NIS2 in Sweden
What binds you in Sweden is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.
Reviewed . Verify against the national official journal before relying on this for a filing.
National transposition
Cybersäkerhetslagen (2025:1506)
Entities had to meet all obligations from entry into force on 15 January 2026 — no phase-in.
This is not the article you read in the directive
Sweden goes beyond the directive for trust service providers: a follow-up notification is due within 24 hours of becoming aware of an incident, where NIS2 itself allows longer. Planning to the directive's deadlines alone puts you late in Sweden.
NCSC / FRA inspections
The supervising body changed twice in 2026, so older guidance names the wrong one: MSB was renamed Myndigheten för civilt försvar (MCF), and on 1 July 2026 cyber responsibilities moved to the Nationellt cybersäkerhetscenter (NCSC) at Försvarets radioanstalt (FRA). Regulations issued earlier may still carry the former agency's name; CERT-SE remains the CSIRT.
Who supervises you
NCSC at FRA (Försvarets radioanstalt) is the competent authority designated by Sweden. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.
Incident notifications under article 23 normally go to CERT-SE, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.
What differs from the directive
Because NIS2 is a directive, Sweden legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:
- Registration. The portal, the information required and the deadline are national.
- Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
- Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
- Reporting format. Deadlines are fixed by the directive; the form and the language are national.
If you operate in several member states
You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.