Compliance & frameworks

What is NIS2?

A plain guide to NIS2 and Sweden's Cybersäkerhetslagen. Who it applies to, what it requires and how to prepare.

Key takeaways
  • NIS2 is Directive (EU) 2022/2555, an EU law setting minimum cybersecurity and incident-reporting duties across 18 sectors.
  • In Sweden it is transposed as Cybersäkerhetslagen (2025:1506), in force since 15 January 2026.
  • It applies to medium-sized and larger entities (50+ staff or over €10 million) in scope sectors, and it pulls their suppliers in too.
  • Entities are split into essential and important, which sets the level of supervision and the fine ceiling.
  • Article 20 makes the board approve, oversee and train on cybersecurity, and holds it personally accountable.
  • Article 21 sets ten baseline measure areas, from incident handling and backups to supply-chain security and multi-factor authentication.
  • Significant incidents follow a three-stage cascade of a 24-hour early warning, a 72-hour notification and a one-month final report.
  • In Sweden you register with and report to NCSC (the National Cyber Security Centre at FRA, since 1 July 2026), alongside your sector authority, with CERT-SE support.
  • Fines reach €10 million or 2% of global turnover for essential entities, and €7 million or 1.4% for important entities.
  • NIS2 runs alongside GDPR and DORA, not instead of them.

NIS2 Explained in Plain Terms

NIS2 is the European Union’s main cybersecurity law. Its formal name is Directive (EU) 2022/2555 and it sets a common baseline of security measures and incident-reporting duties for organisations that run important services across 18 sectors. Sweden put it into national law as Cybersäkerhetslagen which took effect on 15 January 2026.

The directive replaces the first NIS Directive from 2016 and widens it sharply. Far more organisations are now in scope, the security requirements are more specific and for the first time, company boards can be held personally accountable for getting cybersecurity wrong.

That last point is what makes NIS2 different from the paperwork exercises that came before it. It carries real fines, real supervision and in Sweden, a live deadline that has already passed.

Who NIS2 Applies To

NIS2 does not only cover big utilities or national infrastructure. It reaches most medium-sized and larger organisations in its 18 sectors which include energy, transport, banking, health, drinking water, digital infrastructure, public administration, manufacturing, food and waste management.

The basic test is size. If your organisation has at least 50 staff or an annual turnover or balance sheet above €10 million and it operates in a covered sector, NIS2 most likely applies. Some providers are in scope whatever their size including DNS providers, top-level-domain registries, trust service providers and the sole provider of an essential service in a country.

Who NIS2 Applies To

In-scope organisations fall into two groups. Essential entities are the larger bodies in the most critical sectors and they face proactive supervision so regulators can audit and inspect them before anything goes wrong.

Important entities are everyone else in scope and they are usually supervised after a problem or a reported incident. The group you fall into sets your fine ceiling but both groups must meet the same core security duties and the same board accountability.

Scope also travels down the supply chain. If you supply a covered organisation, expect its NIS2 obligations to reach you through contracts and security requirements, even when you are not directly regulated. The Swedish law goes further and applies scope at whole-entity level so once part of an organisation is covered its wider IT estate comes with it.

The Core NIS2 Requirements

NIS2 asks for two things above all. It wants a set of security measures that match your risk and a management body that owns them. The measures sit in Article 21 and the governance duty sits in Article 20.

Article 21 sets an all-hazards baseline of ten measure areas. Here they are in plain business terms.

  • Risk management: Written policies for analysing risk and securing your information systems.
  • Incident handling: A defined way to detect, manage and learn from security incidents.
  • Business continuity: Backups, disaster recovery and crisis management so you can keep running.
  • Supply-chain security: Managing the security risk from your direct suppliers and service providers.
  • Secure development: Security built into how you buy, build and maintain systems, including handling vulnerabilities.
  • Effectiveness testing: Checking that your security measures actually work, not only that they exist.
  • Cyber hygiene and training: Basic good practice and regular cybersecurity training for staff.
  • Cryptography: Policies on the use of encryption where it is appropriate.
  • Access and people: Human-resources security, access control and knowing what assets you hold.
  • Strong authentication: Multi-factor authentication and secured communications where appropriate.

The measures must be appropriate and proportionate, judged against your size, your risk and the state of the art. A regulator will expect to see these controls operating day to day backed by evidence rather than a shelf of unused policies.

Article 20 is the part that changed the conversation in boardrooms. It requires the management body to approve the cybersecurity measures, oversee how they are run and take training so it can judge the risk. Board members can also be held personally liable if the organisation fails its Article 21 duties and for essential entities that can extend to a temporary ban from holding a management role.

Incident Reporting and Penalties

When a significant incident hits, NIS2 starts a strict reporting clock. An incident counts as significant when it seriously disrupts your service or causes major financial loss or when it causes considerable harm to other people or organisations.

Reporting runs in three stages to the national authority.

  • Within 24 hours: An early warning, flagging whether the incident looks malicious or could cross borders.
  • Within 72 hours: A fuller notification with an initial assessment of severity and impact, and any indicators of compromise.
  • Within one month of that notification: A final report with a detailed account, the root cause and what you did about it.

The clock starts when you become aware of the incident, not when it began. If the incident is still live at the one-month mark, you send a progress report and then file the final report within a month of resolving it.

In Sweden, significant incidents are reported to the National Cyber Security Centre (Nationellt cybersäkerhetscenter, NCSC) which took over the incident-reporting function on 1 July 2026 when MCF’s cyber operations moved to FRA. NCSC has been part of FRA since 2024. You report through the Cyberportalen and each report is passed to the supervisory authority for your sector.

The penalties are set to get attention. Essential entities can be fined up to €10 million or 2% of total worldwide annual turnover whichever is higher. Important entities face up to €7 million or 1.4%. These are EU minimum ceilings and Sweden has adopted them at the maximum the directive allows.

Where the same incident also involves personal data, the GDPR breach regime applies in parallel through IMY. To avoid double punishment, NIS2 provides that where a fine has already been imposed under GDPR for the same facts, the competent authority does not add a separate NIS2 fine for that conduct although it can still use its other enforcement powers.

NIS2 in Sweden and Cybersäkerhetslagen

Sweden was late to transpose NIS2. Like most member states it missed the EU deadline of 17 October 2024, and the European Commission issued a formal reasoned opinion in May 2025 before the Swedish law was finished.

The result is Cybersäkerhetslagen (2025:1506), the Swedish Cybersecurity Act together with the Cybersäkerhetsförordningen (2025:1507). Both took effect on 15 January 2026 and replaced the older NIS-era law from 2018. MCF was called MSB until 1 January 2026 so older guidance about the MSB NIS2 rules now points to MCF.

Under the Act, a covered organisation must register (anmälan) with NCSC, put appropriate security measures in place, train its management and report significant incidents. Supervision is shared. Sector authorities such as Energimyndigheten for energy and Finansinspektionen for banking oversee their own sectors while NCSC coordinates at national level.

The detailed rules are arriving in stages. The regulations on incident reporting and information duties (MCFFS 2026:8) have applied since 1 July 2026 and the regulations on security measures and training take effect on 1 October 2026 with the security-audit rules following on the same 2026 timetable. The duties in the Act itself, including registration and reporting already apply.

What NIS2 Failure Looks Like in Sweden

Two recent Swedish incidents show why NIS2 puts so much weight on supply-chain security and business continuity. In both, a single supplier failed and the damage spread across the public sector.

What NIS2 Failure Looks Like in Sweden

The Miljödata Ransomware Attack, 2025

In August 2025 a ransomware attack hit Miljödata, a supplier of HR software that Swedish municipalities use to handle sick leave, rehabilitation and work-injury reports. The attack was detected on 23 August and forced Miljödata to take systems offline.

Early reports suggested around 200 municipalities and regions were affected. Swedish authorities later confirmed 164 municipalities and four regions directly hit rising to about 250 organisations once universities and private firms were counted. Weeks later the stolen data was published on the dark web, exposing personal information belonging to more than 1.5 million people.

The lesson NIS2 draws from this is supplier concentration. When most of a country’s councils depend on one system, that supplier becomes a single point of failure. Supplier risk assessment, continuity planning and a tested incident-reporting process are exactly the duties Article 21 now makes mandatory.

The Tietoevry Outage, 2024

In January 2024 Akira ransomware struck a datacentre in Sweden run by Tietoevry, a Finnish IT and cloud-hosting provider. Tietoevry isolated the affected platform quickly but the damage was already spreading through the services it hosted.

The attack knocked out the Primula payroll and HR system used by most Swedish universities and more than 30 government authorities and it took the cinema chain Filmstaden and the retailer Rusta offline. Restoration ran from days into weeks. January salaries had already been processed which softened the immediate payroll impact.

Tietoevry did not publicly confirm how the attackers got in so the useful takeaway is not a single missing patch. It is dependence. Concentrating critical operations on one hosted platform with no tested fallback is the risk NIS2 wants organisations to plan for through continuity and crisis management.

How NIS2 Fits with GDPR, DORA and ISO 27001

NIS2 does not sit alone. It overlaps with other rules Swedish organisations already know and lining them up avoids both double work and missed duties.

GDPR still applies in full. If an incident exposes personal data, you may owe a separate breach notification to IMY, the Swedish data protection authority within 72 hours under Article 33. The NIS2 and GDPR clocks both start at awareness but go to different regulators so treat them as parallel tracks. Our GDPR compliance page for Sweden covers that duty in detail.

For banks, insurers and other financial entities, DORA takes priority for ICT risk and incident reporting. Where DORA applies to a financial entity, it acts as the specialist rule so that entity follows DORA rather than the equivalent NIS2 provisions, under the supervision of Finansinspektionen. Our DORA compliance page explains where the line falls.

ISO 27001 is the international standard for an information security management system and it maps closely onto many NIS2 measures. It is a strong head start but it is not the same as NIS2. Certification does not prove your scope, your reporting readiness or your board’s involvement which NIS2 checks separately. Our ISO 27001 page for Sweden shows how the two line up.

If you need help turning these duties into working controls, eBuilder Security’s NIS2 compliance services, security awareness training and managed detection and response map directly onto the measures above.

How to Prepare for NIS2

You do not need to solve NIS2 in one go. Work through it in a clear order and keep evidence as you go, because an audit will ask you to show the controls in action.

  • Confirm whether you are in scope and whether you are an essential or an important entity. If you are covered, register (anmälan) with NCSC.
  • Get the board involved early. Have it approve the security measures, arrange its training and record that both happened.
  • Run a gap assessment against the ten Article 21 measure areas and prioritise the gaps that carry the most risk.
  • Fix supply-chain and continuity gaps first. Map your critical suppliers, add security terms to contracts and test that you can keep running if one supplier fails.
  • Stand up an incident-reporting runbook that can produce a 24-hour early warning under pressure with a named owner and a deputy.
  • Keep evidence. Store policies, test results, training records and incident reports so you can show the measures are live.

Done in this order NIS2 becomes a set of routines you can maintain rather than a scramble before each deadline.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. You run IT for a Swedish manufacturer with 120 staff. Leadership assumes NIS2 is only for utilities.

    What is the right call?

    • Agree with them and take no action
    • Check your sector and size against NIS2, since manufacturers over 50 staff are usually in scope
    • Wait until a regulator contacts you
  2. At 09:00 on Monday your team confirms a significant ransomware incident.

    When is the early warning to the authority due?

    • Within 24 hours, so by about 09:00 Tuesday
    • Within 72 hours
    • Only once you have a full root-cause analysis
  3. A single HR software supplier serves most of your region's councils and is hit by ransomware, taking your services down.

    What does NIS2 expect you to have done beforehand?

    • Nothing, it is the supplier's breach
    • Assessed the supplier's risk and planned how to keep running if it failed
    • Reported it to the data protection authority only
  4. Your board wants to hand NIS2 entirely to the IT team and skip any training for directors.

    How should you advise them?

    • That is fine as long as IT owns it
    • The board must approve and oversee the measures and take training itself
    • Training is optional for directors

Knowledge Test

  1. What is the formal name of the NIS2 law?

    • Regulation (EU) 2016/679
    • Directive (EU) 2022/2555
    • Directive (EU) 2016/1148

    NIS2 is Directive (EU) 2022/2555. 2016/1148 was the first NIS Directive and 2016/679 is GDPR.

  2. When did Sweden's Cybersäkerhetslagen enter into force?

    • 17 October 2024
    • 15 January 2026
    • 1 January 2026

    It took effect on 15 January 2026. 1 January 2026 is when MSB was renamed MCF.

  3. Which size test usually brings an organisation into scope?

    • At least 50 staff, or turnover or balance sheet above €10 million
    • At least 250 staff and nothing less
    • Any organisation with a website

    NIS2 generally covers medium-sized and larger entities, meaning 50+ staff or over €10 million.

  4. How many baseline measure areas does Article 21 set?

    • Five
    • Ten
    • Twenty

    Article 21(2) lists ten measure areas, from incident handling to multi-factor authentication.

  5. What is the NIS2 reporting cascade for a significant incident?

    • A single report within 30 days
    • A 24-hour early warning, a 72-hour notification and a one-month final report
    • 72 hours, then one week

    Significant incidents follow a 24-hour, 72-hour and one-month cascade to the authority.

  6. What is the maximum fine for an essential entity under NIS2?

    • €7 million or 1.4% of turnover
    • €10 million or 2% of global turnover
    • €20 million or 4% of turnover

    Essential entities face up to €10 million or 2% of global turnover. €7M or 1.4% applies to important entities.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

Most NIS2 duties come down to people doing the right thing under pressure. Article 21 names basic cyber hygiene and regular training as a required measure, and Article 20 puts the board through training too. Staff who can spot a suspicious request and start the reporting clock are often the difference between a contained incident and a reportable one.

eBuilder Security runs security awareness training built around exactly these habits, so your teams and your leadership can meet the training duty and act quickly when something goes wrong.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.