supervisory guidance sit with the National Cyber Security Centre (NCSC) at FRA, which also receives the registration of operators. From that date the requirements are concrete, and the responsibility sits explicitly with management.
The questions below are phrased so that they can be asked by someone who does not work with IT or security every day. That is the point. Management must be able to set objectives, judge which measures are needed and follow up on their implementation.
1. Are we affected by the Act, and are we registered?
The Act applies to essential and important entities in a large number of sectors, and affected entities must register with their supervisory authority. A good answer states which sector and category you belong to, when the registration was made and who the contact person is. If the answer is uncertain, use our self-assessment for deciding whether you are affected.
2. Has management completed the training, and can we prove it?
The regulations require management to have sufficient knowledge to govern the cybersecurity work. A good answer includes who has been trained, when, what the training covered and how it has been documented. New members need a plan for catching up.
3. Who owns the work, and how is it reported to us?
Cybersecurity cannot be left to the IT department. A good answer points to an accountable person with mandate and resources, describes how risks, measures and the security level are reported to management and how often. The regulations state that management must be informed when needed, but at least once a year.
4. What are our most important information assets and systems?
Without information classification nobody knows what needs the most protection. A good answer is a short list of the services, systems and sets of information the organisation cannot do without, with an owner for each item.
5. Is the risk analysis current, and have we decided which risk we accept?
Risks must be identified, analysed and evaluated by consequence and likelihood, and the organisation must have criteria for the risk it accepts. A good answer states when the analysis was last updated, what the largest risks are, which measures are linked to them and who decided on the risk acceptance. An analysis older than a year is rarely a good basis for decisions.
6. Can we report a significant incident within 24 hours?
Significant incidents follow a three-step timeline: an early warning within 24 hours of becoming aware, a notification within 72 hours and a final report within one month. A good answer describes who decides whether an incident is significant, who reports, how the decision is made on a weekend evening and when the process was last exercised.
7. How long can the business operate without its critical systems?
Continuity is an explicit requirement: the organisation must assess its continuity needs, establish a priority order for recovery and prepare alternative ways of working where needed. A good answer states, per critical service, how long an outage is acceptable, how the business operates during the outage and when recovery from backups was last tested.
8. Do we know which suppliers are critical and what the contracts require?
Cybersecurity risks must be evaluated before systems are procured or information processing is outsourced, and suppliers must be assessed on their ability to meet the security requirements throughout the contract period. A good answer is a list of critical suppliers with the information they handle, the security requirements in the contract and how compliance is followed up. Contracts entered into before 1 October 2026 must be reviewed and, where possible, supplemented if the requirements are insufficient.
9. How do we know the measures work?
A policy and a number of technical settings do not prove that security works. The regulations on security audits and security scanning point towards recurring, independent verification. A good answer includes when security was last reviewed by someone outside day-to-day operations, what the review showed and which deficiencies have been remedied.
10. What happens if we do not meet the requirements?
The Act is backed by supervision and administrative fines. For an essential entity the fine can reach the higher of 2 percent of global annual turnover or the equivalent of 10 million euros, for an important entity the higher of 1.4 percent or the equivalent of 7 million euros. Special rules apply to public entities. A good answer, however, is not mainly about the fines but about what a prolonged outage of your critical services would cost the business and the people you serve.
How to use the list
Go through the ten questions at a management meeting and write down the answers, including the ones that are “we do not know”. Questions without good answers become your prioritised action list. Repeat the exercise once a year, preferably together with the annual reporting to management. Follow-up then becomes part of governance instead of a separate project.
Want help producing the answers or closing the gaps? Read about our work with NIS2 and the Swedish Cybersecurity Act or contact us for a first conversation.
Sources: the Swedish Cybersecurity Act (implementing Directive (EU) 2022/2555, NIS2); the regulations and general guidelines of Myndigheten för civilt försvar on security measures and management training (MCFFS 2026:11) and on security audits and security scanning (MCFFS 2026:12); EUR-Lex, Directive (EU) 2022/2555.
This text is general information and does not constitute legal advice in an individual case.

