Key Takeaways
- NIS2 registration in Sweden is now made to NCSC at Försvarets radioanstalt (FRA). The route through MCF (formerly MSB) stopped being the correct channel on 1 July 2026.
- You download an Excel form and email it to nis2anmalan@ncsc.se. The email must be encrypted with TLS in transit. Without TLS the notification does not arrive.
- Before 1 July, MCF stated that emailed notifications would not be processed. That instruction is now reversed, so anyone working from earlier guidance is doing the opposite of what is required.
- There is no fixed calendar deadline for a first notification. The Act requires it as soon as it can be done. The statutory 14 days applies to reporting a change to details you already filed.
- One notification per legal person. A single notification can cover several sectors. A subsidiary with its own organisation number files separately.
- NCSC receives your notification but does not supervise you. Eight authority groups divide the 18 sectors between them.
- Sanction fees for a private essential entity reach the higher of 2 percent of global annual turnover or the equivalent of EUR 10 million. Public entities face up to SEK 10 million.
What is NIS2 Registration in Sweden?
NIS2 registration in Sweden is the legal duty on every organisation covered by the Cybersecurity Act to notify its own existence, sector and classification to the national single point of contact. The Swedish term is anmälan. It is self-assessed which means no authority tells you first that you are in scope.
That last point is the one that catches people. NCSC does not decide whether your organisation is covered nor which sector you belong to nor whether you count as essential or important. You make that assessment, you document it and you file on the strength of it. Supervisory authorities can sometimes help but the judgement is yours.
The framework arrived in stages rather than all at once. Sweden implemented the NIS2 Directive through Cybersäkerhetslagen (2025:1506) and the Cybersecurity Ordinance (2025:1507), both in force on 15 January 2026, replacing the 2018 NIS law. Notification itself only opened on 2 February 2026 when the notification regulation MCFFS 2026:1 took effect.
Two purposes sit behind the register, according to MCF. Sweden has to compile and maintain a list of every covered entity. Each supervisory authority has to be able to see the entities it is responsible for. The list is not public. Part of the compilation goes to the European Commission and ENISA.
The Dates That Matter
What Changed on 1 July 2026
On 20 November 2025 the government decided to consolidate Sweden’s cybersecurity functions inside Nationellt cybersäkerhetscenter (NCSC) which has been part of FRA since 2024. The decision drew on the inquiry Samlade förmågor för ökad cybersäkerhet (SOU 2025:79). It took effect on 1 July 2026.
What moved was substantial. CERT-SE, Sweden’s national CSIRT. The cyber crisis management authority role. The national single point of contact under NIS2. The tasks under the Cybersecurity Act including notification. Also NCC-SE, the national coordination centre for cybersecurity research.
This was done by legal instrument not by an administrative notice. An amendment to the Cybersecurity Ordinance, SFS 2026:623, substituted Försvarets radioanstalt for MCF as single point of contact as CSIRT unit and as cyber crisis management authority. Because the Ordinance directs notifications to the single point of contact, changing who holds that role changed where notifications go.
One practical oddity follows from the speed of the transfer. The regulations still carry MCF’s name in their designations, MCFFS 2026:1 and MCFFS 2026:8 among them. They will keep doing so until they are revised. FRA is responsible for them now. A regulation labelled MCFFS is still the live rule.
Before 1 July 2026
Notification was made to MCF through an online notification service reached from mcf.se. A simplified version of that service launched on 2 February 2026. Organisations that filed through it do not need to file again.
Critically, MCF stated that notifications arriving by email would not be processed. The address nis2anmalan@mcf.se existed for questions about the service, not for submissions. Anyone who read that instruction learned the rule as do not email your notification.
From 1 July 2026
Email is now the channel. You download the notification form from NCSC as a spreadsheet, complete it and send it to nis2anmalan@ncsc.se. The form has been revised since the transfer so take a fresh copy rather than reusing one saved earlier.
The rule did not simply move address. It inverted. If your compliance notes still say that emailed notifications are rejected, they now describe the opposite of the correct process. This is the single most likely reason a notification filed in the past few weeks never landed.
Who Must Register?
Every covered entity notifies, whatever its sector. The Act divides them across 18 sectors and calls them verksamhetsutövare. Coverage attaches to the legal person which in practice means the organisation number.
The main route in has three parts. You carry out an activity listed in Annex I or Annex II of the NIS2 Directive, you are established in Sweden and you are at least the size of a medium-sized enterprise under Commission Recommendation 2003/361/EC. Transportstyrelsen states that size test as at least 50 employees or an annual turnover and a balance sheet total each reaching at least EUR 10 million.
Size is a default rather than a shield. The Act catches smaller entities on three further grounds. The first is being the sole provider in Sweden of a service essential to critical societal or economic activity.
The second is that disruption of your service could significantly affect life and health, public safety or public health. Disruption capable of causing significant systemic risk also qualifies. The third is carrying particular importance nationally or regionally for a sector, for a type of service or for other sectors that depend on you. Trust service providers are covered regardless of size.
Two further routes matter for technology businesses. Providers of public electronic communications networks or publicly available electronic communications services in Sweden are covered under their own provision.
A separate provision catches cloud services, data centres, content delivery networks, managed services, managed security services, online marketplaces, search engines, social network platforms, TLD registries, DNS services and domain name registration services. These are covered where the main establishment is in Sweden or a representative is established here.
If you previously registered under the old NIS law, you must notify again. NCSC is explicit on this. Earlier registration does not carry over.
Subcontracting alone does not bring you into scope. Supplying an organisation that is covered does not make you a covered entity in your own right though your customers may well pass equivalent requirements down through contracts.
Municipalities and Regions
Municipalities, regions and kommunalförbund are covered under public administration. They notify like everyone else. A whole municipality notifies as a single entity rather than department by department.
That matters because a municipality often runs activity across several sectors at once, water, waste, energy and transport among them. Those go into one notification with multiple sectors selected. Note that the municipal and regional assemblies themselves, kommunfullmäktige and regionfullmäktige, sit outside the Act.
Groups and Subsidiaries
The dividing line is the organisation number, not the group structure. One notification covers one legal person. That single notification can list several sectors.
Where a group is covered across several sectors, the group notifies for all of them, provided the subsidiaries or affiliated partner companies do not hold their own organisation numbers. Where they do hold their own numbers each files its own notification. If you are filing for several entities, NCSC asks for one email per notification rather than a bundle.
Foreign Companies and Representatives
The notification form asks whether you are an organisation in Sweden or a representative in Sweden which is where jurisdiction gets settled in practice.
An entity with no establishment anywhere in the European Economic Area but which otherwise meets the digital-services provision and offers services in Sweden, must appoint a representative. That representative has to be established in Sweden or in another EEA country where the services are offered.
FRA holds the power to issue regulations on what counts as a main establishment. A group with operations in several member states should therefore check the current position before assuming Sweden is or is not the right filing jurisdiction.
Who Sits Outside the Act
The Act does not apply to the Government, the Government Offices, foreign missions, the committee system, agencies under the Riksdag, courts or tribunals exercising adjudication.
State agencies that predominantly conduct security-sensitive activity under the Protective Security Act are also outside it. So are those that predominantly conduct law-enforcement activity. Where only part of an organisation does that kind of work, only that part loses the substantive obligations. Trust service providers get no exemption on these grounds at all.
DORA deserves a careful word. Entities exempted under Article 2.4 of DORA fall outside the Act entirely. For entities that DORA does cover, the Act switches off the obligations on security measures and incident reporting. The notification duty sits in a separate provision that the exemption does not reach so a DORA-regulated firm should not assume it has nothing to file. Confirm the position with Finansinspektionen before concluding either way.
Essential or Important?
Essential Entities
State agencies. Municipalities and regions larger than a medium-sized enterprise. Annex I entities larger than medium. Degree-awarding private education providers larger than medium. Electronic communications providers at or above medium size. TLD registries and DNS providers. Qualified trust service providers.
Important Entities
Every other covered entity. Supervision is event-driven rather than planned. A supervisory authority may act only where it has reason to assume the rules are not being followed.
Both Still Notify
Your classification changes how closely you are supervised and how high the sanction ceiling sits. It does not change the duty to notify, the information required or the channel you use to file.
Is There a Registration Deadline?
Not a fixed one. This is where a good deal of confusion has built up. The Act requires you to notify så snart det kan ske as soon as it can be done. It sets no calendar date for a first notification.
There is a statutory 14 days but it attaches to something different. Where the circumstances reported in a notification change, you must report the change as soon as it can be done and no later than 14 days after the change occurred. That is a rule about keeping an existing filing current.
Alongside that, NCSC states on its registration page that entities should notify as soon as possible from 2 February 2026. It adds that if a notification has not arrived within 14 days the supervisory authorities may take action. Reading those two statements together has led some guidance to circulate a hard deadline of 16 February 2026. No such date appears in the Act.
NCSC’s own answer is more measured. Missing 14 days does not automatically mean supervision or a sanction. The supervisory authority decides when and for which entities to open supervision. It assesses separately whether there are grounds to intervene.
The practical reading for a compliance lead is straightforward. Late is worse than early and neither is a cliff edge. If you have concluded you are in scope, file now rather than waiting for a deadline that does not exist. If you are still assessing, document the assessment as you go because that documentation is what you show a supervisory authority to explain the timing.
How to Register, Step by Step
Work through it in this order.
First, assess and document. Establish whether you are covered using the Act, Annexes I and II of the Directive, the notification regulation MCFFS 2026:1 and NCSC’s guidance on notification and identification. Write down the reasoning.
NCSC’s advice for a borderline case is direct. If you are leaning towards being in scope, document why and file since a notification can be withdrawn later if the assessment changes. If you are leaning the other way, document why anyway so you can show a supervisory authority your working.
Second, appoint one owner. NCSC recommends naming a single person responsible for producing one complete notification covering every part of the organisation that is in scope. Fragmented filing is how sectors get missed.
Third, download the current form. Take it from NCSC’s notification page rather than from a saved copy because the form has been revised since the transfer.
Fourth, complete it. The form asks for your organisation name and number, establishment status, address, email and telephone. It then asks for the sector and any subsector with several selectable plus your sector activity within the EU and EEA.
The remaining fields are the ones people underestimate. You state how you identified yourself as in scope whether you are essential or important, your internet-facing identifiers including IP addresses and domain names, plus the contact details of whoever is filing.
Fifth, send it to nis2anmalan@ncsc.se. One email per notification. NCSC accepts only email that is encrypted with TLS in transit. Most mail services do this automatically. If yours does not, the notification will not reach NCSC and your own provider will bounce it back to you with an error.
If you cannot send over TLS, contact NCSC at ncsc@ncsc.se or by phone for instructions on another secure route. Do not send the notification itself to that address. It is not the filing channel.
Sixth, wait for the acknowledgement. NCSC confirms a processed notification within two working days. If nothing arrives in that window, assume the notification did not get through and follow it up rather than waiting. Where something needs clarifying, NCSC will make contact.
A third party may file on your behalf, an adviser or a group function for instance. No power of attorney is needed at the point of filing but a third-party notification will need to be substantiated if the matter reaches supervision.
Higher Education and Research
The regulation and guidance did not initially spell this out so NCSC has clarified it separately and will fold it into updated guidance during autumn 2026.
Research organisations notify under the Research sector. State universities and colleges that meet the criteria for state agencies notify under Public Administration. Private education providers with the authority to award degrees notify under Research as enskild utbildningsanordnare where they are established in Sweden and meet the size criterion.
Which Authority Supervises You?
NCSC receives your notification. It does not supervise you. Supervision is split across eight authority groups by sector under the Cybersecurity Ordinance. NCSC passes your details to whichever ones apply to you.
Statens energimyndighet covers energy. Transportstyrelsen covers transport plus the manufacture of motor vehicles, trailers and semi-trailers and of other transport equipment. Finansinspektionen covers banking and financial market infrastructure. Inspektionen för vård och omsorg covers healthcare providers. Läkemedelsverket covers the rest of the health sector and the manufacture of medical devices and in vitro diagnostic devices.
Livsmedelsverket covers drinking water, wastewater and the production, processing and distribution of food. Post- och telestyrelsen covers digital infrastructure, digital providers, ICT service management between businesses, post and courier services and space. PTS also supervises the county administrative boards themselves and providers of domain name registration services.
Six county administrative boards, those of Norrbotten, Skåne, Stockholm, Västra Götaland, Örebro and Östergötland share the remainder. That covers waste management, research and public administration other than the county boards themselves. It also covers the manufacture, production and distribution of chemicals plus the manufacture of computers and electronics and optics of electrical equipment and of other machinery.
For municipalities, regions and entities with their registered seat in a county, the county boards divide the country geographically. Norrbotten takes Jämtland, Norrbotten, Västerbotten and Västernorrland. Skåne takes Blekinge, Kronoberg and Skåne. Stockholm takes Gotland and Stockholm. Västra Götaland takes Halland and Västra Götaland. Örebro takes Dalarna, Gävleborg, Södermanland, Uppsala, Värmland, Västmanland and Örebro. Östergötland takes Jönköping, Kalmar and Östergötland.
You can end up with more than one supervisory authority. Where two or more have responsibility for the same entity, the Ordinance requires them to agree between themselves how supervision will be carried out. FRA leads a cooperation forum intended to keep supervision consistent across sectors. A municipality running water and energy alongside its administrative functions is the obvious case.
One more overlap is worth knowing. Where an incident is also a personal data breach, your supervisory authority is required to cooperate with Integritetsskyddsmyndigheten. The incident has to be reported to both NCSC and IMY.
Registration is Not Incident Reporting
These are two separate obligations running on two separate channels. Conflating them is a common and expensive mistake. Filing one does not discharge the other.
Registration is the emailed spreadsheet described above. It happens once, then gets maintained.
Incident reporting runs through the cyber portal at cyberportal.ncsc.se. It requires Swedish e-identification with a fallback procedure available for anyone who lacks it or prefers not to use it. Reports may be written in English. The previous reporting system, IRON, closed on 30 June 2026 so any reporting begun there had to be completed in the new portal.
Since 1 July 2026 all incidents go to NCSC which forwards each report to the supervisory authorities affected. If one incident touches several of your sectors you still file one report rather than several.
The timings are tight. You inform NCSC of a significant incident as soon as you can and no later than 24 hours after becoming aware of it. A fuller incident notification follows as soon as possible within 24 hours for trust service providers and 72 hours for everyone else.
Interim reports come on request. A final report is due within one month. Where the incident is still running at that point you file a status report instead with the final report due a month after the incident is handled.
One point is worth noting for anyone still weighing whether to file. Obligations do not wait for your notification. Security measures and incident reporting have applied since the Act came into force. Registering late does not delay them.
What Happens if You Get Registration Wrong
The risk here is not an automatic fine. It is that you enter the supervisory system on the back foot with a documented failure already on record. Each mechanism below is named in the Act. Each is worth understanding before you need it.
Planned supervision applies to essential entities. A supervisory authority can open supervision on its own schedule without any triggering event. For important entities supervision is event-driven. The Act allows measures only where the authority has reason to assume the rules are not being followed.
Information demands come first in practice. Anyone under supervision must provide the information and documents the authority needs on request. This is where a missing or undocumented scope assessment hurts most because you cannot produce reasoning you never wrote down.
Access to premises is available where needed for supervision excluding dwellings. Security audits can be run regularly against essential entities either by the authority or by an independent body it appoints. Targeted audits are available against anyone under supervision where there are special grounds. Security scans can be carried out, in cooperation with the entity.
Injunctions are the main compliance lever. An authority can order you to meet your obligations, can order you to publish information about your breaches and can attach a penalty payment. A penalty-payment injunction can be directed at the State as well as at a private entity. Where you obstruct supervision, the authority can seek enforcement assistance from Kronofogdemyndigheten.
A breach counts as serious under the Act where it is repeated, where you failed to report or inform as required, where you failed to remedy a significant incident, where you ignored an injunction, where you obstructed a supervisory measure or where you supplied false or grossly incorrect information.
Management bans sit at the far end. A court can bar an individual from holding a management function for one to three years but only against an essential private entity only after an injunction has already been ignored, only where the underlying breach was serious and only where the individual caused it intentionally or through gross negligence. The ban is not available against public entities.
Decisions can be appealed to the general administrative court with leave to appeal required beyond that.
Penalties for Non-Compliance
Sanction fees start at SEK 5,000 in every case. The ceiling depends on what kind of entity you are.
For a private essential entity the maximum is the higher of 2 percent of total global annual turnover for the preceding financial year or the krona equivalent of EUR 10 million. For a private important entity it is the higher of 1.4 percent of that turnover or the krona equivalent of EUR 7 million. For a public entity the maximum is SEK 10 million.
The choice of intervention is not mechanical. An authority weighs how serious the breach was, how long it lasted and what harm or risk of harm it caused. It gives particular weight to any previous breach, to what you did to prevent or limit the damage, to whether the breach was intentional or negligent and to any financial advantage you gained.
Procedure sets real limits. A fee can only be decided where the party has had the opportunity to respond within two years of the breach. Payment falls due within 30 days of the decision gaining legal force. A fee lapses if it has not been enforced within five years. Fees accrue to the State.
For most entities registration itself carries no charge. The exception is providers of public electronic communications networks and services, where a supervisory authority may charge a fee for handling the notification and must also charge an annual fee covering its costs for supervising that group.
Sanction Fee Ceilings
- Private essential entity: the higher of 2 percent of total global annual turnover for the preceding financial year or the krona equivalent of EUR 10 million
- Private important entity: the higher of 1.4 percent of that turnover or the krona equivalent of EUR 7 million
- Public entity: SEK 10 million
- Minimum in every case: SEK 5,000
How to Keep Your Registration Current
Treat the notification as a live record rather than a completed task. The statutory 14 days lives here.
Report any change to the circumstances in your notification as soon as you can and no later than 14 days after the change happened. Send changes, supplements and deregistrations to nis2anmalan@ncsc.se, under the same TLS requirement as the original filing.
Set a trigger for it. The reported circumstances include your organisation number, your registered address, the sectors or subsectors you operate in, your essential or important classification, your internet-facing identifiers such as IP ranges and domain names and the person named as contact.
A subsidiary acquired or divested, a new service line, a data centre migration and a change of compliance lead are all ordinary business events that quietly start a 14-day clock.
Withdraw a notification if your assessment genuinely changes. Deregistration is available. NCSC would rather see a filing withdrawn than a register that is wrong.
Keep watching the regulations because the framework is still filling in. The rules on security measures and management training took effect on 1 October 2026, together with those on security audits and security scans.
Connection to ANTS became a requirement from that date unless it is obviously unnecessary in which case something at least as good is expected instead. Guidance on notification for higher education is due to be updated during autumn 2026.
Remember that notification is the beginning. Management has to undergo training on security measures. The Act sets ten minimum areas for those measures, running from risk analysis and incident handling through continuity management, supply-chain security and cyber hygiene to cryptography, access control and where needed multi-factor authentication.
The preparatory works read management as the board and chief executive of a limited company. For a municipality or region it is the municipal or regional executive board.
Conclusion
The substance of NIS2 registration in Sweden did not change on 1 July 2026. The obligation, the self-assessment and the information required are the same as they were in February. What changed is where the notification goes and how you send it. The change went in the direction fewest people expected from a portal that refused email to an email channel with no portal at all.
So do three things. Take a fresh copy of the notification form from NCSC, send it to nis2anmalan@ncsc.se over a TLS-encrypted connection and check that the acknowledgement arrives within two working days. If it does not, treat the notification as never filed.
Frequently Asked Questions
Who must register under NIS2 in Sweden?
Every entity covered by the Cybersecurity Act, in any of its 18 sectors including municipalities and regions. The main test is an Annex I or II activity, establishment in Sweden and a size at or above a medium-sized enterprise. Smaller entities are caught where they are the sole provider of an essential service or carry particular regional importance.
How do I register for NIS2 in Sweden?
Since 1 July 2026 you download the notification form from NCSC, complete it and email it to nis2anmalan@ncsc.se. The email must be encrypted with TLS in transit, otherwise it will not arrive. Send one email per notification. NCSC confirms a processed notification within two working days.
Is there a NIS2 registration deadline in Sweden?
There is no fixed calendar deadline for a first notification. The Act requires you to notify as soon as it can be done. NCSC asks entities to notify as soon as possible from 2 February 2026 and says supervisory authorities may act if a notification has not arrived within 14 days.
What happens if we do not notify within 14 days?
According to NCSC it does not automatically mean you become subject to supervision or sanctions. The supervisory authority decides when and for which entities to open supervision. It assesses separately whether there are grounds to intervene through a remark, an injunction or a sanction fee.
Who supervises us under NIS2 in Sweden?
Not NCSC. It receives notifications and forwards them. Supervision sits with the sector authority, meaning Energimyndigheten, Transportstyrelsen, Finansinspektionen, IVO, Läkemedelsverket, Livsmedelsverket, PTS or one of six county administrative boards. An entity active in several sectors can have more than one supervisory authority.
Does a group file one NIS2 notification or several?
One notification per legal person. A single notification can list several sectors. Where a group is covered across several sectors it notifies for all of them provided its subsidiaries and affiliated partner companies have no organisation numbers of their own. Those with their own numbers file separately.
Do we still register if we already registered under NIS1?
Yes. NCSC states that every entity covered by the new Cybersecurity Act must notify again, even if it was already covered by the previous NIS law. Registration under the 2018 regime does not carry over because the sectors, criteria and classifications have all changed.
Can someone else file the NIS2 notification for us?
Yes. A notification may be filed by an agent on your behalf, for example an adviser or a group function. No power of attorney is required at the point of filing but a third-party notification will need to be substantiated if the matter later reaches supervision by your sector authority.
This post is also available in: