The Swedish Cybersecurity Act
What the Cybersecurity Act requires
The Cybersecurity Act is the Swedish law implementing the EU NIS 2 directive. It entered into force on 15 January 2026 and requires systematic cybersecurity work across ten requirement areas, from risk management and incident response to supply chain security.
Who is covered
The law covers operations in 18 sectors, both private and public. Entities are divided into essential and important, and those covered have to register with the supervisory authority. If you are unsure whether you are affected, the regulation navigator works through eight questions and shows which rules are likely to apply to you.
The ten requirement areas
The requirements are framed as areas to work within systematically, not as a checklist to tick off once. These are the ten:
- Risk analysis and security policies
- Incident handling
- Business continuity
- Supply chain security
- Security in acquisition, development and maintenance
- Assessing the effectiveness of measures
- Cyber hygiene and training
- Cryptography and encryption
- Personnel security and access control
- Multi-factor authentication and secure communication
The self-assessment works through one requirement area at a time and gives a maturity profile per area. It takes around twenty minutes, is calculated in your browser and serves as a picture of where you stand ahead of a leadership or board review.
What the leadership answers for
The leadership has to approve the risk management, follow up that it is carried out, and undergo cybersecurity training itself. The law makes this the responsibility of the leadership, and serious shortcomings can lead to an administrative fine. The responsibility therefore cannot be delegated away to the IT function.
Reporting a serious incident
The reporting duty runs in stages, from early warning to final report. The Toolbox contains ready made templates for both the early warning within 24 hours and the report within 72 hours, along with a risk register and an information security policy.
The Cybersecurity Act and ISO 27001
ISO 27001 is an international standard for information security management systems. It is not mandatory, but it is an established way of structuring the work so that the requirement areas of the law are covered. The control mapping shows which controls in the standard answer to which requirement area.
How the law relates to other regulation
The Cyber Resilience Act (CRA) is an EU regulation setting cybersecurity requirements on products with digital elements, with full application from December 2027. The Cybersecurity Act is aimed instead at operations and their security work. Many organisations are affected by both: the law for the operation, the CRA for the products. Terms and acronyms are sorted out in the glossary.
Primary sources:
- The Cybersecurity Act (SFS 2025:1506) at the Swedish Riksdag
- The NIS 2 directive at EUR-Lex
- MCF regulations and incident reporting
Take the free self-assessment against the ten requirement areas