Glossary · NIS2
Cybersäkerhetslagen
Sweden's national law transposing the NIS2 Directive, in force since 2026.
Explained in depth: Who NIS2 applies to
Cybersäkerhetslagen (the Swedish Cybersecurity Act) is Sweden's transposition of NIS2, based on government bill Prop. 2025/26:28 ("Ett starkt skydd för nätverks- och informationssystem"). It entered into force in 2026, after the EU's original transposition deadline of October 2024, and replaces the previous Swedish NIS regulation. The law carries over NIS2's core structure: essential and important entities, the ten risk-management measures, the three-stage incident reporting timeline, registration duties, and management accountability. Supervision in Sweden is organised through sector-specific supervisory authorities, with MSB (Myndigheten för samhällsskydd och beredskap) in a central coordinating role and CERT-SE as the national CSIRT receiving incident reports. Swedish entities register with the relevant authority and report incidents through the national channel.
Why it matters
For Swedish organisations, Cybersäkerhetslagen, not the directive itself, is the legally binding text. Deadlines for registration, the exact supervisory setup, and sanction procedures all follow from the Swedish law. This is also one of the highest-volume Swedish search terms in the NIS2 space.
