NIS2 vs. the old NIS law - what's new?

Already had routines under the old NIS law? A good foundation - but not enough on its own.

The Cybersecurity Act (NIS2) replaced, on 15 January 2026, the earlier law (2018:1174) on information security for essential and digital services - commonly known as the "NIS law". The framework was rebuilt from the ground up after the EU found that application varied widely between member states and that the requirements were too vague.

What's new?

Why aren't the old routines enough?

More requirements (supply chain, documented management training, stricter deadlines), a partly new set of covered organisations, and a registration process rebuilt from scratch under a new authority (NCSC). A registration made under the old NIS law doesn't automatically count as a registration under the Cybersecurity Act - check that your organisation is registered under the new rules, even if you already did things right before.

This page is a general summary, not legal advice. Contact us or a lawyer for an assessment of your specific situation.

Take the self-testSee the NIS2 checklist