Five things to check before 1 October under the Swedish Cybersecurity Act

Five things to check before 1 October – new requirements under the Cybersecurity Act

On 1 October 2026, new regulations on security measures and management training take effect. Five areas to check now – from management responsibility and risk to continuity, suppliers and follow-up.

Summary: On 1 October 2026, new regulations on security measures and management training take effect for many entities covered by the Swedish Cybersecurity Act. The requirements become considerably more concrete. Here are five areas organisations should check now – from management responsibility and risk management to continuity, suppliers and follow-up.

The Swedish Cybersecurity Act, which implements NIS2 in Swedish law, has been in force since 15 January 2026. On 1 October, the next important step is taken when MCFFS 2026:11, regulations and general guidance on security measures and management training, enters into force. At the same time, MCFFS 2026:12 on security audit and security scanning also starts to apply.

For organisations that have already worked with NIS2 for a while, it is therefore a good moment to move from the question:

“Have we started with NIS2?”

to:

“Can we show that our security work actually works?”

The new regulations are clearly based on a systematic and risk-based approach. The organisation should not only identify risks and introduce measures, but also follow up, evaluate and improve them. The work must also be integrated with the organisation’s existing management and governance.

Here are five areas we think are especially important to check before 1 October.

1. Does management have the right knowledge – and does it actually take responsibility?

Management responsibility is a central part of the Cybersecurity Act.

It is not enough for the information security manager, the CISO or the IT manager to know the requirements.

According to the new regulations, management training should provide sufficient knowledge and competence for management to be able to set goals and direction for cybersecurity, assess which security measures are needed and follow up on implementation.

Therefore check:

  • Has management completed relevant training?
  • Does management understand the organisation’s most important cyber risks?
  • Are there clear goals and a decided direction for the cybersecurity work?
  • Are roles, authority and resources clearly allocated?
  • Does management receive recurring reporting on risks, measures and security level?

The regulations also state that management should be informed about the implementation of security measures and the organisation’s cybersecurity level when needed, but at least once a year.

This makes cybersecurity a clear part of business governance – not a question that can be left entirely to IT.

2. Is the risk work current and connected to the business?

A risk register that was updated two years ago is a poor basis for today’s security work.

The regulations require that risks are identified, analysed and evaluated based on consequence and likelihood. The risk work should, among other things, build on information classification, threat monitoring and lessons from incidents and near misses. The organisation should also establish criteria for risk acceptance and be able to update analyses when threats and vulnerabilities change.

So don’t just check whether risk analyses exist. Ask:

  • Are they still relevant?
  • Are our most critical information assets and systems identified?
  • Are the risks linked to concrete measures and owners?
  • Are there decided criteria for the risk the organisation actually accepts?

This is also where a current-state or gap analysis can be valuable – but only if the result leads on to prioritisation and implementation.

3. Do incident, continuity and recovery work together?

Having an incident plan is not the same as being able to handle a serious disruption.

The new regulations set clear requirements on continuity. The organisation should, among other things, assess the need for continuity of information processing, establish a priority order for recovery and develop alternative ways of working where needed. The general guidance also states that alternative ways of working and recovery of sector-critical systems should be exercised when needed, but at least annually.

That means a few practical questions need clear answers:

  • Which operations and services must be prioritised?
  • Which systems are most critical?
  • How long can they be unavailable?
  • How does the business continue if the systems cannot be used?
  • How are systems and information recovered?
  • When were backup and recovery last tested?
  • When are the incident process, continuity plan and crisis management activated?

A plan that has never been tested is largely based on assumptions.

That is why testing, exercises and recurring verification need to be a natural part of the work.

4. Do you have control over your suppliers – even after the contract is signed?

Supplier risk also becomes clearer.

Before systems are purchased or information processing is outsourced, the organisation should evaluate and manage the cybersecurity risks. A prospective supplier should also be assessed based on its ability to meet the required security requirements throughout the contract period.

That means supplier management needs to cover more than a security questionnaire ahead of procurement.

For critical suppliers, the organisation should know:

  • what information and which services the supplier handles
  • what risk the supplier poses
  • which subcontractors are used
  • which security requirements are in the contract
  • how incidents and vulnerabilities should be communicated
  • how continuity and recovery work
  • how compliance is followed up during the contract period
  • what happens when the contract ends

The regulations also specifically address existing contracts. The organisation should identify and manage the need to, where possible, supplement contracts entered into before 1 October 2026 if the cybersecurity requirements are insufficient.

This makes supplier review and ongoing third-party risk management an important part of the preparations.

5. Can you show that the security measures actually work?

This is perhaps the most important check.

Being able to show a policy, a risk analysis and a number of technical settings no longer gets you very far.

The organisation needs to be able to follow up on whether the security measures are appropriate and proportionate in relation to requirements, needs and risks.

For sector-critical systems, follow-up and evaluation under MCFFS 2026:11 should take place when needed and at least once a year. The methods mentioned include review, measurement and tests as well as self-assessment, internal and external audit.

So the question is not only “Have we introduced MFA?” but also “Are the right users, accounts and systems covered – and are we still checking that?”

Not only “Do we have backup?” but “Have we verified that it can be restored within the time the business needs?”

Not only “Do we have an incident process?” but “Has it been exercised, and do the people involved know what to do?”

At the same time, MCFFS 2026:12 on security audit and security scanning enters into force. The regulation governs, among other things, how audit and scanning should be carried out when such measures are decided within supervision, and a security audit covers both the design and the actual application of security measures.

This reinforces an important principle: documentation is necessary – but it is the actual application that needs to hold up.

Don’t start by creating more documentation than you need

It is easy to meet new requirements by writing more policies, instructions and checklists.

But the regulations point rather towards a coherent way of working.

The cybersecurity work should be integrated with the organisation’s existing governance. Risks should lead to measures. Measures should be followed up. The result should be fed back to management and the work improved over time.

If the organisation already has a functioning management system based on, for example, ISO 27001, it should therefore be natural to build on it, rather than creating an entirely separate “NIS2 system”.

How Kristensson i Skåne can support the work

Kristensson i Skåne helps organisations translate the Cybersecurity Act and NIS2 into practical and proportionate security work.

We can support with, among other things:

  • scoping and current-state assessment
  • gap analysis against the Cybersecurity Act and the regulations
  • risk analysis and a prioritised action plan
  • governance model, roles and management reporting
  • management and security training
  • incident, continuity and recovery work
  • supplier reviews and third-party management
  • technical verification of security measures
  • internal follow-up and audit preparation
  • ongoing GRC and CISO support

Our starting point is that the work should function after the project is finished.

The goal is not to produce as many documents as possible before 1 October. The goal is for the organisation to understand its risks, have implemented the right security measures and be able to show that they work.

Would you like to know whether you are ready for 1 October? Read more about our work with information security and governance or contact us and we will have a first conversation about your current state and next steps.

A note on the scope of application

MCFFS 2026:11 does not apply in exactly the same way to all sectors. For entities that exclusively operate within, among others, digital infrastructure, digital providers, ICT service management between businesses, postal and courier services and space, only the provision on management training in MCFFS 2026:11 applies. For several of these actors, common security requirements exist in the EU’s directly applicable implementing regulation.

Every organisation therefore needs to assess which provisions and sector-specific requirements apply to its own operations.

Sources and further reading: the Swedish National Cybersecurity Centre (NCSC), MCFFS 2026:11 and MCFFS 2026:12, and the NCSC’s guidance on the Cybersecurity Act. This is an overview and not legal advice.