The Swedish Cybersecurity Act

What the Cybersecurity Act requires

The Cybersecurity Act is the Swedish law implementing the EU NIS 2 directive. It entered into force on 15 January 2026 and requires systematic cybersecurity work across ten requirement areas, from risk management and incident response to supply chain security.

From NIS to NIS 2

NIS 2 replaces the first NIS directive. It tightens the requirements and widens the number of sectors covered, but the biggest change is where responsibility lands. The directive names the leadership as answerable for risk management, with a training duty of its own and the possibility of an administrative fine where there are shortcomings. For operations already working under the first directive, the shift is therefore less about new technical measures and more about governance, follow up and documented ownership. In Swedish law the directive arrives as the Cybersecurity Act, SFS 2025:1506.

Who is covered

The law covers operations in 18 sectors, both private and public. Entities are divided into essential and important, and those covered have to notify the Swedish Authority for Civil Defence. The division does not decide which requirement areas apply, since the law is the same for both, but how supervision is arranged. Essential entities are supervised on an ongoing basis, while important ones are examined only once the supervisory authority has reason to believe the requirements are not being met. Because the classification follows from sector and size, it reaches many operations that do not think of themselves as critical. If you are unsure whether you are affected, the regulation navigator works through eight questions and shows which rules are likely to apply to you.

The ten requirement areas

The requirements are framed as areas to work within systematically, not as a checklist to tick off once. These are the ten:

  1. Risk analysis and security policies. A recurring risk assessment, owned by leadership, that governs which measures you prioritise.
  2. Incident handling. Procedures for early warning and incident notification to NCSC, plus internal handling.
  3. Business continuity. The ability to keep operating and to recover when something serious happens.
  4. Supply chain security. The security of those you depend on, not just your own organisation.
  5. Security in acquisition, development and maintenance. Security built in throughout the life cycle, not bolted on afterwards.
  6. Assessing the effectiveness of measures. Reviews, tests and follow-up showing that the protection holds over time.
  7. Cyber hygiene and training. Everyday routines and knowledge that make the whole organisation a stronger link.
  8. Cryptography and encryption. Protecting sensitive information with encryption where it is needed.
  9. Personnel security and access control. The right person has the right access, and only the access that is needed.
  10. Multi-factor authentication and secure communication. Stronger sign-in and protected communication channels.

The self-assessment works through one requirement area at a time and gives a maturity profile per area. It takes around twenty minutes, is calculated in your browser and serves as a picture of where you stand ahead of a leadership or board review.

What the leadership answers for

The leadership has to approve the risk management, follow up that it is carried out, and undergo cybersecurity training itself. The law makes this the responsibility of the leadership, and serious shortcomings can lead to an administrative fine. The responsibility therefore cannot be delegated away to the IT function. In practice this means the board and the leadership need to be able to ask the right questions and read the answers, not take the technical decisions. That in turn requires reporting that describes risk in business terms, and a meeting structure where cybersecurity recurs rather than surfacing only after an incident.

Reporting a serious incident

The reporting duty runs in three stages. The early warning is submitted within 24 hours, the incident notification within 72 hours and the final report within one month. The deadlines are short enough that the outcome is settled in practice by the preparation, meaning who is allowed to decide that an event is reportable, where the contact routes are kept and who does the writing. The Toolbox contains ready made templates for both the early warning and the 72 hour report, along with a risk register and an information security policy.

Who supervises

Supervision is arranged by sector. The Cybersecurity Ordinance (2025:1507) names, among others, the Swedish Energy Agency for energy, the Transport Agency for transport, Finansinspektionen for banking and financial market infrastructure, the Post and Telecom Authority for digital infrastructure and the Food Agency for drinking water and food, while six county administrative boards share public administration and parts of manufacturing. Notification, by contrast, goes centrally to the Swedish Authority for Civil Defence, MCF, known until 2026 as the Swedish Civil Contingencies Agency, which issues regulations in its own code, MCFFS. Incident reports go to a third address, the National Cyber Security Centre, NCSC, which is the CSIRT unit and part of FRA. They are filed in the Cyber Portal. Three different authorities for three different things is the most common source of confusion about the law.

What happens where there are shortcomings

Serious shortcomings can lead the supervisory authority to decide on an administrative fine. The fine is directed at the entity, but because the law places responsibility for risk management with the leadership, it is the leadership work that is examined when something has gone wrong. That gives documentation a weight it did not have before, because what cannot be shown afterwards does not count in practice. Traceable decisions, approved risk analyses and completed training are therefore both compliance and protection on the day supervision arrives.

The Cybersecurity Act and ISO 27001

ISO 27001 is an international standard for information security management systems. It is not mandatory, and certification is not in itself proof that the law is met, but the standard is an established way of structuring the work so that the requirement areas of the law are covered. The overlap is large without being complete. The standard is broader on governance and documentation, while the law is clearer on reporting and on the leadership answering personally. The control mapping shows which controls in the standard answer to which requirement area, and where the gaps sit.

How the law relates to other regulation

The Cyber Resilience Act (CRA) is an EU regulation setting cybersecurity requirements on products with digital elements, with full application from December 2027. The Cybersecurity Act is aimed instead at operations and their security work. Many organisations are affected by both: the law for the operation, the CRA for the products. Terms and acronyms are sorted out in the glossary.

Where the work starts

The law describes what has to be in place, not how you get there. Most operations begin with a picture of where they stand, meaning which requirement areas are already covered, which are under way and which are missing entirely. From there the prioritisation becomes a leadership question rather than a technical one. Digital resilience is not built by a project but by work that holds over time, and the law is the starting point for that work, not the goal. The book works through the path from requirement area to systematic security work, part by part.

Primary sources:

Take the free self-assessment against the ten requirement areas