Sweden NIS2 Transposition (Cybersäkerhetslagen)
Swedish Cybersecurity Act transposing NIS2 with sector supervisory authorities coordinated by MSB.
| Jurisdiction | Sweden |
|---|---|
| Category | Cybersecurity |
| Status | Active |
| Effective date | |
| Latest development |
Analysis
Sweden has implemented NIS2 through the Cybersäkerhetslagen (SFS 2025:1506) and Cybersäkerhetsförordningen (SFS 2025:1507), in force since 15 January 2026, with sectoral supervisory authorities coordinated by MSB/NCSC as national hub and CSIRT.Regeringen pressmeddelande 12 June 2025Regeringen pressmeddelande 15 December 2025LRR proposition “Ett starkt skydd för nätverks- och informationssystem – en ny cybersäkerhetslag”Cybersäkerhetslagen på NCSC/MSB
Key Requirements
Below are the main obligations under Cybersäkerhetslagen (SFS 2025:1506) transposing NIS2 in Sweden.
1. Scope and Entity Categorisation (Essential / Important entities)
- NIS2 is implemented in Sweden through Cybersäkerhetslagen (2025:1506) and Cybersäkerhetsförordningen (2025:1507), which together replace the previous NIS‑lagen (2018:1174).
- Lagar och förordningar gällande cybersäkerhetslagen – MCF
- Regeringen – “Regeringen utfärdar en ny cybersäkerhetslag”
- Transportstyrelsen – Cybersäkerhet (NIS2)
- The law applies to both public and private “verksamhetsutövare” (operators) in defined sectors and subsectors aligned with NIS2’s Annexes (e.g. energy, transport, health, digital infrastructure, public administration).
- Regeringen proposition – “Ett starkt skydd för nätverks- och informationssystem – en ny cybersäkerhetslag” (PDF)
- EU – NIS2 Directive
- NCSC – “Det här är cybersäkerhetslagen”
- Entities are categorised as “väsentliga” (essential) and “viktiga” (important), mirroring NIS2 classification and driving the level of supervision and possible sanctions.
- EU – NIS2 Directive, Art. 3–4
- NCSC – Cybersäkerhetslagen overview
- BGINSTITUTE – Guide till cybersäkerhetslagen
2. Registration / Notification Duties
- Covered entities must register/notify their activities to the designated supervisory authority under Cybersäkerhetslagen.
- NCSC – “Tidsplan för införandet av cybersäkerhetslagen i Sverige”
- EU – NIS2 Directive, Art. 26 (registries of entities)
- CGI – “NIS2 och cybersäkerhetslagen: Det gäller för din verksamhet”
- Registration is linked to the obligation to provide certain data about the entity, sector, services and contact points, which feeds national and EU‑level registers.
- EU – NIS2 Directive, Art. 26–29
- Regeringen proposition – Cybersäkerhetslagen (PDF)
- Cyberklar – NIS2 i Sverige: Cybersäkerhetslagen SFS 2025:1506
3. Risk Management and Security Measures
- Entities must implement “lämpliga och proportionerliga” (appropriate and proportionate) risk management and technical/organizational security measures for their network and information systems, aligned with NIS2 Article 21.
- Regeringen proposition – Cybersäkerhetslagen (PDF)
- EU – NIS2 Directive, Art. 21
- RISE – “NIS2 är här – är din organisation redo?”
- These measures include policies on risk analysis and information system security, incident handling, business continuity, backup, supply‑chain security, secure development, vulnerability handling and cryptography.
- EU – NIS2 Directive, Art. 21(2)
- NCSC – Cybersäkerhetslagen guidance
- Laglig.se – NIS2 krav och svenska cybersäkerhetslagen
4. Governance, Management Accountability and Cyberculture
- Cybersäkerhetslagen imposes management‑level responsibility: ledningen must approve cyber risk management measures, oversee implementation and can be held personally liable for non‑compliance, reflecting NIS2 governance rules.
- EU – NIS2 Directive, Art. 20
- Regeringen proposition – Cybersäkerhetslagen (PDF)
- Cyberday – “Vad är Cybersäkerhetslagen?”
- Management must ensure regular training and awareness for relevant staff and may be subject to sanctions or disqualification in cases of serious negligence.
- EU – NIS2 Directive, Art. 20–31
- BGINSTITUTE – Guide till cybersäkerhetslagen
- RISE – NIS2 readiness article
5. Incident Reporting Obligations
- Entities must report “betydande incidenter” (significant incidents) to the national CSIRT/NCSC and relevant supervisory authority within strict timelines (initial notification within 24 hours is widely referenced in guidance), in line with NIS2 Articles 23–24.
- Regeringen proposition – Cybersäkerhetslagen (PDF)
- EU – NIS2 Directive, Art. 23–24
- CGI – NIS2 och cybersäkerhetslagen (incidentrapportering 24 h)
- Reporting is made via a national “cyberportal” to NCSC/MSB, which acts as CSIRT and national single point of contact.
- Digital Strategy – NIS2 implementation in Sweden (MSB contact data)
- Cyberklar – Cybersäkerhetslagen (rapportering via cyberportalen)
- SOU 2024:18 – “Nya regler om cybersäkerhet” (MSB as CSIRT and national contact point)
6. Supervision and Enforcement
- Sector‑specific supervisory authorities (e.g. Transportstyrelsen for transport, PTS for electronic communications, Socialstyrelsen for health, etc.) carry out supervision under Cybersäkerhetslagen, coordinated by MSB/NCSC.
- Transportstyrelsen – Cybersäkerhet (NIS2)
- SOU 2024:18 – Nya regler om cybersäkerhet
- Regeringen pressmeddelande – Ny cybersäkerhetslag
- The law introduces significant administrative fines; guidance refers to maximum sanctions of up to 10 million EUR or 2% of global turnover for serious breaches, reflecting NIS2.
- EU – NIS2 Directive, Art. 34
- CGI – NIS2 och cybersäkerhetslagen (sanktionsnivåer)
- Laglig.se – NIS2 — krav, omfattning och svenska cybersäkerhetslagen
7. Interaction with Other Laws (e.g. Secrecy, Electronic Communications, TLDs)
- Cybersäkerhetslagen is accompanied by amendments to laws on electronic communication, top‑level domains and secrecy to align incident reporting and information‑sharing duties.
- Regeringen pressmeddelande – Ny cybersäkerhetslag (ändringar i lagar om elektronisk kommunikation, toppdomäner och sekretess)
- SOU 2024:18 – Nya regler om cybersäkerhet
- EU – NIS2 Directive preamble and sector references
Compliance Challenges
1. Identifying Scope and Entity Status
- Challenge: determining whether an organization is in scope as an essential or important entity and mapping relevant services and sectors.
- NCSC – “Det här är cybersäkerhetslagen”
- BGINSTITUTE – NIS2 i Sverige – Guide till cybersäkerhetslagen
- Laglig.se – NIS2 — krav, omfattning och svenska cybersäkerhetslagen
- Real‑world guidance shows many organizations unsure whether they meet NIS2 size thresholds or criticality criteria, especially in digital services and manufacturing.
- RISE – NIS2 readiness article
- Cyberday – Introduction to Cybersäkerhetslagen
- EU – NIS2 Directive, Annex I–II
2. Integrating NIS2 Requirements into Existing Frameworks
- Organizations often struggle to integrate NIS2‑driven requirements with existing ISO 27001, IT‑security policies and GDPR controls without duplication or gaps.
- RISE – NIS2 är här – är din organisation redo?
- NCSC – Cybersäkerhetslagen guidance pages
- Cyberklar – NIS2 i Sverige: Cybersäkerhetslagen SFS 2025:1506
- Case‑study style industry guides note difficulties in defining risk management processes that meet NIS2 Article 21 while remaining practical for SMEs.
- [BGINSTITUTE – Guide till cybersäkerhetslagen](https://www.bginstitute
Recent developments
- — RISE highlights that Sweden’s new **Cybersäkerhetslagen** implementing NIS2 has applied since 2026-01-15, replacing the previous NIS law, and stresses that organizations must now meet stricter governance, risk management and incident-reporting requirements, prompting extensive readiness work across critical sectors.[6][3] (source)
- — The Swedish National Cybersecurity Center (NCSC) explains that NIS2 is implemented through **Cybersäkerhetslagen (SFS 2025:1506)**, in force since 2026-01-15, outlining scope, obligations and supervision, and positioning the law as the core framework for cybersecurity for essential and important entities in Sweden.[1][10] (source)
- — NCSC describes how NIS2 regulation is structured in Sweden under **Cybersäkerhetslagen**, including which sectors and entities are covered and their duties, and notes an institutional change where cyber responsibilities moved from Myndigheten för civilt försvar (MCF) to NCSC at FRA on 2026-07-01, affecting oversight and support.[12][10] (source)
- — The Swedish Transport Agency explains that NIS2 is transposed via **Cybersäkerhetslagen (2025:1506)**, effective from 2026-01-15, replacing the 2018 NIS law and imposing higher cybersecurity requirements and reporting duties on transport-related essential services, signaling sector-specific operational impacts.[11][3] (source)
- — An international NIS2-focused overview reports that Sweden has transposed NIS2 through the **Cybersecurity Act (Cybersäkerhetslagen, SFS 2025:1506)**, issued 2025-12-11 and in force since 2026-01-15, summarizing key obligations (risk management, incident reporting, governance) and emphasizing that hundreds to thousands of Swedish entities are now directly in scope.[2][3] (source)
- — MCF announces that the general requirements in **Cybersäkerhetslagen** will be complemented by detailed **binding security measures regulations** to be published in June 2026 and entering into force on 2026-10-01, clarifying concrete technical and organizational controls that covered entities must implement, which is expected to intensify compliance work in affected industries.[14][10] (source)
- — A detailed industry analysis estimates that around **6,000 Swedish companies** fall under **Cybersäkerhetslagen (SFS 2025:1506)**, describing significantly tougher NIS2-based requirements, tight registration deadlines in February 2026, and substantial impacts on mid-sized firms that now face enterprise-grade cybersecurity, governance, and reporting obligations.[3] (source)
- — A legal-tech explainer outlines that **Cybersäkerhetslagen (2025:1506)**, in force from 2026-01-15, is Sweden’s NIS2 law replacing the 2018 NIS framework, and clarifies that it applies to state authorities, regions, municipalities and NIS2-listed sectors meeting at least medium-sized company thresholds, underscoring the broadened regulatory perimeter and compliance burden.[8][10] (source)
- — A consultancy “complete guide” for Swedish companies notes that **Cybersäkerhetslagen** and the accompanying **cybersäkerhetsförordning** entered into force on 2026-01-15, applying to entities with ≥50 employees or >€10m turnover across 18 sectors, and highlights extensive practical impacts including mandatory registration with MCF, 24-hour incident reporting, systematic risk management and management training, prompting significant compliance projects.[5][10] (source)
- — A Swedish training and advisory guide explains that the new **Cybersäkerhetslagen (2025:1506)**, effective 2026-01-15, is the central NIS2 implementation instrument in Sweden and details governance, risk management, incident reporting and board-level accountability requirements, indicating strong demand for education and consultancy in the cybersecurity industry.[9][5] (source)
Related regulations
- NYDFS Cybersecurity Regulation — New York, Active, effective 2025-11-01
- Law on Cybersecurity of Vietnam — Vietnam, Active
- Austria NIS2 Act — Austria, Upcoming
- Luxembourg NIS2 Transposition — Luxembourg, Active
- EU Cyber Resilience Act (CRA) — European Union, Phased, effective 2027-12-11
- EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026) — European Union, Active, effective 2026-09-11
- Netherlands NIS2 Transposition (Cyberbeveiligingswet) — Netherlands, Active, effective 2026-08-15
- Belgium NIS2 Transposition — Belgium, Active, effective 2024-10-18
Put it into practice
- Generate the policy: NIS2 policy generator (generatepolicy.com)
- Buy the policy pack: NIS2 Compliance Policy (cyberpolicy.shop)
- Build it yourself: DORA + NIS2 EU Compliance Workbook (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates