NIS2 · National implementation

NIS2 in Sweden

Sweden transposed NIS2 through Cybersäkerhetslagen (SFS 2025:1506), based on government bill Prop. 2025/26:28, in force since 15 January 2026 — well past the directive's October 2024 deadline, which is why Swedish entities faced a compressed preparation window.

National law
Cybersäkerhetslagen (SFS 2025:1506)
Cybersecurity Act
Status
In force
In force
15 January 2026
Authority
MSB (coordinating) and sector authorities

Supervision

Sweden uses a sector-split model: supervision is carried out by sector-specific authorities (for example within energy, health, transport, digital infrastructure and financial services), with MSB (Myndigheten för samhällsskydd och beredskap) as the coordinating authority issuing the common regulations. Incident reports go to CERT-SE, Sweden's national CSIRT, operated by MSB.

Registration

In-scope entities must self-assess against the annex sectors and the size-cap rule and register with the relevant supervisory authority. MSB's regulations (MSBFS) set the registration details. No authority will notify you — the duty to come forward is yours.

What is specific to Sweden

The law follows the directive's structure closely (essential/important entities, the ten Article 21 measures, 24h/72h/1-month reporting), but note three practical points: supervision language is Swedish and reports are filed through MSB's national channels; the law interacts with Sweden's separate implementation of the CER directive and with the pre-existing säkerhetsskyddslag (Protective Security Act) — entities covered by säkerhetsskydd may have parallel, stricter obligations; and management liability follows Article 20, with the board (styrelsen) of an aktiebolag as the accountable management body.

Official sources

Primary references: the national statute book at svenskforfattningssamling.se and the national cybersecurity authority at www.msb.se.

NIS2 in Sweden: frequently asked questions

Last reviewed:

Related reading

All 27 EU member states