Compliance & frameworks

What is Cybersäkerhetslagen?

A plain-English guide to Sweden's NIS2 law: who it applies to, what it requires and how to prepare.

Key takeaways
  • Cybersäkerhetslagen (SFS 2025:1506) is Sweden’s implementation of the EU NIS2 directive and has been in force since 15 January 2026.
  • It replaces the 2018 NIS law and covers far more organisations, across 18 sectors from energy and health to digital infrastructure and public administration.
  • Municipalities, regions and most public authorities are in scope, and so are private companies with at least 50 staff or more than 10 million euro in turnover.
  • Organisations are split into essential and important, which sets how closely they are supervised and how large the fines can be.
  • The law requires risk-based security measures and makes the board responsible for approving and overseeing them.
  • Significant incidents must be reported to NCSC through CERT-SE, with an early warning within 24 hours, a fuller report within 72 hours and a final report within one month.
  • Since 1 July 2026 the national cyber functions, including CERT-SE and the NIS2 contact point, sit at NCSC within FRA rather than MCF.
  • Fines reach the higher of 2 percent of global turnover or 10 million euro for essential operators, and public bodies can be fined up to 10 million kronor.
  • A personal-data breach can trigger both this law and GDPR at once, with a separate 72-hour notice to IMY.
  • The Miljödata attack in August 2025 disrupted around 200 of Sweden’s 290 municipalities and regions through a single shared supplier.

Cybersäkerhetslagen Defined in Plain Terms

Cybersäkerhetslagen, formally SFS 2025:1506, is the Swedish law that brings the EU NIS2 directive into national force. It sets binding cybersecurity duties for organisations that run important services from risk management and staff training to fast incident reporting and it makes senior management answerable for meeting them.

The law took effect on 15 January 2026 and replaced the older 2018 NIS law. It is Sweden’s answer to a simple problem. Too many of the services people rely on, from hospitals to power and payments, now run on systems that were never built to resist a determined attacker.

Two things make this law different from what came before. It reaches far more organisations and it puts named accountability on the board instead of treating security as a technical afterthought.

Who Cybersäkerhetslagen Applies To

Cybersäkerhetslagen covers operators in 18 sectors up from 7 under the old NIS law. The list runs from energy, transport and water to health, food supply, digital infrastructure, public administration and research.

Who Cybersäkerhetslagen Applies To

The law sorts these organisations into two groups. Essential operators are the most critical and face closer supervision. Important operators matter to society but are treated as a step less critical. The group you fall into decides how closely you are watched and how large a fine can be.

For private companies the usual trigger is size. You are generally in scope from 50 employees or more than 10 million euro in annual turnover or balance-sheet total. Municipalities, regions, kommunalförbund and most state authorities are covered whatever their size and a smaller organisation can still be named in if it is judged critical.

Scope does not stop at the obvious names. If you supply software or services to an organisation that is in scope, its duties reach you through contracts and supplier reviews even when your own business would not be covered on its own.

What Cybersäkerhetslagen Requires

At its core the law asks for systematic, risk-based security rather than a folder of policies. The required measures come from Article 21 of NIS2 and cover the whole lifecycle of protecting a service.

  • Risk analysis and security policies: Know your risks and write down how you manage them.
  • Incident handling: Detect, respond to and report incidents in a repeatable way.
  • Business continuity: Keep backups you have tested and a plan to run through a crisis.
  • Supply-chain security: Vet your suppliers and set security requirements in your contracts.
  • Access control and cyber hygiene: Manage accounts, patch quickly and use multi-factor authentication.
  • Training: Teach staff and management to recognise and handle threats.

The law does not leave this to the IT team. The board must approve the security measures and oversee them and senior managers can be held personally accountable if the organisation falls short. For essential operators a serious failure can even lead to a temporary ban on an individual holding a management role.

There is also an administrative duty. You must work out whether you are covered and register with the relevant authority. As practical help, NCSC publishes a set of 11 recommended security measures that support these requirements.

Incident Reporting Under Cybersäkerhetslagen

One of the sharpest duties in the law is reporting. You must report a significant incident, meaning one that has caused or could cause serious operational disruption or economic loss or that harms other people or organisations.

Reporting runs in stages once you become aware of an incident. An early warning is due within 24 hours, a fuller notification within 72 hours and a final report within one month. The clock starts when you notice the incident, not when it is convenient.

Reports go to the National Cybersecurity Centre (NCSC) through CERT-SE, Sweden’s national CSIRT using NCSC’s Cyberportal. NCSC then passes the report to the supervisory authority for your sector.

This is a recent change worth flagging. Until the summer of 2026 these functions sat at MCF (formerly MSB). On 1 July 2026 the national cyber operations including CERT-SE and the NIS2 contact-point role moved to NCSC within FRA so guidance that still says report to MCF is out of date.

Penalties and Enforcement

Supervision is not the same for everyone. Essential operators face planned, recurring checks. Important operators face reactive supervision that begins when something happens such as an incident or a complaint.

The fines are set in the law itself. An essential operator can be fined the higher of 2 percent of global annual turnover or 10 million euro. For an important operator the ceiling is the higher of 1.4 percent or 7 million euro. A public-sector body can be fined up to 10 million kronor.

The fine is not only about incidents. Failing to put the measures in place, failing to register or failing to keep the required records is sanctionable on its own. For serious failures at an essential operator, a supervisory authority can also bar a named person from a management role for a time.

Real-World Cases

The law reads as abstract until you look at what it is meant to prevent. Three Swedish cases show the pattern and each points to a duty the law now makes explicit.

Real-World Cases

Coop and the Kaseya Attack (2021)

In July 2021 the supermarket chain Coop closed nearly all of its roughly 800 Swedish stores for several days. The tills simply stopped working.

Coop was not attacked directly. The ransomware reached it through a payment-systems supplier that used Kaseya’s remote-management software which attackers had compromised. One weakness two suppliers away was enough to empty the shelves.

The lesson maps straight onto supply-chain security. Knowing which suppliers can reach your core systems and segmenting so they cannot spread trouble is now a required control.

The Miljödata Attack (2025)

In August 2025 a ransomware group hit Miljödata, a supplier whose HR and work-environment systems are used by around 80 percent of Sweden’s municipalities. Around 200 of Sweden’s 290 municipalities and 21 regions were caught up in the incident on the supplier’s early estimate. Authorities later put the directly affected figure at 164 municipalities and four regions.

The exposed data was sensitive. It included health-related HR records such as sick leave and rehabilitation alongside names and personal identity numbers. NCSC coordinated the national response and the attack was reported to the police.

Miljödata shows the risk of many public bodies leaning on one supplier. It is why supply-chain security and prompt incident reporting sit at the centre of this law and why a personal-data leak like this also brings GDPR into play.

Kalix Municipality (2021)

In December 2021 Kalix municipality in northern Sweden was hit directly by ransomware. Home care and home health staff lost access to journals and medication lists and fell back to pen and paper. Payroll for around 1,900 employees was disrupted.

Kalix refused to pay. It rebuilt from backups over the following weeks which is the reason the damage was recoverable at all.

Tested backups and a rehearsed response are what turned a serious incident into one the municipality could survive. Both are part of the business-continuity duty the law expects.

Cybersäkerhetslagen and Other Rules

Cybersäkerhetslagen rarely stands alone. Most organisations in scope also answer to other rules and it is more efficient to meet them together instead of running separate projects.

NIS2 is not a separate obligation on top of this law. Cybersäkerhetslagen is how the EU NIS2 directive applies in Sweden so meeting the Swedish law is how you meet NIS2. Our NIS2 compliance in Sweden guide covers the framework in more detail.

GDPR overlaps but is not the same. The security measures line up with GDPR Article 32, yet if an incident exposes personal data you also owe a separate 72-hour breach notice to IMY under Article 33. See our GDPR compliance guide for how the two fit together.

Financial entities have a further layer. DORA is the sector-specific rulebook for digital operational resilience and takes precedence over this law for ICT risk in finance supervised by Finansinspektionen. Our DORA compliance guide explains the overlap.

A recognised management system helps in practice. Building to ISO 27001 gives you much of what the law asks for and makes the evidence easier to show though certification alone does not prove full compliance.

How to Prepare for Cybersäkerhetslagen

If you are not sure where to start, work through these steps in order.

  • Confirm scope: Check your sector, your size and whether you supply an in-scope organisation.
  • Register: Notify the relevant supervisory authority that you are covered.
  • Run a gap assessment: Measure yourself against the Article 21 measures and record what is missing.
  • Close the priority gaps: Multi-factor authentication, monitoring, patching, tested backups and supplier security clauses come first.
  • Write a reporting runbook: Map the 24-hour, 72-hour and one-month steps and point it at NCSC’s Cyberportal.
  • Brief the board and train staff: Management approval and awareness training are duties in their own right.

The measures are already in force so treat them as live obligations for this year, not a plan for later. Start with scope and the reporting runbook because those are the two that hurt most if you are caught without them.

Myths & Facts

Myth

Cybersäkerhetslagen only applies to big companies.

If we never have a breach, the law does not affect us.

Cybersecurity is the IT department's problem.

We still report incidents to MCF.

A supplier's breach is the supplier's problem, not ours.

Meeting NIS2 means we are automatically GDPR compliant.

Fact

It also covers municipalities, regions and most public authorities regardless of size, and private firms from 50 staff or more than 10 million euro in turnover.

The duties apply now. Failing to put the measures in place, register or keep records is sanctionable on its own, breach or not.

The law puts approval and oversight on the board, and senior managers can be held personally accountable for falling short.

Since 1 July 2026 significant incidents go to NCSC through CERT-SE, using NCSC's Cyberportal. MCF's cyber functions moved to NCSC within FRA.

Supply-chain security is a required measure, and the Miljödata and Coop cases show a supplier failure lands on you.

The security measures overlap, but GDPR adds duties this law does not, and a data breach still needs a separate 72-hour notice to IMY.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. You run IT at a mid-size energy company, an essential operator. On Monday morning you confirm a significant incident.

    When must the early warning reach NCSC?

    • Within 24 hours of becoming aware
    • Within 72 hours
    • Within one month
    • Only once systems are back to normal
  2. A shared HR supplier is hit by ransomware and your municipality's systems go down, as happened in the Miljödata attack.

    What is the right first move under the law?

    • Wait for the supplier to report it for you
    • Treat it as your incident, start your runbook and prepare to report
    • Ignore it, the breach was at the supplier
    • Pay the ransom to restore service fastest
  3. Your board says cybersecurity is the CISO's job and does not want to review the security plan.

    Why is that a problem under Cybersäkerhetslagen?

    • It is not a problem, full delegation is fine
    • The board must approve and oversee the measures, and managers can be personally accountable
    • Board oversight is only required for banks
    • It only matters after an incident
  4. You are a 30-person software firm that supplies a booking system to a hospital.

    Are you affected by the law?

    • No, you are under 50 staff
    • Possibly, as a supplier to an in-scope entity you will face security requirements through contracts and could be designated
    • Only if you suffer a breach
    • Only if you work in finance

Knowledge Test

  1. Which EU directive does Cybersäkerhetslagen implement?

    • The GDPR
    • The NIS2 directive
    • DORA
    • The EU AI Act

    Cybersäkerhetslagen transposes the EU NIS2 directive into Swedish law.

  2. When did Cybersäkerhetslagen come into force?

    • 1 January 2026
    • 15 January 2026
    • 17 October 2024
    • 1 July 2026

    The law took effect on 15 January 2026.

  3. How many sectors does the law cover?

    • 7
    • 12
    • 18
    • 24

    It covers 18 sectors, up from 7 under the old NIS law.

  4. Which body now receives significant-incident reports?

    • MSB
    • IMY
    • NCSC through CERT-SE
    • Finansinspektionen

    Since 1 July 2026 reports go to NCSC through CERT-SE, using NCSC's Cyberportal.

  5. What is the maximum fine for an essential operator?

    • The higher of 2 percent of global turnover or 10 million euro
    • A fixed 1 million kronor
    • 0.5 percent of turnover
    • No fines, only warnings

    Essential operators can be fined the higher of 2 percent of global turnover or 10 million euro.

  6. A personal-data breach also triggers which separate duty?

    • A 72-hour notice to IMY under GDPR
    • Nothing further
    • A notice to the police only
    • A DORA report to Finansinspektionen

    If personal data is exposed, GDPR Article 33 requires a separate 72-hour notice to IMY.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

Security awareness training is not optional under Cybersäkerhetslagen. Article 21 lists cyber hygiene and training among the required measures, and the law expects both staff and management to be trained.

Most incidents still begin with a person, whether that is a clicked link or an approved payment. Regular training lowers that risk and produces the records a supervisory authority will ask to see. eBuilder Security runs managed security awareness training and phishing simulations that build this habit and the evidence to go with it.

Frequently Asked Questions

What is Cybersäkerhetslagen?

Cybersäkerhetslagen, SFS 2025:1506, is the Swedish law that transposes the EU NIS2 directive into national law. It has applied since 15 January 2026 and sets cybersecurity duties for essential and important organisations across 18 sectors, from risk management and staff training to reporting significant incidents to the authorities.

When did Cybersäkerhetslagen come into force?

Cybersäkerhetslagen came into force on 15 January 2026. It was published in the Swedish statute book on 17 December 2025 as SFS 2025:1506 and replaced the older 2018 NIS law. Sweden implemented it more than a year after the EU's transposition deadline of October 2024.

Who does Cybersäkerhetslagen apply to?

Cybersäkerhetslagen applies to essential and important operators in 18 sectors, including energy, transport, health, digital infrastructure and public administration. Private companies are usually in scope from 50 employees or more than 10 million euro in turnover, while municipalities, regions and most public authorities are covered regardless of size.

Does Cybersäkerhetslagen apply to municipalities?

Yes. Municipalities, regions and kommunalförbund are in scope of Cybersäkerhetslagen regardless of their size. They must run systematic cybersecurity work, meet the risk-management measures and report significant incidents. Public bodies face administrative fines of up to 10 million kronor if they fail to meet the law's requirements.

What are the requirements of Cybersäkerhetslagen?

Cybersäkerhetslagen requires risk-based security measures set out in NIS2 Article 21, covering risk analysis, incident handling, business continuity, supply-chain security, access control and staff training. Organisations must register with the authorities, and the board must approve and oversee the measures. Senior managers can be held personally accountable.

How is Cybersäkerhetslagen related to NIS2?

Cybersäkerhetslagen is the Swedish law that puts the EU NIS2 directive into force. NIS2 sets the common European framework, and the Swedish act adds the national detail on supervision, sanctions and which authorities apply. So meeting Cybersäkerhetslagen is how a Swedish organisation meets NIS2.

Who do you report incidents to under Cybersäkerhetslagen?

Significant incidents are reported to the National Cybersecurity Centre (NCSC) through CERT-SE, using NCSC's Cyberportal. Since 1 July 2026 these functions sit within FRA rather than MCF. The deadlines are an early warning within 24 hours, a fuller report within 72 hours and a final report within one month.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.