NIS2 & Cybersecurity Act

NIS2, Network and Information Security Directive 2, Cybersecurity Act

NIS2 (the second EU Network and Information Security Directive) represents a major update to Europe’s cybersecurity regulations, aiming to achieve a high common level of security across member states. In Sweden, NIS2 is implemented through a new Cybersecurity Act (Swedish: Cybersäkerhetslagen), which took effect on 15 January 2026. This Act replaces the previous NIS law and broadens the scope of affected organizations. It applies to essential and important entities across 18 sectors, including energy, healthcare, transport, banking, digital infrastructure, public services and more – generally covering medium and large companies (50+ employees or over €10 million turnover) in those sectors. In short, many organizations that handle critical services or data are now in scope, not only traditional “critical infrastructure” operators. This new regulatory landscape matters because it significantly raises the bar for cybersecurity: companies must adopt stricter security measures, report serious incidents within tight deadlines, ensure supply chain security, and strengthen governance – all under the threat of substantial penalties for non-compliance. Complying with NIS2 and the Swedish Cybersecurity Act is not just a legal checkbox; it’s about bolstering your organization’s resilience against escalating cyber threats and avoiding costly disruptions or fines.

Key Focus Areas & Requirements

NIS2 and the Cybersecurity Act introduce a range of requirements and best-practice focus areas that organizations must address. Key areas include.

  • Risk Management & Security Measures
    In-scope entities must adopt a risk-based approach to cybersecurity. This means regularly assessing threats and vulnerabilities and implementing “appropriate and proportionate” technical, operational, and organizational measures to protect networks and information systems. Companies should maintain up-to-date risk assessments and apply controls aligned with recognized standards (e.g. ISO 27001) to mitigate identified risks. This also encompasses planning for business continuity – ensuring you can maintain or quickly restore critical operations in the event of an incident (through backups, disaster recovery plans, etc.). The emphasis is on proactive risk management: anticipate hazards and address them before they result in incidents.
  • Governance & Management Accountability
    NIS2 elevates cybersecurity to a boardroom issue. Leadership is expected to oversee and be accountable for the organization’s cyber risk posture. The Swedish Cybersecurity Act even requires that senior management receive training in cybersecurity measures to ensure they have the competence to identify risks and decide on security investments. In practice, companies need to integrate security into their governance structure – for example, defining clear roles and responsibilities (such as a CISO or security officer reporting to leadership) and having management approve and regularly review security policies. A culture of accountability at the top is crucial: management should treat cybersecurity as a strategic business risk, not just an IT issue.
  • Incident Reporting & Response
    A core obligation under NIS2 is to establish robust incident handling processes and promptly report significant incidents to authorities. Organizations must have internal incident response plans and detection capabilities, so that if a major security incident (like a breach or outage) occurs, they can react swiftly and effectively. Importantly, incidents with significant impact must be reported to the Swedish Civil Contingencies Agency (Myndigheten för Civilt Försvar) within mandated timelines – an initial notification (early warning) is typically required within 24 hours of becoming aware of the incident, with a more detailed incident report within 72 hours. Additional updates or a final report may be due within a month after the incident. This means your team must be prepared to recognize incidents, follow an established escalation procedure, and gather necessary information quickly. NIS2’s reporting rules also include informing service recipients about incidents that affect them. Having tested incident response and crisis communication plans is therefore critical to meet these obligations and minimize damage when incidents happen.
  • Third-Party & Supply Chain Security
    Your security is only as strong as the weakest link in your supply chain. NIS2 places new emphasis on managing cyber risks in third-party services and supplier relationships. Organizations need to evaluate and improve the security of their vendors, service providers, and partners. In practical terms, this could involve conducting due diligence or audits of key suppliers, updating contracts to include cybersecurity requirements, and ensuring suppliers implement adequate safeguards. The Swedish implementation explicitly highlights “security in the supply chain,” and many companies will need to perform a gap analysis and update internal governance documents and supplier agreements to address supply-chain vulnerabilities. By extending risk management to third parties, you mitigate the chance that a vendor breach or supply chain attack could disrupt your critical services. Ongoing review (such as periodically reviewing third-party security reports or certifications) becomes part of compliance under NIS2.
  • Security Policies & Training
    Fulfilling NIS2 obligations isn’t just about technology – it requires organizational policies and human awareness. Companies should establish or update comprehensive security policies and procedures covering areas like access control, data protection, incident management, acceptable use, and more. Ensuring these policies are aligned with NIS2 requirements (and any sector-specific standards) will likely be an outcome of your initial gap analysis. Moreover, training and awareness are mandatory components: staff at all levels should be educated on cybersecurity best practices and the procedures to follow. NIS2 specifically mandates that management level representatives be trained in cybersecurity, and more broadly, employees involved in incident response or in key IT roles should receive regular training. Building a security-aware culture – through workshops, e-learning, phishing simulations, etc. – helps reduce human error and keeps security practices effective. Well-defined policies combined with ongoing training ensure that everyone in the organization knows their role in maintaining cybersecurity and compliance.

Common Challenges

Implementing NIS2 and meeting the Cybersecurity Act’s requirements can be challenging. Organizations often encounter a few common hurdles.

  • Understanding the New Requirements
    The legal and technical details of NIS2 can be complex. Many organizations, especially those new to regulation struggle with awareness and interpretation of what exactly the directive requires and whether it applies to them. Determining if you fall within scope (figuring out if your services are in an affected sector and if you meet size thresholds) is an important first step that can be confusing. Even once in scope, translating NIS2’s requirements into concrete actions (e.g. what constitutes “appropriate” measures or a “significant” incident) can be daunting without expert guidance.
  • Resource and Skill Gaps
    Achieving compliance is not as simple as updating a policy – it often demands new investments in technology, processes, and people. Many companies face technical complexity and limited resources when trying to upgrade their cybersecurity capabilities. For instance, smaller organizations might not have a dedicated security team, or budget for new tools, making it challenging to implement all the needed controls. Hiring or training staff with cybersecurity expertise is another hurdle, given the industry-wide skills shortage. In short, organizations may worry about the cost and effort required – it’s a project that touches many parts of the business, not just an IT fix. Studies have noted that full NIS2 compliance can be costly and organizationally demanding, requiring structured approaches to align investments with risk priorities.
  • Integrating Compliance into Existing Processes
    Most organizations already have some cybersecurity or compliance frameworks in place (e.g. ISO 27001, GDPR controls, or earlier NIS directive measures). A challenge is aligning NIS2’s new requirements with your existing governance and processes. This might involve reconciling different frameworks and avoiding duplication of effort. For example, you may need to update your ISO 27001-aligned ISMS to cover NIS2 specifics, or ensure your incident response plan meets the new reporting rules. This integration requires cross-functional coordination – IT, security, legal, risk management, and business units all need to work together so that NIS2 obligations are embedded into day-to-day operations. NIS2 does not exist in isolation and should be mapped alongside other cybersecurity frameworks to create a unified compliance strategy rather than a siloed checklist.
  • Maintaining Ongoing Compliance
    NIS2 compliance is not a one-time tick box; it’s an ongoing effort. After the initial rush to meet the January 2026 deadline, organizations might struggle with sustaining their cybersecurity posture. Threats evolve, business processes change, and regulations will be refined – all of which means your security program needs continuous attention. Continuous improvement and monitoring are challenging for organizations not used to it. Without a plan for regular reviews, tests, and updates, there’s a risk of falling out of compliance over time. It’s widely recognized that achieving NIS2 compliance is “not a one-time project – it’s a maturity journey”, requiring clear milestones, executive support, and continuous improvement to remain effective. Companies need to treat NIS2 as an ongoing program of resilience-building, rather than a one-off compliance task. This can be difficult without external support or an internal champion keeping the momentum.

Frequently asked questions

Which organisations are affected by NIS2?

The Act applies to ‘essential’ and ‘important’ entities across around 18 sectors – including energy, transport, banking and financial-market infrastructure, healthcare, drinking and waste water, digital infrastructure, ICT service management, public administration, postal services, waste, chemicals, food, manufacturing, digital providers and research. As a rule it reaches medium-sized and larger organisations (from 50 employees, or more than €10 million in annual turnover or balance-sheet total), but some entities are in scope regardless of size. Because supply-chain role and sector-specific rules can bring you in even if you have never seen yourself as ‘critical’, a short scoping assessment is usually the right first step.

What does NIS2 mean for management?

Cybersecurity becomes an explicit leadership responsibility. Senior management is expected to approve the risk-management measures, oversee the work and undergo training so they can understand and challenge cyber risk – and management can be held accountable. In practice this means clear ownership reporting to the board, documented decisions, and cyber risk treated as a strategic business risk rather than an IT-only concern.

Which security measures should we work with?

The work must be systematic and risk-based. NIS2 sets a baseline that in-scope entities must have in place, including: risk analysis and information-security policy; incident handling; business continuity, backup and crisis management; supply-chain security; security in acquisition, development and maintenance (including vulnerability handling and disclosure); policies to evaluate whether measures work; basic cyber hygiene and training; cryptography and encryption; human-resources security, access control and asset management; and multi-factor authentication and secure communications. Measures must be ‘appropriate and proportionate’ to your risk.

How should we prepare for incident reporting?

Significant incidents follow a three-step timeline: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within one month. In Sweden the reports go to the relevant supervisory authority / CSIRT, and in-scope entities also need to register with their authority. Meeting the deadlines requires a tested process for identifying, escalating, documenting and reporting incidents – decided in advance, not improvised during a crisis.

How can NIS2 be aligned with ISO 27001?

A well-run ISO 27001 management system is a strong foundation – it gives you governance, risk management and controls that map onto much of what the Act expects. But it is not automatically sufficient: the Act adds specific legal duties such as incident reporting to authorities on deadline, registration, mandatory management training and liability, and sector-specific requirements. The efficient path is to extend your existing ISMS to cover those gaps rather than build a separate NIS2 track.

What are the penalties for non-compliance?

The Act is backed by supervision and administrative fines (sanktionsavgift), and responsibility reaches management. For an essential entity the fine can reach the higher of 2% of total global annual turnover or the SEK equivalent of €10 million; for an important entity, the higher of 1.4% or the SEK equivalent of €7 million. Public-sector entities have a separate cap of SEK 10 million, and the minimum fine is SEK 5,000. Beyond fines, the supervisory authority can issue binding orders – and the operational and reputational cost of a serious incident often exceeds the fine itself.

Helping You Comply

At Kristensson i Skåne AB, we specialize in Information Security & Governance and serve as a partner-oriented advisor to guide you through NIS2 and the Cybersecurity Act compliance process. Whether you’re just starting your NIS2 readiness journey or you need to enhance ongoing efforts, our team is here to help every step of the way. Our approach is structured and tailored to your organization’s needs, typically covering.

  • NIS2 Readiness Assessment & Gap Analysis
    We begin by evaluating your current security posture against NIS2 requirements. This baseline assessment identifies which parts of the directive apply to you and where gaps exist in your controls, policies, and procedures. Our consultants will review key areas – from risk management processes to incident response plans and third-party arrangements – to see how they stack up against the new obligations. This often includes conducting interviews and document reviews to understand your existing capabilities. The outcome is a detailed gap analysis showing what is already in place and what needs improvement. By understanding your starting point, we can prioritize efforts on the most critical gaps that pose compliance or security risks.
  • Compliance Roadmap & Strategy
    Based on the assessment findings, we work with you to develop a tailored roadmap for NIS2 compliance. This roadmap is essentially a strategic project plan that plots out the required remediation steps and initiatives in a logical order. We help you prioritize actions by risk and regulatory impact – for example, you might need to first establish an incident reporting procedure and then improve technical measures like network monitoring. The roadmap will outline concrete measures such as updating or drafting security policies, implementing specific technical controls (e.g. improved access management or encryption where needed), enhancing vendor risk management processes, and defining governance structures (like assigning a NIS2 responsible owner or reporting mechanism to your board). We set clear timelines, responsibilities, and milestones for each task. Importantly, we align this plan with your business objectives and any frameworks you already follow. By leveraging standards you use (ISO 27001, NIST CSF, etc.), we ensure existing investments are utilized and the NIS2 compliance efforts integrate smoothly into your overall security program. The roadmap gives you a structured path forward so you can move from gap identification to full implementation in an organized, manageable way.
  • Implementation & Policy Development
    Achieving compliance involves making tangible improvements, and our team provides hands-on support to implement the roadmap’s initiatives. This includes developing and updating documentation – we can help write all the necessary security policies, procedures, and guidelines to meet NIS2 requirements. For instance, we assist in creating or refining your incident response plan (to incorporate the new reporting criteria), business continuity and disaster recovery plans, risk assessment procedures, third-party security assessment checklists, and any other governance documents needed. We ensure these documents are not just compliant, but also practical and tailored to your organization’s context. On the technical side, our experts can advise on or help implement security controls like improved network security measures, vulnerability management processes, monitoring solutions, or access controls, depending on what your gap analysis showed. We coordinate with your IT and security teams (or external providers) to embed these measures effectively. Throughout implementation, Kristensson provides project management and overview to keep things on track. Our goal is to not only check the compliance boxes but to strengthen your overall security – for example, by instituting regular risk review meetings or integrating security requirements into procurement processes. By the end of this phase, you will have the required measures and structures in place – from updated policies to technical safeguards – laying a strong foundation for compliance and cyber resilience.
  • Training & Awareness Programs
    Compliance is as much about people as it is about processes. We help ensure that all relevant stakeholders are knowledgeable and prepared to fulfill their roles under NIS2. A key offering is targeted training for different groups in your organization. For top management and board members, we provide executive briefings or workshops to fulfill the Act’s requirement that management be trained in security measures – giving leaders a clear understanding of their cybersecurity responsibilities and the basics of cyber risk overview. For IT and security teams, we can conduct in-depth training or drills on the new incident reporting and response procedures, so they’re ready to meet the 24-hour notification rule and manage incidents effectively. We also offer general security awareness training for all employees, tailored to your policies and threat landscape (covering topics like phishing, safe data handling, and incident escalation). These sessions and materials help cultivate a security-conscious culture, which is essential for NIS2 readiness. When your staff are aware of the risks and vigilant in following security best practices, your organization not only complies with the regulations’ spirit but also significantly reduces the likelihood of breaches. Kristensson can schedule recurring training, provide e-learning content, or even run simulated cyber incident exercises to keep everyone sharp and aware. This comprehensive approach to education ensures that from the senior management to the frontline, everyone is aligned with your cybersecurity governance.
  • Continuous Support & Improvement
    Compliance doesn’t end once the initial measures are in place – regulators (and good security governance) expect ongoing vigilance. Kristensson i Skåne AB offers ongoing support services to help you maintain and improve your NIS2 compliance posture over time. This can include periodic audits or maturity assessments to verify that controls remain effective and identify new gaps as your business or the threat environment changes. We can assist in continuous monitoring activities, such as reviewing log management or incident reports, to ensure any security events are noticed and managed per your procedures. We also stay abreast of updates in regulations and standards, keeping you informed about any changes (for example, new guidance from authorities or sector-specific rules) that might affect your compliance. If desired, our experts can participate in annual strategy reviews or governance meetings to provide an external perspective on cybersecurity. The idea is to embed a cycle of continuous improvement – much like ISO 27001’s Plan-Do-Check-Act model – into your operations. By doing so, you transform NIS2 compliance from a one-off project into a sustainable, living program. Remember, maintaining compliance is a journey, not a destination: we help you establish metrics and dashboards to track your progress and ensure accountability at the executive level, reinforcing that cybersecurity remains a priority. With our ongoing partnership, you can adapt to new threats and regulatory expectations confidently, knowing that your NIS2 obligations are consistently met and your organization’s resilience keeps strengthening.

Navigating NIS2 and the Swedish Cybersecurity Act can seem complex, but you don’t have to do it alone. Kristensson i Skåne AB is your experienced partner in achieving information security compliance and building a robust cyber defenses. We take a clear, action-oriented approach to help you prepare, comply, and excel under the new regulations. Whether you need an initial gap assessment or hands-on help refining your security program, our team is ready to assist.

Contact us today to discuss your NIS2 readiness or ongoing compliance needs. Let’s work together to ensure your organization not only meets the Cybersecurity Act requirements but gains lasting security improvements. With the right guidance and support, you can turn regulatory compliance into an opportunity to strengthen trust, resilience, and confidence in your business – so you can focus on your core operations knowing your information security and governance are in expert hands.

Related reference cases: An ISO 27001 (ISMS) implementation and project management for a DORA implementation – see our reference cases.

Get NIS2 Ready

Selected official sources: European Commission: NIS2 Directive; EUR-Lex: Directive (EU) 2022/2555; ENISA: NIS Directive 2.