NIS2 Country Guide

NIS2 Sweden: New Cybersecurity Act, Authorities & Key Requirements

Understand how Sweden is implementing the NIS2 Directive (EU) 2022/2555 through the new Cybersecurity Act (Cybersäkerhetslagen), which entities are in scope, how supervision and incident handling will work, and what steps you should take now to get ready before the law applies.

Sweden New Cybersecurity Act from: 15 Jan 2026 Replaces: 2018 NIS Act (2018:1174)

Introduction: NIS2 Directive & the Swedish context

NIS2 strengthens cybersecurity requirements across the EU and significantly widens the range of entities in scope. In Sweden, NIS2 will be implemented through a new Cybersecurity Act (Cybersäkerhetslagen), replacing the current NIS Act on information security for essential and digital services (2018:1174). The new law is planned to apply from 15 January 2026 and will cover both public and private operators across 18 sectors.

If you operate in Sweden (or provide services targeting Swedish users), you should assess whether you qualify as a väsentlig (essential) or viktig (important) entity under NIS2, and map which Swedish supervisory authority will oversee you.

Quick link: Before diving into Sweden’s specifics, read our overview “What is NIS2?” and “NIS vs NIS2” for background.

NIS2 Directive implementation in Sweden

Sweden is implementing NIS2 through a new framework law commonly referred to as the Cybersecurity Act (Cybersäkerhetslagen). The legislative package is based on the inquiry SOU 2024:18 – Nya regler om cybersäkerhet and the government bill “Ett stärkt skydd för nätverks- och informationssystem – en ny cybersäkerhetslag”. The new act will replace the existing NIS Act (2018:1174).

Status

NIS2 transposition is in its final phase. The Cybersecurity Act is planned to enter into force on 15 January 2026, with the current NIS Act being repealed at the same time.

Core legislation

Cybersecurity Act implementing NIS2 and aligning with the EU CER Directive. It sets horizontal rules, with detailed obligations and supervision distributed to sectoral authorities.

Registration

Under NIS2, each in-scope operator must self-identify and notify its activity. MSB will provide an online registration/notification portal when the Cybersecurity Act applies. Until then, organisations can use MSB’s self-assessment tools to understand if they are in scope.

AreaSwedish note
Existing NIS rules The current NIS Act (2018:1174) on information security for essential and digital services remains in force until the Cybersecurity Act starts to apply. NIS2 already influences how current obligations are interpreted.
Public sector The new framework will cover most state authorities and a wide range of regions and municipalities, as “public administration” is its own sector under NIS2. Certain high-level bodies (e.g. parliament, government, courts) are expected to be excluded or covered by other security regulations.
Link with CER Sweden is coordinating NIS2 with the CER Directive to ensure coherent requirements for critical entities (e.g. energy, transport, banking, health). Some operators may be in scope of both regimes.

NIS2 Sweden: what you need to know about compliance & certification

Sweden will use the NIS2 model with two main categories: väsentliga (essential) and viktiga (important) entities, largely based on sector and size, with some entities designated regardless of size.

Scope criteria

  • Operate in one of the sectors listed in Annex I or II of NIS2 (energy, transport, health, water, digital infrastructure, public administration, etc.).
  • Meet NIS2 size thresholds (typically: medium-sized and above – 50+ employees or ≥ EUR 10 million turnover/balance sheet). Larger groups (250+ employees or higher revenues) will often be treated as essential entities.
  • Established in Sweden or providing NIS2-relevant services on Swedish territory. Smaller operators can still be included if they are particularly critical or part of key supply chains.

Obligations

  • Documented risk management and security policies for networks and information systems (IT and OT).
  • Formal incident management and reporting processes, including strict timeframes for serious incidents.
  • Business continuity and crisis management (BCP/DR plans, exercises).
  • Supply-chain security and contractual requirements for key ICT and cloud providers.
  • Secure development, change management and vulnerability handling for systems and software.
  • Governance: board and executive management will have explicit responsibilities for cybersecurity oversight and must ensure adequate training.

Standards & certification

The Cybersecurity Act does not mandate a single standard but encourages alignment with frameworks such as ISO/IEC 27001, NIST CSF 2.0 and sector-specific standards (e.g. IEC 62443 for industrial control systems). Many Swedish authorities reference ISO 27001 as a practical way to structure compliance.

Incident reporting: Serious incidents will have to be reported to the competent authority, typically via MSB and/or CERT-SE, within strict timelines (initial warning, follow-up, and final report). Expect similar timeframes to NIS2 (e.g. 24h / 72h / 1 month) once detailed Swedish rules are published.

Competent authorities & CSIRT in Sweden

NIS2 supervision in Sweden is shared between the national cybersecurity authority and several sectoral regulators. Roles are being refined as the Cybersecurity Act is finalised, but the main building blocks are already clear.

RoleAuthorityNotes
Overall coordination & NIS2 framework Myndigheten för samhällsskydd och beredskap (MSB) Coordinates implementation of NIS2 and the Cybersecurity Act, provides guidance, self-assessment tools, and will host central information about registration and obligations.
National CSIRT / Single Point of Contact CERT-SE (at MSB) Sweden’s national CSIRT. Supports public and private organisations in preventing and managing IT security incidents. Expected to be central in incident reporting and handling under NIS2.
Electronic communications Post- och telestyrelsen (PTS) Sector authority for electronic communications and certain digital infrastructure. Provides NIS/NIS2 guidance for telecom and related services and will supervise relevant operators.
Energy sector Energimyndigheten Proposed supervisory authority for NIS2 in the energy sector (electricity, district heating/cooling, oil, gas, hydrogen). Publishes sector-specific NIS2 guidance and self-evaluation tools.
Other sectors Sector-specific regulators Additional authorities (e.g. for banking, financial market infrastructure, health and food sectors) will supervise NIS2 obligations in their domains. Check MSB’s NIS2 pages for updated lists.

National NIS2 timeline & key dates (Sweden)

27 Dec 2022 — NIS2 Directive (EU) 2022/2555 is published in the EU Official Journal.
17 Oct 2024 — EU deadline for Member States to transpose NIS2 into national law.
5 Mar 2024 — Swedish NIS2/CER inquiry SOU 2024:18 – Nya regler om cybersäkerhet is published.
12 Jun 2025 — Government sends a draft Cybersecurity Act implementing NIS2 to the Council on Legislation.
Autumn 2025 — Government bill “Ett stärkt skydd för nätverks- och informationssystem – en ny cybersäkerhetslag” is submitted to Parliament.
15 Jan 2026 — The new Cybersecurity Act enters into force in Sweden, implementing NIS2 and replacing the previous NIS Act.

Sector-specific requirements (Sweden)

  • Energy: electricity, district heating/cooling, oil, gas and hydrogen suppliers will be in scope, with Energimyndigheten as the main supervisory authority. Additional sector-specific guidance and checklists are being published for energy operators.
  • Public administration: many state agencies, regions and municipalities will be covered as a dedicated NIS2 sector. For public entities, obligations under the Cybersecurity Act will apply alongside other security and continuity regulations.
  • Digital infrastructure & ICT service providers: cloud, data centre services, content delivery, managed security and managed IT services are explicitly targeted by NIS2 and will be important focus areas for Swedish supervisors.
  • Health, food, water and transport: hospitals, laboratories, drinking water suppliers, food producers, and transport operators may be designated as essential or important entities depending on size and criticality.
  • Supply chain: suppliers that are not directly in scope may still need to meet heightened security expectations via contracts if they serve NIS2-covered operators.

Penalties for non-compliance

The Cybersecurity Act introduces administrative fines for serious breaches of NIS2 obligations. For private companies, fines can reach up to approximately EUR 10 million or a percentage of global annual turnover (in line with NIS2 ceilings). For public organisations, the law will set caps in Swedish kronor, with discussions around maximum levels in the range of several million SEK.

Supervisory authorities will also be able to issue binding instructions, require corrective measures, and in some cases impose recurring penalty payments (vite) if serious deficiencies are not addressed.

How to prepare for NIS2 in Sweden

  1. Clarify if you are in scope: check your sector, size, and role in critical services. Use Swedish authorities’ self-assessment tools (e.g. MSB and Energimyndigheten) to identify if you are an essential or important entity.
  2. Map your supervisory authority: determine whether MSB, PTS, Energimyndigheten or another sectoral regulator will oversee you under the Cybersecurity Act.
  3. Perform a gap analysis: compare current controls against NIS2 requirements (governance, risk management, incident handling, business continuity, supply-chain security, training, etc.).
  4. Strengthen governance: ensure the board and executive management understand their NIS2 responsibilities, receive training, and have regular reporting on cyber risks and compliance status.
  5. Update policies and technical measures: align your ISMS (e.g. ISO 27001) with NIS2, covering both IT and OT environments and the full lifecycle of systems.
  6. Prepare for registration: collect the information you will need when MSB’s NIS2 registration portal goes live (legal entity data, sectors, services, contact points, cross-border dependencies).
  7. Build incident readiness: define clear criteria and workflows for reporting serious incidents, including 24/7 escalation paths and coordination with CERT-SE and your sector authority.
  8. Document and evidence: keep records of risk assessments, security measures, exercises, supplier reviews, and training – this documentation will be crucial in supervisory audits.

Official links & resources

FAQ: NIS2 in Sweden

When will NIS2-based rules start to apply in Sweden?
The new Cybersecurity Act (Cybersäkerhetslagen) implementing NIS2 applies from 15 January 2026, replacing the previous NIS Act (2018:1174).
Who is the main authority for NIS2 in Sweden?
MSB (Myndigheten för samhällsskydd och beredskap) coordinates NIS2 implementation and is responsible for several tasks under the directive, working together with sectoral authorities such as PTS and Energimyndigheten.
How do we know if our organisation is covered?
Check whether you operate within one of the sectors listed in Annex I or II of NIS2 and meet the size thresholds (typically medium-sized and above). Public authorities, regions and municipalities may fall within scope regardless of standard SME thresholds. MSB and relevant sector authorities provide self-assessment tools to help you determine if you qualify as an essential or important entity.
Where will we register under NIS2?
Under NIS2, each in-scope operator must self-identify and notify its activities to the relevant authority. Sweden provides an official registration/notification service, coordinated by MSB and sectoral authorities under the Cybersecurity Act. Organizations should prepare by gathering the required information in advance.
Does NIS2 apply to municipalities and regions?
Yes, public administration is a dedicated sector under NIS2. Many state authorities, regions and municipalities in Sweden will be covered by the Cybersecurity Act, although certain top-level bodies (like the parliament and courts) are expected to follow separate security frameworks.
Are we required to certify against ISO 27001?
No, the law does not mandate a specific certification. However, Swedish guidance frequently refers to ISO/IEC 27001 and similar frameworks as practical ways to structure and evidence compliance with NIS2 requirements.
Information provided for general guidance; consult official Swedish sources and legal counsel for the latest updates on NIS2 and the Cybersecurity Act.