NIS2 · National implementation
NIS2 in Sweden
Sweden transposed NIS2 through Cybersäkerhetslagen (SFS 2025:1506), based on government bill Prop. 2025/26:28, in force since 15 January 2026 — well past the directive's October 2024 deadline, which is why Swedish entities faced a compressed preparation window.
- National law
- Cybersäkerhetslagen (SFS 2025:1506)
- Cybersecurity Act
- Status
- In force
- In force
- 15 January 2026
- Authority
- MSB (coordinating) and sector authorities
Supervision
Sweden uses a sector-split model: supervision is carried out by sector-specific authorities (for example within energy, health, transport, digital infrastructure and financial services), with MSB (Myndigheten för samhällsskydd och beredskap) as the coordinating authority issuing the common regulations. Incident reports go to CERT-SE, Sweden's national CSIRT, operated by MSB.
Registration
In-scope entities must self-assess against the annex sectors and the size-cap rule and register with the relevant supervisory authority. MSB's regulations (MSBFS) set the registration details. No authority will notify you — the duty to come forward is yours.
What is specific to Sweden
The law follows the directive's structure closely (essential/important entities, the ten Article 21 measures, 24h/72h/1-month reporting), but note three practical points: supervision language is Swedish and reports are filed through MSB's national channels; the law interacts with Sweden's separate implementation of the CER directive and with the pre-existing säkerhetsskyddslag (Protective Security Act) — entities covered by säkerhetsskydd may have parallel, stricter obligations; and management liability follows Article 20, with the board (styrelsen) of an aktiebolag as the accountable management body.
Official sources
Primary references: the national statute book at svenskforfattningssamling.se and the national cybersecurity authority at www.msb.se.
NIS2 in Sweden: frequently asked questions
Last reviewed:
Related reading
Definitions
