Published
Summary: 20 questions in five areas show how far you have come with the requirements of the Swedish Cybersecurity Act (cybersäkerhetslagen) and the regulations that have applied since 1 October 2026: responsibility and registration, risk and governance, incidents and continuity, suppliers and development, and everyday protection. The self-test takes 10–15 minutes, and the result appears straight away on a scale from red to green, with suggestions for what to do next. It is an indication, not a legal opinion or an audit.
About this guide
- Who it is for
- Organisations covered by the Swedish Cybersecurity Act, or that think they are, and want to know where they stand.
- What you get
- A self-test in five areas with four questions each, following the Act’s ten basic security measures, that takes 10–15 minutes and shows the result straight away with suggested next steps – guidance, not an audit.
The questions follow the Swedish Cybersecurity Act (2025:1506) and the regulations MCFFS 2026:1, 2026:8 and 2026:11. Answer yes only if you can show it, for example with a document, a procedure or a decision. “It should exist” counts as no. Choose Yes, No or Don’t know for each question, and the result appears straight away on the page. If you are reading without the buttons, count the yes answers in each area.
Your answers stay in your browser and are not stored. We only count that a test was completed and which level it gave. If you would like to be contacted, you send the result yourselves with the form below the result.
First: do you know that your organisation is covered by the Swedish Cybersecurity Act? This question does not count in the result. If you are unsure, start with the self-assessment on who is covered.
Area 1: Responsibility and registration
- Have you registered the organisation with the National Cyber Security Centre (NCSC) at FRA, and do you report changes within 14 days? (Chapter 2, Section 2; MCFFS 2026:1)
- Has management approved the security measures, and is it informed about their implementation at least once a year? (MCFFS 2026:11, Chapter 3, Section 4)
- Has management completed training on security measures? (Chapter 2, Section 4; MCFFS 2026:11)
- Has it been decided who coordinates the cybersecurity work and prepares the material for management? (MCFFS 2026:11)
Area 2: Risk and governance
- Is there a risk analysis of your network and information systems that has been updated in the past year? (Chapter 2, Section 3)
- Is there an information security policy adopted by management? (Chapter 2, Section 3)
- Do you have an inventory of your systems, services and the information they handle? (Chapter 2, Section 3)
- Do you regularly assess whether the security measures work, for example with tests or reviews? (Chapter 2, Section 3)
Area 3: Incidents and continuity
- Can you give an initial alert within 24 hours and an incident notification within 72 hours to NCSC through Cyberportalen? (Chapter 2, Sections 5–8; MCFFS 2026:8)
- Is there a procedure for assessing whether an incident is significant, using the criteria in the regulations, and has it been decided who decides on reporting? (MCFFS 2026:8)
- Are there continuity and crisis plans for the services you provide, and have they been exercised in the past year? (Chapter 2, Section 3)
- Do you test that backups can be restored? (Chapter 2, Section 3)
Area 4: Suppliers and development
- Do you set security requirements in the contracts with the suppliers your services depend on? (Chapter 2, Section 3)
- Have you assessed the risks of your most important suppliers? (Chapter 2, Section 3)
- Are security requirements set when you buy, develop and maintain systems? (Chapter 2, Section 3)
- Is there a procedure for handling vulnerabilities, from discovery to fix? (Chapter 2, Section 3)
Area 5: Everyday protection
- Is multi-factor authentication used for remote access, email and administrator accounts? (Chapter 2, Section 3)
- Do staff only get the access they need, and are permissions reviewed regularly? (Chapter 2, Section 3)
- Are there rules for encryption, and are they followed? (Chapter 2, Section 3)
- Do all staff receive basic training in cyber hygiene? (Chapter 2, Section 3)
- Several of the basics are missing. Start with registration, management responsibility and training, the risk analysis and the ability to report incidents.
- The foundation is partly there, but several parts are missing. Prioritise the areas with two yes answers or fewer.
- Most of it is in place. The remaining gaps can usually be closed with a procedure or a decision.
- The basics are in place. Follow them up at least once a year and when the business changes.
- Gap analysis against ISO 27001, NIS2 or DORA A documented current state, gaps per requirement and a prioritised action plan management can decide on.
- Senior GRC advisory Ongoing support from a senior adviser on governance, risk and compliance, when and as much as you need.
- Management cybersecurity training Training for management and the board that meets the Cybersecurity Act and DORA requirements, documented.
- Interim CISO A senior security leader who takes responsibility for the security work for a period, reporting to management.
- Security maturity assessment An assessment of how well the security measures work in practice, with prioritised improvements.
- Incident preparedness and tabletop exercise An incident procedure with roles and a reporting flow, exercised in a realistic scenario.
- Business continuity management and exercise Impact analysis, continuity plans and an exercise that shows the plans hold.
- Backup and recovery verification We check that the backups exist, are protected and can actually be restored.
- Supplier and third-party review Security requirements in contracts, risk-assessed suppliers and a follow-up procedure.
- Vulnerability assessment and penetration testing We look for the vulnerabilities before someone else does, with a prioritised list of fixes.
Would you like to go through the result with us?
Fill in your details and we will be in touch. The result in the box below is sent with the form, exactly as it reads there. We use the details only to contact you about the result and keep them for one year. Read more in our privacy notice.
Reading the result
- Solid foundation, 18–20 yes: The basics are in place. Follow them up at least once a year and when the business changes.
- Nearly there, 14–17 yes: Most of it is in place. The remaining gaps can usually be closed with a procedure or a decision.
- Clear gaps, 10–13 yes: The foundation is partly there, but several parts are missing. Prioritise the areas with two yes answers or fewer.
- Foundation missing, 9 yes or fewer: Several of the basics are missing. Start with registration, management responsibility and training, the risk analysis and the ability to report incidents.
The same scale applies per area: four yes is a solid foundation, three nearly there, two clear gaps, and one or none means the foundation is missing.
The self-test is an indication. It shows whether the basics seem to be there, not that you comply with the Act. A gap analysis assesses each requirement with evidence. If you answer no or don’t know to the questions on registration, management approval, management training, incident reporting or security requirements on suppliers, it should be looked into whatever the total, and the result shows this below the scale.
What to do next
- Two yes or fewer in at least two areas: start with a gap analysis, which gives a documented current state and a prioritised plan.
- Gaps in single areas: close them yourselves or with senior GRC advisory.
- No to the question on management training: read what the Act and the regulations actually require.
- Solid foundation: follow the work up at least once a year, and go through the ten questions for management.
Would you like to go through the result with us? Read more about NIS2 and the Swedish Cybersecurity Act or contact us.
Sources: the Swedish Cybersecurity Act (2025:1506), Chapter 2, Sections 2–8; the Cybersecurity Ordinance (2025:1507); the regulations MCFFS 2026:1, 2026:8 and 2026:11; Directive (EU) 2022/2555 (NIS2), Articles 20, 21 and 23; the National Cyber Security Centre (NCSC) at FRA, guidance on the Cybersecurity Act. Fact-checked on 4 October 2026.
This text is general information and does not constitute legal advice in an individual case.

