NIS2 & Cybersecurity Act
NIS2 (the second EU Network and Information Security Directive) represents a major update to Europe’s cybersecurity regulations, aiming to achieve a high common level of security across member states.
NIS2 (the second EU Network and Information Security Directive) represents a major update to Europe’s cybersecurity regulations, aiming to achieve a high common level of security across member states. In Sweden, NIS2 is implemented through a new Cybersecurity Act (Swedish: Cybersäkerhetslagen), which took effect on 15 January 2026. This Act replaces the previous NIS law and broadens the scope of affected organizations. It applies to essential and important entities across 18 sectors, including energy, healthcare, transport, banking, digital infrastructure, public services and more – generally covering medium and large companies (50+ employees or over €10 million turnover) in those sectors. In short, many organizations that handle critical services or data are now in scope, not only traditional “critical infrastructure” operators. This new regulatory landscape matters because it significantly raises the bar for cybersecurity: companies must adopt stricter security measures, report serious incidents within tight deadlines, ensure supply chain security, and strengthen governance – all under the threat of substantial penalties for non-compliance. Complying with NIS2 and the Swedish Cybersecurity Act is not just a legal checkbox; it’s about bolstering your organization’s resilience against escalating cyber threats and avoiding costly disruptions or fines.
In brief
- Who
- Essential and important entities in the sectors affected by the Swedish Cybersecurity Act, and their suppliers
- What
- Risk-based security measures, management responsibility and training, incident reporting within 24 and 72 hours, supply chain security, policies and training
- How
- Readiness assessment and gap analysis, roadmap, implementation and policies, training for management and staff, ongoing follow-up
Key Focus Areas & Requirements
NIS2 and the Swedish Cybersecurity Act introduce a set of requirements and focus areas, following established practice, that organisations have to handle. The central ones are these.
- Risk management and security measures
Organisations in scope must take a risk-based approach. That means assessing threats and vulnerabilities regularly and putting “appropriate and proportionate” technical, operational and organisational measures in place to protect networks and information systems. Risk analyses should be kept current, with controls in line with established standards such as ISO 27001 to reduce the risks identified. It also covers business continuity — being able to maintain or quickly restore critical operations during an incident, through backups, disaster recovery plans and the rest. The emphasis is on proactive risk management: anticipating risks and dealing with them before they turn into incidents. - Governance and management responsibility
NIS2 makes cybersecurity a matter for management and the board. Management is expected to have oversight of, and be accountable for, the organisation’s cyber risk. The Swedish Cybersecurity Act additionally requires that senior management receives training in cybersecurity measures, so they are equipped to identify risks and decide on security investment. In practice that means integrating security into the governance model — making roles and responsibilities explicit, such as a CISO or security owner reporting to management, and having management approve and regularly follow up the security policies. A culture of accountability at the top is decisive: cybersecurity belongs with the strategic business risks, not only with IT. - Incident handling and reporting
A core NIS2 requirement is solid incident handling and prompt reporting of significant incidents to the authorities. Organisations need internal incident plans and the ability to detect, so they can act quickly and effectively on a major incident such as an intrusion or a disruption. Significant incidents are reported to the National Cyber Security Centre (NCSC) through the Cyberportalen within the prescribed timeframes. The recipient is the NCSC through CERT-SE, Sweden’s national CSIRT, which then forwards the report to the relevant supervisory authority. An initial notification, the early warning, is typically required within 24 hours of becoming aware of the incident, with a more detailed report within 72 hours. Further updates or a final report may be required within a month. The team therefore has to be able to recognise an incident, follow a defined escalation process and gather the necessary information quickly. The NIS2 reporting rules also cover informing recipients of services about incidents that affect them. Tested incident and crisis communication plans are critical, both to meet the requirements and to limit the damage. - Third-party and supply chain security
Your security is no stronger than the weakest link in the supply chain. NIS2 puts more weight on managing the cyber risks that come with third-party services and suppliers. Organisations need to assess and improve security at their suppliers, service providers and partners. In practice that can mean due diligence or audits of key suppliers, updated contracts carrying cybersecurity requirements, and suppliers putting adequate safeguards in place. The Swedish implementation names supply chain security explicitly, and many organisations need a gap analysis and updates to internal governing documents and supplier agreements to handle it. Extending risk management to third parties reduces the chance that a supplier breach or a supply chain attack reaches your critical services. Ongoing follow-up, reviewing third-party reports or certifications, becomes part of compliance. - Security policies and training
Meeting NIS2 is not only a technical matter — it takes governance, policies and people. Organisations should establish or update policies and routines covering access, data protection, incident handling, acceptable use and the rest. Getting those policies aligned with NIS2, and with any sector requirements, is often an outcome of the initial gap analysis. Training belongs here too, but the requirements differ. NIS2 and the Swedish Cybersecurity Act place an explicit requirement on training for management. Broader security awareness among staff is instead one of the organisational measures to be taken on the basis of risk — important, but not the same statutory requirement that applies to management. In practice that means regular training for key roles in incident handling and IT, and basic awareness for everyone else. Building a security-aware culture through workshops, e-learning and phishing simulations reduces human error and keeps the routines effective. Clear policies together with ongoing training mean everyone knows their part in maintaining security and compliance.
Common Challenges
Implementing NIS2 and meeting the requirements of the Swedish Cybersecurity Act can be demanding. The common obstacles are these.
- Understanding the new requirements
The legal and technical detail in NIS2 can be complex. Many organisations, particularly those new to regulation, have limited awareness and find it hard to interpret exactly what the directive requires and whether it applies to them. Determining whether you are in scope — which sector, which size criteria — is an important first step and can be confusing. Even once you know you are in scope, translating the requirements into concrete measures is hard without expert support: what counts as appropriate protection, or as a significant incident. - Resource and competence gaps
Compliance is rarely a policy update; it takes investment in technology, processes and people. Many organisations meet technical complexity and limited resources when improving their security capability. Smaller organisations may have no security team and no budget for tooling, which makes it difficult to put every control in place. Recruiting or training the competence is also hard in a market short of it. In short, this is an organisation-wide initiative rather than a simple IT measure. Full NIS2 compliance is known to be costly and organisationally demanding, which calls for a structured approach where investment is prioritised by risk. - Integrating compliance into existing processes
Most organisations already work to a framework — ISO 27001, GDPR controls, or measures from the earlier NIS directive. The challenge is fitting NIS2 to the existing governance without duplicating effort. That can mean updating the ISMS to cover the NIS2-specific requirements, or making sure incident plans meet the new deadlines. It takes cross-functional work between IT, security, legal, risk and the business, so that NIS2 becomes part of the everyday work rather than a separate checklist. - Sustaining compliance over time
NIS2 is not a one-off effort but an ongoing programme. After the initial push ahead of January 2026 it can be hard to hold the level. Threats change, the business changes and the regulation is clarified, which means the security programme needs continuous attention. Without a plan for regular reviews, testing and updates, compliance drifts. NIS2 compliance is a maturity journey, with clear milestones, management backing and continuous improvement. For many that requires an internal owner driving it, or an external partner to keep the momentum.
Helping You Comply
At Kristensson i Skåne AB we specialise in information security and governance and work as a partner-minded adviser guiding you through NIS2 and the Swedish Cybersecurity Act. Whether you are at the start or need to strengthen work already under way, we help across the whole of it. Our approach is structured, risk-based and fitted to your organisation, and usually focuses on these.
- NIS2 readiness assessment and gap analysis
We start by assessing your current state against NIS2. The assessment shows which parts apply to you and where the gaps sit in controls, policies and routines. We review the key areas — risk management, incident handling and third-party governance — through interviews and document review. The outcome is a detailed gap analysis showing what is already in place and what needs to improve, with clear priorities. - Roadmap and compliance strategy
From those findings we produce a tailored roadmap: a plan setting out the measures, the order, the priorities and the milestones. We prioritise by risk and regulatory impact, and align with your business goals and the frameworks you already use, ISO 27001 and NIST CSF among them, so the investments you have already made carry as far as they can. The roadmap covers policies, technical controls, supplier governance and governance itself — the named owner, and the reporting to board and management. - Implementation and policy development
We help you carry the improvements out with hands-on support. That includes updating or producing the governing documents: incident plans with the new reporting requirements, continuity and DR plans, risk routines, third-party checklists and the rest. We also support the technical controls — network security, vulnerability management, monitoring, IAM — depending on where your gaps are. We hold the delivery together with clear project management, and keep the focus on both compliance and real security improvement. - Training and security awareness
Compliance is as much about people as about technology. We offer targeted training for management and the board, to meet the requirement in the Act, for IT and security teams on incident reporting and the 24-hour rule, and general security training for all staff. We can also run recurring exercises and incident simulations to build a security culture and reduce the risk of human error. - Continuous support and improvement
We offer ongoing support so the level holds over time: periodic audits and maturity assessments, follow-up of controls, and support when the threat picture or the regulation changes. We help you put a continuous improvement cycle in place, PDCA for instance, with measures and dashboards so that ownership and progress are visible at management level. The aim is to make NIS2 a living programme that strengthens your resilience.
Navigating NIS2 and the Swedish Cybersecurity Act can seem complex, but you don’t have to do it alone. Kristensson i Skåne AB is your experienced partner in achieving information security compliance and building a robust cyber defenses. We take a clear, action-oriented approach to help you prepare, comply, and excel under the new regulations. Whether you need an initial gap assessment or hands-on help refining your security program, our team is ready to assist.
Want to know what it would look like for you? Contact us and we will tell you more. Read more about how we work and about our gap analysis against NIS2.
Frequently asked questions
Which organisations are affected by NIS2?
The Act applies to ‘essential’ and ‘important’ entities across around 18 sectors – including energy, transport, banking and financial-market infrastructure, healthcare, drinking and waste water, digital infrastructure, ICT service management, public administration, postal services, waste, chemicals, food, manufacturing, digital providers and research. As a rule it reaches medium-sized and larger organisations (from 50 employees, or more than €10 million in annual turnover or balance-sheet total), but some entities are in scope regardless of size. Because supply-chain role and sector-specific rules can bring you in even if you have never seen yourself as ‘critical’, a short scoping assessment is usually the right first step.
What does NIS2 mean for management?
Cybersecurity becomes an explicit leadership responsibility. Senior management is expected to approve the risk-management measures, oversee the work and undergo training so they can understand and challenge cyber risk – and management can be held accountable. In practice this means clear ownership reporting to the board, documented decisions, and cyber risk treated as a strategic business risk rather than an IT-only concern.
Which security measures should we work with?
The work must be systematic and risk-based. NIS2 sets a baseline that in-scope entities must have in place, including: risk analysis and information-security policy; incident handling; business continuity, backup and crisis management; supply-chain security; security in acquisition, development and maintenance (including vulnerability handling and disclosure); policies to evaluate whether measures work; basic cyber hygiene and training; cryptography and encryption; human-resources security, access control and asset management; and multi-factor authentication and secure communications. Measures must be ‘appropriate and proportionate’ to your risk.
How should we prepare for incident reporting?
Significant incidents follow a three-step timeline: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within one month. In Sweden the reports are submitted through Cyberportalen to the National Cyber Security Centre (NCSC) via CERT-SE, which forwards them to the relevant supervisory authority, and in-scope entities also need to register. Meeting the deadlines requires a tested process for identifying, escalating, documenting and reporting incidents – decided in advance, not improvised during a crisis.
How can NIS2 be aligned with ISO 27001?
A well-run ISO 27001 management system is a strong foundation – it gives you governance, risk management and controls that map onto much of what the Act expects. But it is not automatically sufficient: the Act adds specific legal duties such as incident reporting to authorities on deadline, registration, mandatory management training and liability, and sector-specific requirements. The efficient path is to extend your existing ISMS to cover those gaps rather than build a separate NIS2 track.
What are the penalties for non-compliance?
The Act is backed by supervision and administrative fines (sanktionsavgift), and responsibility reaches management. For an essential entity the fine can reach the higher of 2% of total global annual turnover or the SEK equivalent of €10 million; for an important entity, the higher of 1.4% or the SEK equivalent of €7 million. Public-sector entities have a separate cap of SEK 10 million, and the minimum fine is SEK 5,000. Beyond fines, the supervisory authority can issue binding orders – and the operational and reputational cost of a serious incident often exceeds the fine itself.
Want to know where you stand against the Cybersecurity Act?
Contact us