Part I · Chapter 5

The Swedish cybersecurity ecosystem

MCF, NCSC and CERT-SE are names often mentioned in the same breath while doing different things. This chapter sorts out the roles in the Swedish cybersecurity ecosystem, which authorities are responsible for what, which of them supervise the Cybersecurity Act, and above all where an organisation actually turns once an incident is a fact and the clock is running.

  • CISOs and security leads
  • Boards and leadership teams

Last reviewed

Sweden has built a cybersecurity ecosystem with many actors and clear mandates. The problem for the individual organisation is rarely that support is missing, but that it is hard to know where it sits when it is needed. The names resemble one another, the abbreviations overlap, and several of the actors have changed name or mandate in recent years. An incident in progress is not the moment to work out the difference.

The chapter goes through the actors one by one. The Swedish Civil Defence Agency and its role in civil defence and information security, including its power to issue regulations and its methodological support. The National Cybersecurity Centre as the hub for cooperation between public authorities and industry. CERT-SE as the operational function during incidents, the point of contact most organisations will actually use. The National Defence Radio Establishment with its signals intelligence mandate and technical capability. The Security Service within protective security and counter espionage. The Agency for Psychological Defence for information influence, an area taken further in chapter 26. After that come the supervisory authorities, who reviews compliance with the Cybersecurity Act in each sector, a question with different answers depending on the operation in question. The closing sections summarise the ecosystem as a whole, answer where to turn in different situations, and describe how the structure is still changing. How the civil ecosystem meets the military one is covered in chapter 6 on cyber defence.

The question has become more pressing for two reasons. The reporting duty under the Cybersecurity Act assumes the organisation knows who should receive the report and within what time, and that knowledge has to be written down somewhere other than in one person's head. On top of that, the division of responsibility between authorities was adjusted during 2026, which means older procedure documents may point at a recipient that no longer holds the mandate. The organisation with contact routes written down and tested wins the first few hours, and those are the hours that decide how the incident develops.

This page shows what the chapter covers and why the division of roles is worth knowing in advance. The mandates in detail and the practical contact routes are in chapter 5 of the book.

You do not need to know every actor. You only need to know where to turn when it counts.

Key insights

  • The roles are divided by function. Regulation, operational support, intelligence and supervision do not sit with the same body.
  • CERT-SE is the operational point of contact during incidents, while supervision sits with the sector authorities.
  • The ecosystem is being rebuilt, and responsibilities shifted during 2026.
  • The contact routes need to be known before they are needed. Hunting for them mid incident costs hours you do not have.

Tools that belong to this chapter

The templates and interactive tools are in the Toolbox, free of charge.

Read on

Next step

Where does your organisation stand?

The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.