Are we affected by the Swedish Cybersecurity Act? A simple self-assessment

Are we affected by the Swedish Cybersecurity Act? A simple self-assessment

Five steps to assess whether your organisation is affected by the Swedish Cybersecurity Act: sector, size, public administration, DORA and the essential or important category.

Summary: Whether you are affected by the Swedish Cybersecurity Act depends mainly on two things: the sector you operate in and how large you are. Some entities are affected regardless of size, and for financial entities partly different rules apply. This self-assessment takes about fifteen minutes and gives an indication. The formal answer comes from the Act and your supervisory authority.

The Swedish Cybersecurity Act, which implements the EU NIS2 Directive in Sweden, has applied since 15 January 2026 and covers considerably more organisations than the previous NIS legislation. Many organisations are still unsure whether they are affected. Go through the five steps below and write down your answers.

Step 1: Do you operate in one of the sectors?

The Act builds on the two annexes of the NIS2 Directive. Sectors of high criticality:

  • Energy (electricity, district heating and cooling, oil, gas, hydrogen)
  • Transport (air, rail, water, road)
  • Banking and financial market infrastructures
  • Health, including laboratories, pharmaceuticals and medical devices in certain cases
  • Drinking water and waste water
  • Digital infrastructure and business-to-business ICT service management
  • Public administration
  • Space

Other critical sectors:

  • Postal and courier services
  • Waste management
  • Manufacture, production and distribution of chemicals
  • Production, processing and distribution of food
  • Manufacturing of medical devices, computers and electronics, electrical equipment, machinery, motor vehicles and other transport equipment
  • Digital providers: online marketplaces, search engines and social networking platforms
  • Research

Write down: which sector and which type of activity within the sector you belong to. If you are not in either list you are probably not directly affected, but you may be a supplier to someone who is. Then the requirements reach you through the contracts.

Step 2: Are you large enough?

The main rule is that the Act applies to medium-sized and large entities in the sectors. Medium-sized means at least 50 employees, or an annual turnover and a balance sheet total that both exceed 10 million euros. Size is calculated according to the EU definition of small and medium-sized enterprises, which means that partner and linked enterprises in a group may have to be counted.

Some entities are affected regardless of size. This includes providers of public electronic communications networks and services, trust service providers, top-level domain name registries, DNS service providers and public administration. An entity that is the sole provider of a service essential to society may also be affected despite being small.

Write down: the number of employees, turnover and balance sheet total for the whole enterprise, and whether you belong to one of the groups that are affected regardless of size.

Step 3: Are you public administration?

Government agencies, regions and municipalities are as a rule affected as public administration, without a size threshold. Municipal and regional companies may instead be affected through the sector they operate in, for example energy, water or waste. Check each company separately.

Step 4: Do other rules apply instead?

For financial entities within the scope of DORA, the EU regulation on digital operational resilience, DORA’s requirements on ICT risk management and incident reporting apply instead of the corresponding parts of NIS2. Banks, insurance companies, investment firms and many other financial actors therefore assess their obligations primarily under DORA. Other sectors may have their own security rules that apply in parallel. Read more about DORA and financial regulations.

Step 5: Essential or important entity?

The Act distinguishes between essential and important entities. As a main rule, large entities in the sectors of high criticality are essential, while the others that are affected are important. Some entities are essential regardless of size. The distinction affects how supervision is carried out and how high the administrative fines can be, but the security requirements are largely the same.

Interpreting the result

  • You are in a sector and are medium-sized or larger: you are probably affected. Continue with the next steps below.
  • You are in a sector but are small: check the exceptions in step 2 and whether you are the sole provider of an essential service. Otherwise you are probably not directly affected.
  • You are not in any sector: you are probably not affected, but your customers may be. Expect security requirements in contracts and procurements.

The self-assessment is an indication. In case of doubt, the supervisory authority for your sector, or a legal assessment, decides.

What to do next if you are affected

  1. Register the entity with your supervisory authority and appoint a contact person.
  2. Make sure management receives the training the regulations require and document it.
  3. Carry out a current-state analysis against the Act and the regulations, with a prioritised action plan.
  4. Update the risk analysis and decide on criteria for risk acceptance.
  5. Secure the incident process so that you can give an early warning within 24 hours and a notification within 72 hours.
  6. Review critical suppliers and contracts.

Management can use our guide The Swedish Cybersecurity Act: ten questions for management to follow up on the work. Want help with the assessment or the current-state analysis? Read about our work with NIS2 and the Swedish Cybersecurity Act or contact us.

Sources: Directive (EU) 2022/2555 (NIS2), Article 2 on scope and Annexes I and II; Commission Recommendation 2003/361/EC concerning the definition of micro, small and medium-sized enterprises; the Swedish Cybersecurity Act; Myndigheten för civilt försvar, guidance on who is affected; Regulation (EU) 2022/2554 (DORA).

This text is general information and does not constitute legal advice in an individual case.