NIS2 vs. the old NIS law - what's new?
Already had routines under the old NIS law? A good foundation - but not enough on its own.
The Cybersecurity Act (NIS2) replaced, on 15 January 2026, the earlier law (2018:1174) on information security for essential and digital services - commonly known as the "NIS law". The framework was rebuilt from the ground up after the EU found that application varied widely between member states and that the requirements were too vague.
What's new?
More sectors
Expanded from 7 to 18 sectors. Many organisations that were never covered by the NIS law - such as manufacturing, food, postal and courier services, public administration - are now in scope.
Essential or important, no longer the authority's discretion
Under the NIS law, authorities designated which "providers of essential services" were in scope, case by case. The Cybersecurity Act instead relies on clear size thresholds (medium/large) within the 18 sectors - far more organisations fall automatically within the law's scope.
Explicit management liability
The Cybersecurity Act makes clear that the board must approve the risk-management measures and undergo training, and can be held personally liable for gross negligence - something that wasn't as explicit under the NIS law.
Explicit supply chain security
The NIS law focused on your own operations. The Cybersecurity Act explicitly requires you to also keep track of whether your suppliers and subcontractors maintain a reasonable security level.
Stricter, more harmonised incident deadlines
Three hard deadlines - early warning within 24 hours, formal notification within 72 hours, a final report within one month - replace vaguer national requirements.
Significantly higher sanctions
Sanctions are now tied to global revenue, similar to GDPR's model, instead of smaller fixed amounts - and supervision is more active, especially for essential entities.
Why aren't the old routines enough?
More requirements (supply chain, documented management training, stricter deadlines), a partly new set of covered organisations, and a registration process rebuilt from scratch under a new authority (NCSC). A registration made under the old NIS law doesn't automatically count as a registration under the Cybersecurity Act - check that your organisation is registered under the new rules, even if you already did things right before.
This page is a general summary, not legal advice. Contact us or a lawyer for an assessment of your specific situation.