NIS2 Sweden: Cybersäkerhetslagen (2025:1506), NCSC & Fines
Sweden implemented the NIS2 Directive through the Cybersecurity Act (Cybersäkerhetslagen, SFS 2025:1506), in force since 15 January 2026. It repealed the 2018 NIS Act. Registration and incident reports now go to NCSC at FRA, and supervision is split across thirteen authorities.
Introduction: NIS2 Directive & the Swedish context
Sweden transposed NIS2 through the Cybersecurity Act (Cybersäkerhetslagen, SFS 2025:1506), issued on 11 December 2025 and in force since 15 January 2026. It repealed the 2018 NIS Act on information security for essential and digital services (2018:1174), which still governs infringements committed before that date. The Act covers public and private operators across 18 sectors.
If you operate in Sweden, or provide covered services here, you must assess yourself whether you are a väsentlig (essential) or viktig (important) verksamhetsutövare and then register. No authority makes that call for you — see Registration. Which of the thirteen supervisory authorities oversees you depends on your sector and, for public bodies, on your county.
What you must do in Sweden
These duties have applied since 15 January 2026. There was no transition period.
- Work out whether you are covered, yourself. Sweden runs on self-assessment. NCSC states plainly that it does not decide whether an individual organisation is in scope, nor how it should be classified. Three tests, in order: type of activity, size, jurisdiction.
- Register. Chapter 2, Section 2 requires you to notify "as soon as possible". There is no statutory deadline, but NCSC's published position is that supervisory authorities may act if the notification has not arrived within 14 days. See Registration.
- Put the ten security measures in place. Chapter 2, Section 3 lists them, from risk analysis and incident handling through supply-chain security, cryptography and access control.
- Train your management. Chapter 2, Section 4 requires the people in an operator's management to undergo training on the security measures.
- Be able to give early notice within 24 hours. Significant incidents go to the CSIRT unit at FRA on a 24-hour, 72-hour and one-month chain. See Incident reporting.
- Keep your registration current. Changes must be notified within 14 days of the change.
- If you are outside the EEA but offer covered services in Sweden, appoint a representative established in Sweden or in another EEA state where you offer them.
NIS2 Directive implementation in Sweden
Sweden implemented NIS2 through the Cybersecurity Act (Cybersäkerhetslagen, SFS 2025:1506), together with the Cybersecurity Ordinance (Cybersäkerhetsförordningen, SFS 2025:1507) which names the supervisory authorities. Both were issued on 11 December 2025 and took effect on 15 January 2026. The package came out of the inquiry SOU 2024:18 – Nya regler om cybersäkerhet and the bill Ett stärkt skydd för nätverks- och informationssystem, and it repealed the 2018 NIS Act (2018:1174) and its ordinance (2018:1175).
Status
In force since 15 January 2026, with no transition period. The registration portal opened on 2 February 2026. Detailed regulations are still being issued through 2026.
Core legislation
Cybersäkerhetslagen (2025:1506) sets the duties; Cybersäkerhetsförordningen (2025:1507) names who supervises what. The Act is horizontal, with supervision distributed across thirteen sectoral and regional authorities.
Registration
Operators self-identify and notify. Since 1 July 2026 notifications are received by NCSC at FRA, not by MCF. The governing regulation is MCFFS 2026:1, which still carries the old agency's name until it is revised.
| Area | Swedish note |
|---|---|
| The old NIS Act | Repealed on 15 January 2026. It still applies to infringements committed before that date, so conduct is judged under whichever law was in force at the time. |
| Public sector | Municipalities, regions and municipal associations are in scope regardless of size, and every state agency in scope counts as an essential entity. Excluded outright: the Government, the Government Offices, foreign missions, the committee system, agencies under the Riksdag, the courts, and the elected assemblies — kommunfullmäktige and regionfullmäktige. |
| Security and law enforcement | State agencies whose work is predominantly security-sensitive or law-enforcement fall outside the Act, as do private operators working solely in that space or solely for such agencies. Mixed operators are exempt only for that part of the business — and the carve-out never applies to trust service providers. |
| Overlap with other rules | Entities under DORA are exempt from the security and reporting duties in Chapter 2. More generally, a sector-specific law displaces those duties where its requirements are at least equivalent in effect, taking account of supervision and sanctions. |
Compliance & obligations
Sweden uses the two NIS2 categories — väsentliga (essential) and viktiga (important). The duties are broadly the same for both; what differs is how you are supervised and how hard you can be fined.
Three tests, in order
- Type of activity — one of the 18 sectors, by reference to Annex 1 or 2 of the Directive.
- Size — medium-sized or larger, as a general rule. You must count partner and linked enterprises, so group structure matters.
- Jurisdiction — normally where you are established; by exception, where you provide the service, where your main establishment is, or for public bodies the state that set them up.
Some operators are covered regardless of size: municipalities, regions and municipal associations; providers of public electronic communications; trust service providers; sole providers of an essential service in Sweden; and operators of particular national or regional importance.
Which category are you?
Essential (Chapter 1, Section 9) covers:
- Any state agency in scope, whatever its size.
- Municipalities, regions, Annex 1 operators and degree-awarding education providers that are larger than medium-sized.
- Public electronic communications providers of medium size or larger.
- Top-level domain registries and DNS service providers.
- Qualified trust service providers.
Important is the residual category: anything in scope that is not essential. The practical difference is supervision — essential entities face regular security audits, while important entities are supervised only where an authority has reason to suspect non-compliance.
Standards & certification
Chapter 2, Section 3 sets ten mandatory areas: risk analysis and system security policies; incident handling; business continuity and crisis management; supply-chain security; security in acquisition, development and maintenance; procedures to assess whether the measures actually work; cyber hygiene and security training; cryptography and encryption; personnel security, access control and asset management; and where needed, multi-factor authentication and secured communications. No certification is mandated, so ISO/IEC 27001, NIST CSF 2.0 or IEC 62443 for industrial control systems remain the practical way to structure and evidence the work.
Registration & the anmälan
Sweden runs on self-assessment and self-registration. Nobody will tell you that you are in scope, and nobody will confirm your category for you.
The deadline that is not a deadline
Chapter 2, Section 2 says operators must notify “så snart det kan ske” — as soon as possible. No statutory date is set. NCSC's published position is that the supervisory authorities may take action if a notification has not arrived within 14 days. Treat that as the operative expectation, but know the difference between the two.
Where it goes
To the single point of contact — which since 1 July 2026 is NCSC at FRA. The portal opened on 2 February 2026, when notifications still went to MCF. If your guidance says to register with MSB or MCF, it is out of date.
You classify yourself
NCSC states that it does not assess whether an individual organisation is covered, nor how it should be classified by sector or as essential or important. That judgement is yours. Supervisory authorities can give some support.
What the form asks for
- Organisation name, organisation number, address, email and telephone.
- Establishment — organisation in Sweden, or representative in Sweden.
- Sector and any subsector, and whether you carry on that activity elsewhere in the EU or EEA.
- How you identified yourself as an operator, and whether you are essential or important.
- Internet identifiers — IP addresses and domain names.
- Contact details for the person making the notification.
Incident reporting
Significant incidents go to the CSIRT unit at FRA. The clock starts when you become aware of the incident.
| Stage | Deadline | What it is |
|---|---|---|
| Early notice | 24 hours | Inform the authority as soon as possible, and at the latest 24 hours after becoming aware. |
| Incident notification | 72 hours 24 hours for trust service providers |
The formal notification of the significant incident. |
| Interim report | On request | Relevant status updates, where the authority asks for them. |
| Final report | 1 month after the notification | If the incident is still ongoing, a status report is due instead, and the final report one month after it has been handled. |
What counts as a significant incident
Chapter 2, Section 5 defines it: an incident that has caused or may cause serious operational disruption to the service, or economic damage to the operator, or that has affected or may affect other natural or legal persons by causing significant damage. Any one of the three is enough.
- Tell your customers where it is appropriate — for incidents likely to affect service delivery, and for significant cyber threats, where you must also describe the protective measures they can take.
- Domain registries have a separate 72-hour clock. Top-level domain registries and domain name registration services must answer a lawful, reasoned request for registration data within 72 hours. This does not apply to the .se domain administrator, which follows its own act.
NIS2 timeline & key dates (Sweden)
Sector-specific notes (Sweden)
- Energy: electricity, district heating and cooling, oil, gas, hydrogen and charging infrastructure, supervised by Statens energimyndighet.
- Public administration: municipalities, regions and municipal associations are in scope regardless of size, and every state agency in scope is an essential entity. Supervision runs through the county administrative boards, not through a national regulator.
- Health: supervision is split. IVO takes care providers; Läkemedelsverket takes the rest of the sector and medical device manufacturing.
- Water and food: drinking water, waste water and the food chain all sit with Livsmedelsverket — one authority for what elsewhere is often three.
- Digital infrastructure and ICT services: cloud, data centres, content delivery networks, managed services and managed security services, supervised by PTS. Public electronic communications providers are in scope regardless of size, and are the only group that pays fees — a charge for processing the registration and an annual supervisory fee.
- Education and research: Sweden names private degree-awarding education providers in the Act itself, and research is its own sector. Both are supervised by the county boards.
- Supply chain: suppliers outside scope can still face contractual security requirements from covered operators, since supply-chain security is one of the ten mandatory measures.
How Sweden differs
Six things here do not carry across from other member states.
- The whole entity is covered, regardless of size, if it is public. Municipalities, regions and municipal associations are in scope whatever their size, and every state agency in scope is automatically an essential entity. Most member states apply the size test to public bodies too.
- Group figures count. Sweden requires you to include partner and linked enterprises when measuring size. Bulgaria switches that aggregation off entirely, and Germany relieves it where the entity is IT-independent. The same group can be in scope in Stockholm and out in Sofia.
- There is no registration deadline in the statute — only “as soon as possible”, with a 14-day enforcement expectation published by the authority. Germany and Luxembourg both set hard dates.
- Fines have a floor of SEK 5,000 and public bodies have their own flat ceiling of SEK 10 million rather than a turnover percentage.
- Supervision is regionalised. Six county administrative boards supervise the public sector and several manufacturing sectors, split geographically. No other member state we cover devolves NIS2 supervision to regional government.
- A management ban is a court decision, not a regulator's. The supervisory authority must apply to an administrative court, and the ban runs for one to three years.
Swedish terms you will meet
| Swedish | English | What it is |
|---|---|---|
| Cybersäkerhetslagen | the Cybersecurity Act | SFS 2025:1506. The law itself. |
| Cybersäkerhetsförordningen | the Cybersecurity Ordinance | SFS 2025:1507. Names who supervises what. |
| verksamhetsutövare | operator | The term for anyone in scope. |
| väsentlig / viktig | essential / important | The two categories. |
| anmälan | notification | The registration you must file. |
| betydande incident | significant incident | The trigger for the 24-hour clock. |
| tillsynsmyndighet | supervisory authority | Thirteen of them. |
| sanktionsavgift | sanction fee | The administrative fine. |
| vite | penalty payment | A conditional fine attached to an order. Cannot be combined with a sanction fee for the same breach. |
| föreläggande | order / injunction | What a supervisor issues to force compliance. |
| länsstyrelse | county administrative board | Regional supervisor for the public sector and several manufacturing sectors. |
| NCSC / FRA | National Cyber Security Centre / National Defence Radio Establishment | Where registrations and incident reports go. |
Penalties for non-compliance
Chapter 4 sets the sanctions. Sweden took the maximum levels the Directive allows, and added a floor the Directive does not require.
| Who | Sanction fee (sanktionsavgift) |
|---|---|
| Private essential operator | The higher of 2% of total global annual turnover or an amount in kronor corresponding to EUR 10,000,000 |
| Private important operator | The higher of 1.4% of total global annual turnover or an amount in kronor corresponding to EUR 7,000,000 |
| Public operator | A flat SEK 10,000,000 — no turnover percentage applies |
| All of the above | Minimum SEK 5,000 in every case |
- A fine and a penalty payment are alternatives, not both. No sanction fee may be imposed where the same breach underlies an application to enforce a vite.
- Two-year limitation. A fee can only be imposed if you were given the chance to respond within two years of the infringement. Payment falls due 30 days after the decision takes legal effect, and an unenforced decision lapses after five years.
- Intervention is mandatory, not discretionary. Where an operator has failed its duties the authority shall intervene — by order, by applying for a management ban, by a sanction fee, or at minimum by a formal remark.
- What makes a breach “serious”: repeated infringements, failing to report or inform, failing to remedy a significant incident, ignoring an order, obstructing supervision, or giving false or grossly incorrect information.
Orders, publication and the management ban
Supervisors can order you to comply, and can order you to publish information about your own infringement. Orders may carry a vite, and may be directed at the state itself. They can require documents, enter premises other than dwellings, run security audits, and carry out security scans — those in cooperation with you. If you obstruct them they can call on the enforcement authority, Kronofogdemyndigheten.
For essential operators only, an administrative court may bar an individual from holding a management function for one to three years. It applies where an earlier order went unmet, the underlying breach was serious, and the person caused it intentionally or through gross negligence. The supervisory authority applies; the court decides and must handle the case promptly. Decisions under the Act are appealed to the administrative courts.
How to prepare for NIS2 in Sweden
- Run the three tests and write down the answer: type of activity, size (counting partner and linked companies), jurisdiction. Because Sweden runs on self-assessment, your reasoning is your evidence — the registration form asks how you identified yourself.
- Identify your supervisor: by sector from the table in Competent authorities — and if you are a public body or a manufacturer supervised by a county board, by the county where you are registered.
- Perform a gap analysis: compare current controls against NIS2 requirements (governance, risk management, incident handling, business continuity, supply-chain security, training, etc.).
- Strengthen governance: ensure the board and executive management understand their NIS2 responsibilities, receive training, and have regular reporting on cyber risks and compliance status.
- Update policies and technical measures: align your ISMS (e.g. ISO 27001) with NIS2, covering both IT and OT environments and the full lifecycle of systems.
- Register, if you have not: the portal has been open since 2 February 2026 and notifications go to NCSC at FRA. Have your organisation number, sectors and subsectors, IP addresses and domain names, and your essential-or-important determination ready.
- Rehearse the 24-hour clock: agree in advance who decides an incident is betydande, and make sure early notice can reach the CSIRT unit at FRA within 24 hours of awareness — at any hour, on any day.
- Document and evidence: keep records of risk assessments, security measures, exercises, supplier reviews and training. Essential operators face regular security audits, so this is what a supervisor will ask to see.
Operating in more than one EU country
NIS2 is one Directive and 27 national laws. Sweden is one of the stricter readings, and several of its rules will not match what you built elsewhere.
- Four jurisdiction rules. The general rule is the country where you are established. By exception: where you provide the service, where your main establishment is, or — for public administration entities — the member state that set them up.
- Digital providers are governed from their main establishment. Cloud, data centre, CDN, managed service, managed security, marketplace, search and social network providers answer to one member state, not to each country they serve. In Sweden, that means PTS.
- Size tests are not portable. Sweden counts partner and linked companies; Bulgaria does not; Germany relieves aggregation only where the entity is IT-independent.
- Registration mechanics differ more than the duties do. Sweden identifies nobody and expects you to file; Bulgaria compiles the register itself and never publishes it; Germany and Luxembourg set hard deadlines.
- Reporting clocks travel well. The 24-hour, 72-hour and one-month chain is broadly consistent, including Sweden's 24-hour rule for trust service providers.
- Sector law can displace the general regime. DORA entities are exempt from the Swedish security and reporting duties, and any equivalent sector law has the same effect.
Official links & resources
FAQ: NIS2 in Sweden
When did the Cybersecurity Act enter into force in Sweden?
Who is the main authority — MSB, MCF or FRA?
How do we know if we are covered?
Where do we register, and by when?
Does the Act apply to municipalities and regions?
Are we required to certify against ISO 27001?
Are web agencies and digital service providers in scope?
Which county administrative board supervises us?
- Norrbotten — Jämtland, Norrbotten, Västerbotten, Västernorrland
- Skåne — Blekinge, Kronoberg, Skåne
- Stockholm — Gotland, Stockholm
- Västra Götaland — Halland, Västra Götaland
- Örebro — Dalarna, Gävleborg, Södermanland, Uppsala, Värmland, Västmanland, Örebro
- Östergötland — Jönköping, Kalmar, Östergötland
Sources & verification
Every date, figure and authority on this page was read out of the Swedish statutory text or the responsible authority's own guidance on 3 August 2026. Public NIS2 trackers contradict each other and are not used here.
- Cybersäkerhetslag (2025:1506) — scope, registration, the ten security measures, the reporting chain, supervision and the sanction scale.
- Cybersäkerhetsförordning (2025:1507), as amended by förordning (2026:623) — where registrations and incident reports go, and the full list of supervisory authorities with the county split.
- NCSC guidance on the Act, on scope assessment and on registration — the 2 February portal opening, the 14-day enforcement position, the self-assessment rule and the contents of the form.
- MCFFS 2026:1 — the regulation on notification and identification.
