How to tell whether your organisation is affected by the new Swedish Cybersecurity Act – and what you need to have in place.
NIS2 is the EU’s updated cybersecurity directive. In Sweden, the directive has been implemented through the Swedish Cybersecurity Act (Cybersäkerhetslagen), which entered into force on 15 January 2026.
The law means that far more organisations than before need to work in a more structured way with cybersecurity, risk management, incident reporting and supplier governance. For many, the first question is not exactly how to meet the requirements, but whether the organisation is affected at all.
That is often where the work should begin.
Is your organisation affected by the Swedish Cybersecurity Act?
The Swedish Cybersecurity Act applies to operators in a number of designated sectors, including energy, transport, healthcare, banking, digital infrastructure, public administration and certain digital services.
In practice, organisations need to assess three things:
- which sector the operations belong to
- whether the operations meet the relevant size criteria
- whether there are specific exemptions or rules that mean the organisation is affected anyway
For many companies this is not obvious. An operation can, for example, be an important part of a supply chain, handle critical services, or be affected through its role in a regulated sector – even if it has never seen itself as “critical infrastructure”.
That is why an initial scoping assessment is often a wise first step.
What does the law require?
If the organisation is affected, it needs to be able to show that its cybersecurity work is systematic, risk-based and anchored with management.
Some central areas are:
Risk-based security
The organisation needs to continuously assess threats, vulnerabilities and consequences, and implement proportionate technical and organisational security measures.
Management responsibility
Cybersecurity becomes more clearly a matter for management and the board. Management needs to understand the risks, follow up on the work and ensure that responsibilities, resources and competence are in place.
Incident reporting
Significant incidents need to be identified, escalated, documented and reported within short timeframes. That requires processes, roles and practised ways of working.
Supply chain security
The organisation needs to have control over its important suppliers and subcontractors. That can mean clearer requirements in contracts, better follow-up and risk-based supplier assessments.
Policies, procedures and training
Technology is not enough. Employees, managers and key roles need to understand their responsibilities and know how to act in everyday work and during incidents.
Why is this hard for many organisations?
We often see four challenges.
The first is understanding whether the law applies to your operations. That requires both knowledge of the sectors and an understanding of how the business actually operates.
The second is translating the requirements into practical measures. Wordings such as “appropriate and proportionate security measures” need to become concrete decisions, controls and procedures.
The third is coordinating the work with what already exists. Many organisations already have ISO 27001, GDPR routines, incident processes or supplier requirements. It is rarely wise to build an entirely new parallel track for NIS2.
The fourth is sustaining the work over time. Compliance is not a one-off effort. The threat landscape, the business, systems and suppliers change, and the security work needs to be followed up and adjusted accordingly.
How to get started
A good first step is a current-state analysis.
It should answer three questions:
- Are we affected by the Swedish Cybersecurity Act?
- What do we already have in place?
- Which gaps should be prioritised first?
From there, you can create a realistic action plan instead of trying to solve everything at once.
We help organisations with scoping assessments, current-state analysis, gap analysis and practical implementation related to the Swedish Cybersecurity Act/NIS2. The work can also be connected to existing frameworks and processes, such as ISO 27001, GDPR, incident management, business continuity and supplier governance.
Read more about how we work with NIS2 and the Swedish Cybersecurity Act or contact us for an initial conversation.
Curious what this looks like in practice? Our reference cases include an ISO 27001 (ISMS) implementation and project management of a DORA implementation.
Frequently asked questions about NIS2 and the Swedish Cybersecurity Act
The Act applies to ‘essential’ and ‘important’ entities across around 18 sectors – including energy, transport, banking and financial-market infrastructure, healthcare, drinking and waste water, digital infrastructure, ICT service management, public administration, postal services, waste, chemicals, food, manufacturing, digital providers and research. As a rule it reaches medium-sized and larger organisations (from 50 employees, or more than €10 million in annual turnover or balance-sheet total), but some entities are in scope regardless of size. Because supply-chain role and sector-specific rules can bring you in even if you have never seen yourself as ‘critical’, a short scoping assessment is usually the right first step.
Cybersecurity becomes an explicit leadership responsibility. Senior management is expected to approve the risk-management measures, oversee the work and undergo training so they can understand and challenge cyber risk – and management can be held accountable. In practice this means clear ownership reporting to the board, documented decisions, and cyber risk treated as a strategic business risk rather than an IT-only concern.
The work must be systematic and risk-based. NIS2 sets a baseline that in-scope entities must have in place, including: risk analysis and information-security policy; incident handling; business continuity, backup and crisis management; supply-chain security; security in acquisition, development and maintenance (including vulnerability handling and disclosure); policies to evaluate whether measures work; basic cyber hygiene and training; cryptography and encryption; human-resources security, access control and asset management; and multi-factor authentication and secure communications. Measures must be ‘appropriate and proportionate’ to your risk.
Significant incidents follow a three-step timeline: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within one month. In Sweden the reports go to the relevant supervisory authority / CSIRT, and in-scope entities also need to register with their authority. Meeting the deadlines requires a tested process for identifying, escalating, documenting and reporting incidents – decided in advance, not improvised during a crisis.
A well-run ISO 27001 management system is a strong foundation – it gives you governance, risk management and controls that map onto much of what the Act expects. But it is not automatically sufficient: the Act adds specific legal duties such as incident reporting to authorities on deadline, registration, mandatory management training and liability, and sector-specific requirements. The efficient path is to extend your existing ISMS to cover those gaps rather than build a separate NIS2 track.
The Act is backed by supervision and administrative fines (sanktionsavgift), and responsibility reaches management. For an essential entity the fine can reach the higher of 2% of total global annual turnover or the SEK equivalent of €10 million; for an important entity, the higher of 1.4% or the SEK equivalent of €7 million. Public-sector entities have a separate cap of SEK 10 million, and the minimum fine is SEK 5,000. Beyond fines, the supervisory authority can issue binding orders – and the operational and reputational cost of a serious incident often exceeds the fine itself.

