NIS2 Country Guide

NIS2 Sweden: Cybersäkerhetslagen (2025:1506), NCSC & Fines

Sweden implemented the NIS2 Directive through the Cybersecurity Act (Cybersäkerhetslagen, SFS 2025:1506), in force since 15 January 2026. It repealed the 2018 NIS Act. Registration and incident reports now go to NCSC at FRA, and supervision is split across thirteen authorities.

In force: 15 Jan 2026 Law: Cybersäkerhetslagen 2025:1506 Replaced: 2018 NIS Act (2018:1174) Register & report to: NCSC at FRA Last updated: 3 Aug 2026

Introduction: NIS2 Directive & the Swedish context

Sweden transposed NIS2 through the Cybersecurity Act (Cybersäkerhetslagen, SFS 2025:1506), issued on 11 December 2025 and in force since 15 January 2026. It repealed the 2018 NIS Act on information security for essential and digital services (2018:1174), which still governs infringements committed before that date. The Act covers public and private operators across 18 sectors.

If you operate in Sweden, or provide covered services here, you must assess yourself whether you are a väsentlig (essential) or viktig (important) verksamhetsutövare and then register. No authority makes that call for you — see Registration. Which of the thirteen supervisory authorities oversees you depends on your sector and, for public bodies, on your county.

Quick link: Before diving into Sweden’s specifics, read our overview “What is NIS2?” and “NIS vs NIS2” for background.

What you must do in Sweden

These duties have applied since 15 January 2026. There was no transition period.

  • Work out whether you are covered, yourself. Sweden runs on self-assessment. NCSC states plainly that it does not decide whether an individual organisation is in scope, nor how it should be classified. Three tests, in order: type of activity, size, jurisdiction.
  • Register. Chapter 2, Section 2 requires you to notify "as soon as possible". There is no statutory deadline, but NCSC's published position is that supervisory authorities may act if the notification has not arrived within 14 days. See Registration.
  • Put the ten security measures in place. Chapter 2, Section 3 lists them, from risk analysis and incident handling through supply-chain security, cryptography and access control.
  • Train your management. Chapter 2, Section 4 requires the people in an operator's management to undergo training on the security measures.
  • Be able to give early notice within 24 hours. Significant incidents go to the CSIRT unit at FRA on a 24-hour, 72-hour and one-month chain. See Incident reporting.
  • Keep your registration current. Changes must be notified within 14 days of the change.
  • If you are outside the EEA but offer covered services in Sweden, appoint a representative established in Sweden or in another EEA state where you offer them.

NIS2 Directive implementation in Sweden

Sweden implemented NIS2 through the Cybersecurity Act (Cybersäkerhetslagen, SFS 2025:1506), together with the Cybersecurity Ordinance (Cybersäkerhetsförordningen, SFS 2025:1507) which names the supervisory authorities. Both were issued on 11 December 2025 and took effect on 15 January 2026. The package came out of the inquiry SOU 2024:18 – Nya regler om cybersäkerhet and the bill Ett stärkt skydd för nätverks- och informationssystem, and it repealed the 2018 NIS Act (2018:1174) and its ordinance (2018:1175).

Status

In force since 15 January 2026, with no transition period. The registration portal opened on 2 February 2026. Detailed regulations are still being issued through 2026.

Core legislation

Cybersäkerhetslagen (2025:1506) sets the duties; Cybersäkerhetsförordningen (2025:1507) names who supervises what. The Act is horizontal, with supervision distributed across thirteen sectoral and regional authorities.

Registration

Operators self-identify and notify. Since 1 July 2026 notifications are received by NCSC at FRA, not by MCF. The governing regulation is MCFFS 2026:1, which still carries the old agency's name until it is revised.

AreaSwedish note
The old NIS Act Repealed on 15 January 2026. It still applies to infringements committed before that date, so conduct is judged under whichever law was in force at the time.
Public sector Municipalities, regions and municipal associations are in scope regardless of size, and every state agency in scope counts as an essential entity. Excluded outright: the Government, the Government Offices, foreign missions, the committee system, agencies under the Riksdag, the courts, and the elected assemblies — kommunfullmäktige and regionfullmäktige.
Security and law enforcement State agencies whose work is predominantly security-sensitive or law-enforcement fall outside the Act, as do private operators working solely in that space or solely for such agencies. Mixed operators are exempt only for that part of the business — and the carve-out never applies to trust service providers.
Overlap with other rules Entities under DORA are exempt from the security and reporting duties in Chapter 2. More generally, a sector-specific law displaces those duties where its requirements are at least equivalent in effect, taking account of supervision and sanctions.

Compliance & obligations

Sweden uses the two NIS2 categories — väsentliga (essential) and viktiga (important). The duties are broadly the same for both; what differs is how you are supervised and how hard you can be fined.

Three tests, in order

  • Type of activity — one of the 18 sectors, by reference to Annex 1 or 2 of the Directive.
  • Size — medium-sized or larger, as a general rule. You must count partner and linked enterprises, so group structure matters.
  • Jurisdiction — normally where you are established; by exception, where you provide the service, where your main establishment is, or for public bodies the state that set them up.

Some operators are covered regardless of size: municipalities, regions and municipal associations; providers of public electronic communications; trust service providers; sole providers of an essential service in Sweden; and operators of particular national or regional importance.

Which category are you?

Essential (Chapter 1, Section 9) covers:

  • Any state agency in scope, whatever its size.
  • Municipalities, regions, Annex 1 operators and degree-awarding education providers that are larger than medium-sized.
  • Public electronic communications providers of medium size or larger.
  • Top-level domain registries and DNS service providers.
  • Qualified trust service providers.

Important is the residual category: anything in scope that is not essential. The practical difference is supervision — essential entities face regular security audits, while important entities are supervised only where an authority has reason to suspect non-compliance.

Standards & certification

Chapter 2, Section 3 sets ten mandatory areas: risk analysis and system security policies; incident handling; business continuity and crisis management; supply-chain security; security in acquisition, development and maintenance; procedures to assess whether the measures actually work; cyber hygiene and security training; cryptography and encryption; personnel security, access control and asset management; and where needed, multi-factor authentication and secured communications. No certification is mandated, so ISO/IEC 27001, NIST CSF 2.0 or IEC 62443 for industrial control systems remain the practical way to structure and evidence the work.

Management training is required, but no interval is set. Chapter 2, Section 4 says the people in an operator's management must undergo training on the security measures. Unlike Bulgaria, which fixes a two-year cycle in statute, the Swedish Act leaves the frequency open. Treat it as a standing duty and document what you did.

Competent authorities & CSIRT

Sweden distributes NIS2 across more bodies than any member state we have covered. The national roles moved twice in 2026, so a great deal of published guidance — including much that is still online — names the wrong authority.

RoleAuthorityNotes
Single Point of Contact, CSIRT and cyber crisis authority NCSC at FRA — Nationellt cybersäkerhetscenter, at Försvarets radioanstalt Registration and incident reports both go here. Also national coordination towards the supervisory authorities, the EU contact point, and the body that issues the common regulations. Took these roles on 1 July 2026.
National CSIRT (operational) CERT-SE Still Sweden's national CSIRT, and still the name you will deal with in an incident. It now sits within NCSC at FRA rather than at MSB.
Former national coordinator MCF — Myndigheten för civilt försvar MSB was renamed MCF on 1 January 2026, then its cyber operations moved to NCSC on 1 July 2026. Its regulations stay in force under FRA and still carry the MCF name (MCFFS 2026:1) until revised.
Energy Statens energimyndighet Electricity, district heating and cooling, oil, gas, hydrogen and charging infrastructure.
Transport & vehicle manufacturing Transportstyrelsen Transport, plus manufacture of motor vehicles, trailers and semi-trailers and of other transport equipment.
Finance Finansinspektionen Banking and financial market infrastructure.
Healthcare providers Inspektionen för vård och omsorg (IVO) Care providers within the health sector.
Rest of health, and medical devices Läkemedelsverket The health sector other than care providers, and manufacture of medical devices and in vitro diagnostics.
Water & food Livsmedelsverket Drinking water, waste water, and the production, processing and distribution of food.
Digital & postal Post- och telestyrelsen (PTS) Digital infrastructure, digital providers, ICT service management between businesses, postal and courier services, and space. Also supervises the county boards themselves and domain name registration services.
Public sector, waste, chemicals, manufacturing, research Six länsstyrelser (county administrative boards) Norrbotten, Skåne, Stockholm, Västra Götaland, Örebro and Östergötland. They cover public administration, waste management, research, chemicals, computers and electronics, electrical equipment and other machinery — plus degree-awarding education providers and the preparedness agencies. Which one is yours depends on your county: see Sector-specific notes.

Registration & the anmälan

Sweden runs on self-assessment and self-registration. Nobody will tell you that you are in scope, and nobody will confirm your category for you.

The deadline that is not a deadline

Chapter 2, Section 2 says operators must notify “så snart det kan ske” — as soon as possible. No statutory date is set. NCSC's published position is that the supervisory authorities may take action if a notification has not arrived within 14 days. Treat that as the operative expectation, but know the difference between the two.

Where it goes

To the single point of contact — which since 1 July 2026 is NCSC at FRA. The portal opened on 2 February 2026, when notifications still went to MCF. If your guidance says to register with MSB or MCF, it is out of date.

You classify yourself

NCSC states that it does not assess whether an individual organisation is covered, nor how it should be classified by sector or as essential or important. That judgement is yours. Supervisory authorities can give some support.

What the form asks for

  • Organisation name, organisation number, address, email and telephone.
  • Establishment — organisation in Sweden, or representative in Sweden.
  • Sector and any subsector, and whether you carry on that activity elsewhere in the EU or EEA.
  • How you identified yourself as an operator, and whether you are essential or important.
  • Internet identifiers — IP addresses and domain names.
  • Contact details for the person making the notification.
Municipalities and regions must register too, and so must every preparedness agency listed in the annex to the government agencies preparedness ordinance. The governing regulation is MCFFS 2026:1 on notification and identification — it still carries the former agency's name, but FRA is responsible for it now. Changes to anything you have notified must be reported within 14 days.

Incident reporting

Significant incidents go to the CSIRT unit at FRA. The clock starts when you become aware of the incident.

StageDeadlineWhat it is
Early notice 24 hours Inform the authority as soon as possible, and at the latest 24 hours after becoming aware.
Incident notification 72 hours
24 hours for trust service providers
The formal notification of the significant incident.
Interim report On request Relevant status updates, where the authority asks for them.
Final report 1 month after the notification If the incident is still ongoing, a status report is due instead, and the final report one month after it has been handled.

What counts as a significant incident

Chapter 2, Section 5 defines it: an incident that has caused or may cause serious operational disruption to the service, or economic damage to the operator, or that has affected or may affect other natural or legal persons by causing significant damage. Any one of the three is enough.

  • Tell your customers where it is appropriate — for incidents likely to affect service delivery, and for significant cyber threats, where you must also describe the protective measures they can take.
  • Domain registries have a separate 72-hour clock. Top-level domain registries and domain name registration services must answer a lawful, reasoned request for registration data within 72 hours. This does not apply to the .se domain administrator, which follows its own act.

NIS2 timeline & key dates (Sweden)

27 Dec 2022 — NIS2 Directive (EU) 2022/2555 is published in the EU Official Journal.
5 Mar 2024 — the Swedish NIS2 and CER inquiry SOU 2024:18 – Nya regler om cybersäkerhet is published.
17 Oct 2024 — EU transposition deadline. Sweden misses it by nearly 15 months.
14 Oct 2025 — the bill Ett stärkt skydd för nätverks- och informationssystem is presented to the Riksdag.
10 Dec 2025 — the Riksdag adopts the Cybersecurity Act. It is issued on 11 December as SFS 2025:1506.
1 Jan 2026 — MSB is renamed MCF, Myndigheten för civilt försvar.
15 Jan 2026Cybersäkerhetslagen enters into force, repealing the 2018 NIS Act. No transition period.
2 Feb 2026 — the registration portal opens.
1 Jul 2026 — the single point of contact, the CSIRT unit and the cyber crisis authority move from MCF to NCSC at FRA. Registrations and incident reports have gone there since.
Through 2026 — further regulations under the Act continue to be issued.

Sector-specific notes (Sweden)

  • Energy: electricity, district heating and cooling, oil, gas, hydrogen and charging infrastructure, supervised by Statens energimyndighet.
  • Public administration: municipalities, regions and municipal associations are in scope regardless of size, and every state agency in scope is an essential entity. Supervision runs through the county administrative boards, not through a national regulator.
  • Health: supervision is split. IVO takes care providers; Läkemedelsverket takes the rest of the sector and medical device manufacturing.
  • Water and food: drinking water, waste water and the food chain all sit with Livsmedelsverket — one authority for what elsewhere is often three.
  • Digital infrastructure and ICT services: cloud, data centres, content delivery networks, managed services and managed security services, supervised by PTS. Public electronic communications providers are in scope regardless of size, and are the only group that pays fees — a charge for processing the registration and an annual supervisory fee.
  • Education and research: Sweden names private degree-awarding education providers in the Act itself, and research is its own sector. Both are supervised by the county boards.
  • Supply chain: suppliers outside scope can still face contractual security requirements from covered operators, since supply-chain security is one of the ten mandatory measures.

How Sweden differs

Six things here do not carry across from other member states.

  • The whole entity is covered, regardless of size, if it is public. Municipalities, regions and municipal associations are in scope whatever their size, and every state agency in scope is automatically an essential entity. Most member states apply the size test to public bodies too.
  • Group figures count. Sweden requires you to include partner and linked enterprises when measuring size. Bulgaria switches that aggregation off entirely, and Germany relieves it where the entity is IT-independent. The same group can be in scope in Stockholm and out in Sofia.
  • There is no registration deadline in the statute — only “as soon as possible”, with a 14-day enforcement expectation published by the authority. Germany and Luxembourg both set hard dates.
  • Fines have a floor of SEK 5,000 and public bodies have their own flat ceiling of SEK 10 million rather than a turnover percentage.
  • Supervision is regionalised. Six county administrative boards supervise the public sector and several manufacturing sectors, split geographically. No other member state we cover devolves NIS2 supervision to regional government.
  • A management ban is a court decision, not a regulator's. The supervisory authority must apply to an administrative court, and the ban runs for one to three years.

Swedish terms you will meet

SwedishEnglishWhat it is
Cybersäkerhetslagenthe Cybersecurity ActSFS 2025:1506. The law itself.
Cybersäkerhetsförordningenthe Cybersecurity OrdinanceSFS 2025:1507. Names who supervises what.
verksamhetsutövareoperatorThe term for anyone in scope.
väsentlig / viktigessential / importantThe two categories.
anmälannotificationThe registration you must file.
betydande incidentsignificant incidentThe trigger for the 24-hour clock.
tillsynsmyndighetsupervisory authorityThirteen of them.
sanktionsavgiftsanction feeThe administrative fine.
vitepenalty paymentA conditional fine attached to an order. Cannot be combined with a sanction fee for the same breach.
föreläggandeorder / injunctionWhat a supervisor issues to force compliance.
länsstyrelsecounty administrative boardRegional supervisor for the public sector and several manufacturing sectors.
NCSC / FRANational Cyber Security Centre / National Defence Radio EstablishmentWhere registrations and incident reports go.

Penalties for non-compliance

Chapter 4 sets the sanctions. Sweden took the maximum levels the Directive allows, and added a floor the Directive does not require.

WhoSanction fee (sanktionsavgift)
Private essential operator The higher of 2% of total global annual turnover or an amount in kronor corresponding to EUR 10,000,000
Private important operator The higher of 1.4% of total global annual turnover or an amount in kronor corresponding to EUR 7,000,000
Public operator A flat SEK 10,000,000 — no turnover percentage applies
All of the above Minimum SEK 5,000 in every case
  • A fine and a penalty payment are alternatives, not both. No sanction fee may be imposed where the same breach underlies an application to enforce a vite.
  • Two-year limitation. A fee can only be imposed if you were given the chance to respond within two years of the infringement. Payment falls due 30 days after the decision takes legal effect, and an unenforced decision lapses after five years.
  • Intervention is mandatory, not discretionary. Where an operator has failed its duties the authority shall intervene — by order, by applying for a management ban, by a sanction fee, or at minimum by a formal remark.
  • What makes a breach “serious”: repeated infringements, failing to report or inform, failing to remedy a significant incident, ignoring an order, obstructing supervision, or giving false or grossly incorrect information.

Orders, publication and the management ban

Supervisors can order you to comply, and can order you to publish information about your own infringement. Orders may carry a vite, and may be directed at the state itself. They can require documents, enter premises other than dwellings, run security audits, and carry out security scans — those in cooperation with you. If you obstruct them they can call on the enforcement authority, Kronofogdemyndigheten.

For essential operators only, an administrative court may bar an individual from holding a management function for one to three years. It applies where an earlier order went unmet, the underlying breach was serious, and the person caused it intentionally or through gross negligence. The supervisory authority applies; the court decides and must handle the case promptly. Decisions under the Act are appealed to the administrative courts.

How to prepare for NIS2 in Sweden

  1. Run the three tests and write down the answer: type of activity, size (counting partner and linked companies), jurisdiction. Because Sweden runs on self-assessment, your reasoning is your evidence — the registration form asks how you identified yourself.
  2. Identify your supervisor: by sector from the table in Competent authorities — and if you are a public body or a manufacturer supervised by a county board, by the county where you are registered.
  3. Perform a gap analysis: compare current controls against NIS2 requirements (governance, risk management, incident handling, business continuity, supply-chain security, training, etc.).
  4. Strengthen governance: ensure the board and executive management understand their NIS2 responsibilities, receive training, and have regular reporting on cyber risks and compliance status.
  5. Update policies and technical measures: align your ISMS (e.g. ISO 27001) with NIS2, covering both IT and OT environments and the full lifecycle of systems.
  6. Register, if you have not: the portal has been open since 2 February 2026 and notifications go to NCSC at FRA. Have your organisation number, sectors and subsectors, IP addresses and domain names, and your essential-or-important determination ready.
  7. Rehearse the 24-hour clock: agree in advance who decides an incident is betydande, and make sure early notice can reach the CSIRT unit at FRA within 24 hours of awareness — at any hour, on any day.
  8. Document and evidence: keep records of risk assessments, security measures, exercises, supplier reviews and training. Essential operators face regular security audits, so this is what a supervisor will ask to see.

Operating in more than one EU country

NIS2 is one Directive and 27 national laws. Sweden is one of the stricter readings, and several of its rules will not match what you built elsewhere.

  • Four jurisdiction rules. The general rule is the country where you are established. By exception: where you provide the service, where your main establishment is, or — for public administration entities — the member state that set them up.
  • Digital providers are governed from their main establishment. Cloud, data centre, CDN, managed service, managed security, marketplace, search and social network providers answer to one member state, not to each country they serve. In Sweden, that means PTS.
  • Size tests are not portable. Sweden counts partner and linked companies; Bulgaria does not; Germany relieves aggregation only where the entity is IT-independent.
  • Registration mechanics differ more than the duties do. Sweden identifies nobody and expects you to file; Bulgaria compiles the register itself and never publishes it; Germany and Luxembourg set hard deadlines.
  • Reporting clocks travel well. The 24-hour, 72-hour and one-month chain is broadly consistent, including Sweden's 24-hour rule for trust service providers.
  • Sector law can displace the general regime. DORA entities are exempt from the Swedish security and reporting duties, and any equivalent sector law has the same effect.

Official links & resources

Cybersäkerhetslag (2025:1506) — the Act itself, in full.
Cybersäkerhetsförordning (2025:1507) — the ordinance naming every supervisory authority and the county split.
NCSC — Det här är cybersäkerhetslagen — the authority's overview.
NCSC — Omfattas verksamheten av cybersäkerhetslagen? — the three-step scope assessment.
NCSC — Att anmäla en verksamhet — how to register, and what the form asks for.
CERT-SE — the national CSIRT, now at NCSC within FRA.
Energimyndigheten — energy sector guidance on the Act.
PTS — digital infrastructure, digital providers and electronic communications.

FAQ: NIS2 in Sweden

When did the Cybersecurity Act enter into force in Sweden?
15 January 2026. The Cybersecurity Act (Cybersäkerhetslagen, SFS 2025:1506) was adopted by the Riksdag on 10 December 2025, issued on 11 December, and took effect on 15 January 2026 with no transition period. It repealed the 2018 NIS Act (2018:1174), which still governs infringements committed before that date.
Who is the main authority — MSB, MCF or FRA?
NCSC at FRA (Försvarets radioanstalt), as of 1 July 2026. The chain is easy to lose: MSB was renamed MCF on 1 January 2026, and on 1 July 2026 the single point of contact, the CSIRT unit and the cyber crisis authority all moved to NCSC at FRA. Registration and incident reports go there. Day-to-day supervision, though, sits with thirteen sectoral and regional authorities — not with NCSC.
How do we know if we are covered?
You decide. NCSC states that it does not assess whether an individual organisation is in scope or how it should be classified. Work through three tests in order: type of activity (one of the 18 sectors), size (medium-sized or larger, counting partner and linked enterprises), and jurisdiction. Municipalities, regions, public electronic communications providers and trust service providers are covered regardless of size.
Where do we register, and by when?
With NCSC at FRA, through the portal that opened on 2 February 2026. The Act says to notify “as soon as possible” and sets no deadline, but NCSC has said supervisory authorities may act if a notification has not arrived within 14 days. Changes to what you have notified must also be reported within 14 days.
Does the Act apply to municipalities and regions?
Yes — and regardless of size. Municipalities, regions and municipal associations are all covered, and they must register like anyone else. Their supervisor is one of six county administrative boards, determined by county. Excluded outright are the Government, the Government Offices, foreign missions, agencies under the Riksdag, the courts, and the elected assemblies themselves — kommunfullmäktige and regionfullmäktige.
Are we required to certify against ISO 27001?
No. The Act mandates no certification. Chapter 2, Section 3 sets ten areas that your measures must cover, and ISO/IEC 27001 remains a practical way to structure and evidence them — but it is a means, not a requirement.
Are web agencies and digital service providers in scope?
Building websites is not, by itself, a covered activity. What decides it is whether you also provide, on an ongoing basis, one of the services named in Chapter 1, Section 7: managed services (utlokaliserade driftstjänster), managed security services (utlokaliserade säkerhetstjänster), cloud services, data centre services or content delivery networks. A studio that designs and builds a site, hands it over and moves on is generally outside the Act. An agency that also hosts, operates, patches and monitors client systems under a retainer is providing managed services and should assess itself seriously. The size test still applies — medium-sized or larger, counting partner and linked companies — unless you are the sole provider of an essential service or otherwise caught regardless of size. Your supervisor would be PTS.
Which county administrative board supervises us?
For municipalities, regions and operators supervised by a county board, it follows where you are registered:
  • Norrbotten — Jämtland, Norrbotten, Västerbotten, Västernorrland
  • Skåne — Blekinge, Kronoberg, Skåne
  • Stockholm — Gotland, Stockholm
  • Västra Götaland — Halland, Västra Götaland
  • Örebro — Dalarna, Gävleborg, Södermanland, Uppsala, Värmland, Västmanland, Örebro
  • Östergötland — Jönköping, Kalmar, Östergötland
The county boards themselves are supervised by PTS.

Sources & verification

Every date, figure and authority on this page was read out of the Swedish statutory text or the responsible authority's own guidance on 3 August 2026. Public NIS2 trackers contradict each other and are not used here.

  • Cybersäkerhetslag (2025:1506) — scope, registration, the ten security measures, the reporting chain, supervision and the sanction scale.
  • Cybersäkerhetsförordning (2025:1507), as amended by förordning (2026:623) — where registrations and incident reports go, and the full list of supervisory authorities with the county split.
  • NCSC guidance on the Act, on scope assessment and on registration — the 2 February portal opening, the 14-day enforcement position, the self-assessment rule and the contents of the form.
  • MCFFS 2026:1 — the regulation on notification and identification.
What we deliberately do not state. We give no total number of organisations in scope: registration is self-service, no figure is published by the authorities, and the counts circulating in the market are estimates. We do not say MCF has no role — its cyber operations moved to NCSC on 1 July 2026, but its regulations remain in force under FRA and still carry its name. We give no registration deadline, because the Act sets none; we give the statutory wording and NCSC's 14-day enforcement expectation, and label which is which. We give no training frequency, because Chapter 2, Section 4 sets none. And we give the euro ceilings as the Act does — it refers to an amount in kronor corresponding to the euro figure, with no fixed conversion published.
Information provided for general guidance; consult the Cybersecurity Act (2025:1506) and its ordinance as published in Svensk författningssamling, and Swedish legal counsel, for final NIS2 compliance requirements.