Directive NIS2 European Union
SE · Member state

NIS2 in Sweden


What binds you in Sweden is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.

Transposition
Transposed
Competent authority
NCSC at FRA (Försvarets radioanstalt)
National CSIRT
VAT on your purchase
25%

Reviewed . Verify against the national official journal before relying on this for a filing.

The text that actually binds you

National transposition


National law

Cybersäkerhetslagen (2025:1506)

In force

Entities had to meet all obligations from entry into force on 15 January 2026 — no phase-in.

This is not the article you read in the directive

Sweden goes beyond the directive for trust service providers: a follow-up notification is due within 24 hours of becoming aware of an incident, where NIS2 itself allows longer. Planning to the directive's deadlines alone puts you late in Sweden.

Supervision

NCSC / FRA inspections

The supervising body changed twice in 2026, so older guidance names the wrong one: MSB was renamed Myndigheten för civilt försvar (MCF), and on 1 July 2026 cyber responsibilities moved to the Nationellt cybersäkerhetscenter (NCSC) at Försvarets radioanstalt (FRA). Regulations issued earlier may still carry the former agency's name; CERT-SE remains the CSIRT.

Who supervises you

NCSC at FRA (Försvarets radioanstalt) is the competent authority designated by Sweden. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.

Incident notifications under article 23 normally go to CERT-SE, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.

What differs from the directive

Because NIS2 is a directive, Sweden legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:

  • Registration. The portal, the information required and the deadline are national.
  • Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
  • Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
  • Reporting format. Deadlines are fixed by the directive; the form and the language are national.

If you operate in several member states

You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.

Cart 0