Part I · Chapter 3

The regulatory map

The Cybersecurity Act and NIS2, what actually applies to your organisation? The question is harder than it sounds, because the rules overlap and one and the same operation is often caught by several at once. This chapter draws the map of the base layer, GDPR, the Protective Security Act, DORA, the Cybersecurity Act and the regulations issued for central government agencies, and shows how they relate to each other.

  • CISOs and security leads
  • Boards and leadership teams

Last reviewed

The most common question from a leadership team is not what the law requires. It is whether the law applies to us. And that question surprisingly often gets three different answers inside the same organisation, depending on who is asked. The lawyer answers from the legal form of the company, the head of operations from what the organisation does, and the IT manager from which systems exist. None of them is wrong, and none has the whole answer.

The chapter opens with the regulatory explosion, why the number of rules has grown so quickly and what that does to an organisation's ability to see its own position. Then follows the Cybersecurity Act in detail. The background and the link to the NIS2 directive, who is covered as an essential or important entity, what the law actually requires of those who are, what responsibility is placed on the leadership and what that responsibility means in practice. After that come the 24 and 72 hour reporting duties, the supervisory structure with its various sector authorities, and the state of the regulations, which is still being built out. Then the rules that apply in parallel. The Protective Security Act and its relationship to the Cybersecurity Act, including the question of security protection agreements in the supplier chain. GDPR and the overlap that arises when an incident is both a cyber incident and a personal data breach. DORA as special legislation for the financial sector, and the regulations for central government agencies. Product regulation and the AI Act sit in chapter 4, which continues the map.

The question is pressing for a simple reason. The law entered into force on 15 January 2026 and supervision has begun. At the same time the structure of the detailed regulations is still changing, which means anyone waiting for full clarity before starting risks waiting too long. What does stand firm is the direction, systematic work with documented leadership responsibility. Whoever builds that will not have to rebuild it when the regulations are made precise. Knowing which rules apply is also a precondition for judging which ones do not, which saves at least as much work.

This page shows what the chapter covers and why the map is needed before the work is planned. The boundaries, the exemptions and the supervisory structure in detail are in chapter 3 of the book.

They reach different parts of the operation, but the requirements run in the same direction.

Key insights

  • The Swedish Cybersecurity Act (2025:1506) names the leadership as responsible. That responsibility cannot be delegated away, only distributed.
  • Whether you are covered is decided by sector and size, not by how digital the operation feels itself to be.
  • Incident reporting follows a two-step model, with early warning within 24 hours and a full report within 72 hours.
  • DORA is special legislation for the financial sector and takes precedence over the Cybersecurity Act where both could apply.
  • The overlap is an opportunity. Systematic work answers to several sets of rules at once.

Tools that belong to this chapter

The templates and interactive tools are in the Toolbox, free of charge.

Read on

Next step

Where does your organisation stand?

The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.