NIS2 Explained in Plain Terms
NIS2 is the European Union’s main cybersecurity law. Its formal name is Directive (EU) 2022/2555 and it sets a common baseline of security measures and incident-reporting duties for organisations that run important services across 18 sectors. Sweden put it into national law as Cybersäkerhetslagen which took effect on 15 January 2026.
The directive replaces the first NIS Directive from 2016 and widens it sharply. Far more organisations are now in scope, the security requirements are more specific and for the first time, company boards can be held personally accountable for getting cybersecurity wrong.
That last point is what makes NIS2 different from the paperwork exercises that came before it. It carries real fines, real supervision and in Sweden, a live deadline that has already passed.
Who NIS2 Applies To
NIS2 does not only cover big utilities or national infrastructure. It reaches most medium-sized and larger organisations in its 18 sectors which include energy, transport, banking, health, drinking water, digital infrastructure, public administration, manufacturing, food and waste management.
The basic test is size. If your organisation has at least 50 staff or an annual turnover or balance sheet above €10 million and it operates in a covered sector, NIS2 most likely applies. Some providers are in scope whatever their size including DNS providers, top-level-domain registries, trust service providers and the sole provider of an essential service in a country.

In-scope organisations fall into two groups. Essential entities are the larger bodies in the most critical sectors and they face proactive supervision so regulators can audit and inspect them before anything goes wrong.
Important entities are everyone else in scope and they are usually supervised after a problem or a reported incident. The group you fall into sets your fine ceiling but both groups must meet the same core security duties and the same board accountability.
Scope also travels down the supply chain. If you supply a covered organisation, expect its NIS2 obligations to reach you through contracts and security requirements, even when you are not directly regulated. The Swedish law goes further and applies scope at whole-entity level so once part of an organisation is covered its wider IT estate comes with it.
The Core NIS2 Requirements
NIS2 asks for two things above all. It wants a set of security measures that match your risk and a management body that owns them. The measures sit in Article 21 and the governance duty sits in Article 20.
Article 21 sets an all-hazards baseline of ten measure areas. Here they are in plain business terms.
- Risk management: Written policies for analysing risk and securing your information systems.
- Incident handling: A defined way to detect, manage and learn from security incidents.
- Business continuity: Backups, disaster recovery and crisis management so you can keep running.
- Supply-chain security: Managing the security risk from your direct suppliers and service providers.
- Secure development: Security built into how you buy, build and maintain systems, including handling vulnerabilities.
- Effectiveness testing: Checking that your security measures actually work, not only that they exist.
- Cyber hygiene and training: Basic good practice and regular cybersecurity training for staff.
- Cryptography: Policies on the use of encryption where it is appropriate.
- Access and people: Human-resources security, access control and knowing what assets you hold.
- Strong authentication: Multi-factor authentication and secured communications where appropriate.
The measures must be appropriate and proportionate, judged against your size, your risk and the state of the art. A regulator will expect to see these controls operating day to day backed by evidence rather than a shelf of unused policies.
Article 20 is the part that changed the conversation in boardrooms. It requires the management body to approve the cybersecurity measures, oversee how they are run and take training so it can judge the risk. Board members can also be held personally liable if the organisation fails its Article 21 duties and for essential entities that can extend to a temporary ban from holding a management role.
Incident Reporting and Penalties
When a significant incident hits, NIS2 starts a strict reporting clock. An incident counts as significant when it seriously disrupts your service or causes major financial loss or when it causes considerable harm to other people or organisations.
Reporting runs in three stages to the national authority.
- Within 24 hours: An early warning, flagging whether the incident looks malicious or could cross borders.
- Within 72 hours: A fuller notification with an initial assessment of severity and impact, and any indicators of compromise.
- Within one month of that notification: A final report with a detailed account, the root cause and what you did about it.
The clock starts when you become aware of the incident, not when it began. If the incident is still live at the one-month mark, you send a progress report and then file the final report within a month of resolving it.
In Sweden, significant incidents are reported to the National Cyber Security Centre (Nationellt cybersäkerhetscenter, NCSC) which took over the incident-reporting function on 1 July 2026 when MCF’s cyber operations moved to FRA. NCSC has been part of FRA since 2024. You report through the Cyberportalen and each report is passed to the supervisory authority for your sector.
The penalties are set to get attention. Essential entities can be fined up to €10 million or 2% of total worldwide annual turnover whichever is higher. Important entities face up to €7 million or 1.4%. These are EU minimum ceilings and Sweden has adopted them at the maximum the directive allows.
Where the same incident also involves personal data, the GDPR breach regime applies in parallel through IMY. To avoid double punishment, NIS2 provides that where a fine has already been imposed under GDPR for the same facts, the competent authority does not add a separate NIS2 fine for that conduct although it can still use its other enforcement powers.
NIS2 in Sweden and Cybersäkerhetslagen
Sweden was late to transpose NIS2. Like most member states it missed the EU deadline of 17 October 2024, and the European Commission issued a formal reasoned opinion in May 2025 before the Swedish law was finished.
The result is Cybersäkerhetslagen (2025:1506), the Swedish Cybersecurity Act together with the Cybersäkerhetsförordningen (2025:1507). Both took effect on 15 January 2026 and replaced the older NIS-era law from 2018. MCF was called MSB until 1 January 2026 so older guidance about the MSB NIS2 rules now points to MCF.
Under the Act, a covered organisation must register (anmälan) with NCSC, put appropriate security measures in place, train its management and report significant incidents. Supervision is shared. Sector authorities such as Energimyndigheten for energy and Finansinspektionen for banking oversee their own sectors while NCSC coordinates at national level.
The detailed rules are arriving in stages. The regulations on incident reporting and information duties (MCFFS 2026:8) have applied since 1 July 2026 and the regulations on security measures and training take effect on 1 October 2026 with the security-audit rules following on the same 2026 timetable. The duties in the Act itself, including registration and reporting already apply.
What NIS2 Failure Looks Like in Sweden
Two recent Swedish incidents show why NIS2 puts so much weight on supply-chain security and business continuity. In both, a single supplier failed and the damage spread across the public sector.

The Miljödata Ransomware Attack, 2025
In August 2025 a ransomware attack hit Miljödata, a supplier of HR software that Swedish municipalities use to handle sick leave, rehabilitation and work-injury reports. The attack was detected on 23 August and forced Miljödata to take systems offline.
Early reports suggested around 200 municipalities and regions were affected. Swedish authorities later confirmed 164 municipalities and four regions directly hit rising to about 250 organisations once universities and private firms were counted. Weeks later the stolen data was published on the dark web, exposing personal information belonging to more than 1.5 million people.
The lesson NIS2 draws from this is supplier concentration. When most of a country’s councils depend on one system, that supplier becomes a single point of failure. Supplier risk assessment, continuity planning and a tested incident-reporting process are exactly the duties Article 21 now makes mandatory.
The Tietoevry Outage, 2024
In January 2024 Akira ransomware struck a datacentre in Sweden run by Tietoevry, a Finnish IT and cloud-hosting provider. Tietoevry isolated the affected platform quickly but the damage was already spreading through the services it hosted.
The attack knocked out the Primula payroll and HR system used by most Swedish universities and more than 30 government authorities and it took the cinema chain Filmstaden and the retailer Rusta offline. Restoration ran from days into weeks. January salaries had already been processed which softened the immediate payroll impact.
Tietoevry did not publicly confirm how the attackers got in so the useful takeaway is not a single missing patch. It is dependence. Concentrating critical operations on one hosted platform with no tested fallback is the risk NIS2 wants organisations to plan for through continuity and crisis management.
How NIS2 Fits with GDPR, DORA and ISO 27001
NIS2 does not sit alone. It overlaps with other rules Swedish organisations already know and lining them up avoids both double work and missed duties.
GDPR still applies in full. If an incident exposes personal data, you may owe a separate breach notification to IMY, the Swedish data protection authority within 72 hours under Article 33. The NIS2 and GDPR clocks both start at awareness but go to different regulators so treat them as parallel tracks. Our GDPR compliance page for Sweden covers that duty in detail.
For banks, insurers and other financial entities, DORA takes priority for ICT risk and incident reporting. Where DORA applies to a financial entity, it acts as the specialist rule so that entity follows DORA rather than the equivalent NIS2 provisions, under the supervision of Finansinspektionen. Our DORA compliance page explains where the line falls.
ISO 27001 is the international standard for an information security management system and it maps closely onto many NIS2 measures. It is a strong head start but it is not the same as NIS2. Certification does not prove your scope, your reporting readiness or your board’s involvement which NIS2 checks separately. Our ISO 27001 page for Sweden shows how the two line up.
If you need help turning these duties into working controls, eBuilder Security’s NIS2 compliance services, security awareness training and managed detection and response map directly onto the measures above.
How to Prepare for NIS2
You do not need to solve NIS2 in one go. Work through it in a clear order and keep evidence as you go, because an audit will ask you to show the controls in action.
- Confirm whether you are in scope and whether you are an essential or an important entity. If you are covered, register (anmälan) with NCSC.
- Get the board involved early. Have it approve the security measures, arrange its training and record that both happened.
- Run a gap assessment against the ten Article 21 measure areas and prioritise the gaps that carry the most risk.
- Fix supply-chain and continuity gaps first. Map your critical suppliers, add security terms to contracts and test that you can keep running if one supplier fails.
- Stand up an incident-reporting runbook that can produce a 24-hour early warning under pressure with a named owner and a deputy.
- Keep evidence. Store policies, test results, training records and incident reports so you can show the measures are live.
Done in this order NIS2 becomes a set of routines you can maintain rather than a scramble before each deadline.




