NIS2 and the Swedish Cybersecurity Act
What the EU's NIS2 directive actually means in Sweden - and what the Swedish Cybersecurity Act requires of you.
The NIS2 directive vs. the Cybersecurity Act
NIS2 (EU 2022/2555) is the EU's revised cybersecurity directive. An EU directive doesn't automatically become national law - each member state has to implement it through its own legislation. In Sweden that law is called the Cybersecurity Act, and it came into force on 15 January 2026.
Who is the supervisory authority?
Responsibility has moved: the Cybersecurity Act was originally administered by the Swedish Civil Contingencies Agency (MSB), which was reorganised into the Agency for Civil Defence (MCF). Since 1 July 2026, national cybersecurity responsibility sits with the National Cybersecurity Center (NCSC), part of the National Defence Radio Establishment (FRA). Some sectors have their own supervisory authorities, e.g. the Swedish Post and Telecom Authority (PTS) for telecom and the Swedish Transport Agency for transport.
Which sectors are covered?
The law divides organisations into essential and important sectors - including energy, transport, banking and finance, healthcare, drinking water, digital infrastructure, public administration, space, postal and courier services, waste management, chemicals, food, and certain manufacturing. Generally, medium and large organisations are covered (50+ employees or €10M+ in revenue), but smaller suppliers can be covered indirectly through requirements from their customers in the supply chain.
What does the law require?
Risk-management measures for network and information security, incident reporting within three deadlines (early warning within 24 hours, formal notification within 72 hours, a final report within one month), supply chain security, business continuity planning, and regular training for staff and management.
Who is responsible?
Ultimate responsibility lies with management and the board. They must approve the risk-management measures and undergo training, and can be held personally liable for gross negligence. The day-to-day work should be delegated and documented internally.
This page is a general summary, not legal advice. Contact us or a lawyer for an assessment of your specific situation.