Are you ready for the Swedish Cybersecurity Act? A self-test in 20 questions

20 questions in five areas show how far you have come with the Swedish Cybersecurity Act and its regulations. The result appears straight away, red to green.

Summary: 20 questions in five areas show how far you have come with the requirements of the Swedish Cybersecurity Act (cybersäkerhetslagen) and the regulations that have applied since 1 October 2026: responsibility and registration, risk and governance, incidents and continuity, suppliers and development, and everyday protection. The self-test takes 10–15 minutes, and the result appears straight away on a scale from red to green, with suggestions for what to do next. It is an indication, not a legal opinion or an audit.

About this guide

Who it is for
Organisations covered by the Swedish Cybersecurity Act, or that think they are, and want to know where they stand.
What you get
A self-test in five areas with four questions each, following the Act’s ten basic security measures, that takes 10–15 minutes and shows the result straight away with suggested next steps – guidance, not an audit.

The questions follow the Swedish Cybersecurity Act (2025:1506) and the regulations MCFFS 2026:1, 2026:8 and 2026:11. Answer yes only if you can show it, for example with a document, a procedure or a decision. “It should exist” counts as no. Choose Yes, No or Don’t know for each question, and the result appears straight away on the page. If you are reading without the buttons, count the yes answers in each area.

Your answers stay in your browser and are not stored. We only count that a test was completed and which level it gave. If you would like to be contacted, you send the result yourselves with the form below the result.

First: do you know that your organisation is covered by the Swedish Cybersecurity Act? This question does not count in the result. If you are unsure, start with the self-assessment on who is covered.

Area 1: Responsibility and registration

  1. Have you registered the organisation with the National Cyber Security Centre (NCSC) at FRA, and do you report changes within 14 days? (Chapter 2, Section 2; MCFFS 2026:1)
  2. Has management approved the security measures, and is it informed about their implementation at least once a year? (MCFFS 2026:11, Chapter 3, Section 4)
  3. Has management completed training on security measures? (Chapter 2, Section 4; MCFFS 2026:11)
  4. Has it been decided who coordinates the cybersecurity work and prepares the material for management? (MCFFS 2026:11)

Area 2: Risk and governance

  1. Is there a risk analysis of your network and information systems that has been updated in the past year? (Chapter 2, Section 3)
  2. Is there an information security policy adopted by management? (Chapter 2, Section 3)
  3. Do you have an inventory of your systems, services and the information they handle? (Chapter 2, Section 3)
  4. Do you regularly assess whether the security measures work, for example with tests or reviews? (Chapter 2, Section 3)

Area 3: Incidents and continuity

  1. Can you give an initial alert within 24 hours and an incident notification within 72 hours to NCSC through Cyberportalen? (Chapter 2, Sections 5–8; MCFFS 2026:8)
  2. Is there a procedure for assessing whether an incident is significant, using the criteria in the regulations, and has it been decided who decides on reporting? (MCFFS 2026:8)
  3. Are there continuity and crisis plans for the services you provide, and have they been exercised in the past year? (Chapter 2, Section 3)
  4. Do you test that backups can be restored? (Chapter 2, Section 3)

Area 4: Suppliers and development

  1. Do you set security requirements in the contracts with the suppliers your services depend on? (Chapter 2, Section 3)
  2. Have you assessed the risks of your most important suppliers? (Chapter 2, Section 3)
  3. Are security requirements set when you buy, develop and maintain systems? (Chapter 2, Section 3)
  4. Is there a procedure for handling vulnerabilities, from discovery to fix? (Chapter 2, Section 3)

Area 5: Everyday protection

  1. Is multi-factor authentication used for remote access, email and administrator accounts? (Chapter 2, Section 3)
  2. Do staff only get the access they need, and are permissions reviewed regularly? (Chapter 2, Section 3)
  3. Are there rules for encryption, and are they followed? (Chapter 2, Section 3)
  4. Do all staff receive basic training in cyber hygiene? (Chapter 2, Section 3)

Reading the result

  • Solid foundation, 18–20 yes: The basics are in place. Follow them up at least once a year and when the business changes.
  • Nearly there, 14–17 yes: Most of it is in place. The remaining gaps can usually be closed with a procedure or a decision.
  • Clear gaps, 10–13 yes: The foundation is partly there, but several parts are missing. Prioritise the areas with two yes answers or fewer.
  • Foundation missing, 9 yes or fewer: Several of the basics are missing. Start with registration, management responsibility and training, the risk analysis and the ability to report incidents.

The same scale applies per area: four yes is a solid foundation, three nearly there, two clear gaps, and one or none means the foundation is missing.

The self-test is an indication. It shows whether the basics seem to be there, not that you comply with the Act. A gap analysis assesses each requirement with evidence. If you answer no or don’t know to the questions on registration, management approval, management training, incident reporting or security requirements on suppliers, it should be looked into whatever the total, and the result shows this below the scale.

What to do next

Would you like to go through the result with us? Read more about NIS2 and the Swedish Cybersecurity Act or contact us.

Sources: the Swedish Cybersecurity Act (2025:1506), Chapter 2, Sections 2–8; the Cybersecurity Ordinance (2025:1507); the regulations MCFFS 2026:1, 2026:8 and 2026:11; Directive (EU) 2022/2555 (NIS2), Articles 20, 21 and 23; the National Cyber Security Centre (NCSC) at FRA, guidance on the Cybersecurity Act. Fact-checked on 4 October 2026.

This text is general information and does not constitute legal advice in an individual case.