Regulations & Compliance

Sweden’s NIS2 Rules Now Mandate Intrusion Detection, MFA and Board Training

Sweden's NIS2 Rules Now Mandate Intrusion Detection, MFA and Board Training

Since 1 October, Swedish organisations covered by Cybersäkerhetslagen have had to meet a legal minimum for cybersecurity. MCFFS 2026:11 requires essential and important entities to run intrusion detection on production IT networks and to use multi-factor authentication for administrators and for anyone connecting from outside. Their management team must also be trained in security measures.

The National Cyber Security Centre (NCSC) at FRA confirmed the regulation’s entry into force on 1 October. A companion regulation, MCFFS 2026:12, took effect the same day and governs how supervisory authorities may use security audits and security scanning. Both implement NIS2 in Sweden through Cybersäkerhetslagen (SFS 2025:1506), in force since 15 January 2026. MCF (formerly MSB) issued them in June and they still carry its name because its cyber operations moved to NCSC on 1 July. NCSC says the rules apply unchanged until they are revised.

Intrusion Detection, MFA and DNSSEC Are No Longer Optional

Most of the regulation is risk-based. Operators must classify information, analyse risks and choose proportionate measures. A handful of requirements in chapter 4 leave no such room.

  • Intrusion detection and prevention for IT segments in the production environment (chapter 4, section 29).
  • MFA for administrative access to IT systems and to production OT segments. It also applies to IT systems holding information that needs enhanced protection and to staff and suppliers connecting over external networks (chapter 4, section 17).
  • Logging of unauthorised access and attempted access, plus analysis of each system’s logs at an interval matched to risk (chapter 4, sections 21 and 22).
  • DNSSEC for the organisation’s registered domain names unless obviously unnecessary (chapter 4, section 26).
  • Connection to ANTS, the national CSIRT’s automated notifications of technical vulnerabilities unless obviously unnecessary (chapter 4, section 20).
  • Prompt security updates on IT systems with unsupported software replaced or upgraded without undue delay (chapter 4, section 31).

The general advice attached to the patching rule recommends starting work on a security update within 72 hours of the fix becoming available. That figure is advice. The regulation itself says general advice is not binding.

Real-time Monitoring is Advice and IMY Fined Miljödata for Lacking It

On monitoring, the binding text is softer. Chapter 4, section 20 requires operators to “identify and handle the need” for real-time monitoring. Actually using it in production for central security functions and sector-critical systems appears only in the general advice.

Nine days before the regulation took effect, the Swedish Authority for Privacy Protection (IMY) fined Miljödata SEK 1.8 million under Article 32 of the GDPR. The Karlskrona company supplies work-environment and HR systems used by most Swedish municipalities. IMY found it had not run sufficient checks when installing new software and had no automated real-time monitoring to detect intrusions. According to Miljödata, the August 2025 attack affected 2.2 million people. IMY concluded the company had acted negligently.

Contracts Signed Before 1 October Need a Second Look

Chapter 4, section 1 makes operators responsible for ensuring suppliers meet the regulation’s requirements wherever the operator does not meet them itself. Operators must also assess whether a supplier can meet the security requirements for the whole contract term. For agreements signed before 1 October 2026 the duty is narrower, identify and handle the need to add cybersecurity requirements where possible and manage the risk where a contract falls short.

The general advice lists the terms it recommends for outsourcing contracts. They include when the supplier must report suspected incidents, how much incident and crisis handling it exercises with the customer, how risk from subcontractors is shared and a right to terminate early if the supplier fails the agreed security requirements.

Management Approves the Measures and Is Briefed At Least Once a Year

Chapter 2 defines what management training is for: enough knowledge to set objectives for cybersecurity, judge which measures the organisation needs and oversee their implementation. Chapter 3, section 4 requires management to approve and oversee the measures. It must be informed about their implementation and the organisation’s level of cybersecurity when needed and at least once a year.

The general advice goes further. It puts three decisions on management’s desk: the criteria for accepting risk, the order in which operations are restored and which systems count as sector-critical. The advice is not binding.

Cloud and Managed Service Providers Follow a Different Rulebook

Chapter 1, section 1 narrows the regulation for one group. Operators whose covered activity lies solely in digital infrastructure, digital providers, ICT service management, postal and courier services or space need only meet the management training requirement.

For cloud, data centre, managed service and managed security service providers, the technical requirements sit instead in Commission Implementing Regulation (EU) 2024/2690 which applies directly across the EU. A Swedish operator and its cloud or managed service provider can therefore be held to different technical rulebooks.

Guidance Arrives Three Months After the Rules

NCSC has published an introduction to the regulation and says fuller guidance on individual requirements will follow around the turn of the year. Until then, operators are bound by rules whose detailed interpretation has not been published. FRA can grant exemptions in individual cases where there are special reasons.

Section 20 After the Miljödata Fine

Read alongside the Miljödata decision, chapter 4, section 20 leaves less room than its wording suggests. IMY fined Miljödata partly for lacking the automated real-time monitoring that the regulation only asks operators to assess the need for. We would treat any decision not to monitor sector-critical systems in real time as one for management to approve under chapter 3, section 4 with reasons that would hold up in front of IMY as well as the sector supervisor.

References

  1. Föreskrifter om säkerhetsåtgärder träder i kraft
  2. MCFFS 2026:11 Föreskrifter och allmänna råd om säkerhetsåtgärder och ledningens utbildning
  3. The Swedish Cybersecurity Act Autumn 2026: Supervision So Far and New Requirements from 1 October
  4. Sanktionsavgift mot Miljödata för bristande säkerhet
  5. Miljödata Fined SEK 1.8 Million After Major Data Breach, Swedish Watchdog Says
  6. Sweden Fines Miljödata $183,000 Over Breach Affecting 2.2 Million
  7. Commission Implementing Regulation (EU) 2024/2690

This post is also available in: Svenska

Erik Berg

Erik Berg is CTO and Principal Security Architect at eBuilder Security, with more than a decade in blue team security operations across the private and public sectors, and a focus on emerging threats including the security risks that come with AI.