Network and information security (NIS)

All operators of an essential service within the energy sector in Sweden are required to register with the Swedish Energy Agency.

If an incident occurs within your network or information system that affects the continuity of your essential service, you are also required to report it.

The Swedish Energy Agency's supervisory mandate

The Swedish Energy Agency is the regulatory authority for organisations that have identified themselves as operators of essential services (OES) within the energy sector.

In Sweden, operators within the designated societal sectors are responsible for determining whether they fall under the scope of the legislation. The law applies to both the private and public sector.

It is the legal person who delivers the service who must register. If you have identified several areas in the company or business where you are OES, you must send in a application per area.

Please note that you cannot register for NIS2 as of yet.

How to register as a operator of essential services within the energy sector (in Swedish)

+

What is the NIS2 Directive?

The NIS2 Directive establishes a unified legal framework to uphold cybersecurity in critical sectors across the EU. The proposal introduces more stringent supervisory measures for national authorities, stricter enforcement requirements and aims at harmonising sanctions regimes across all member states. A significantly larger number of organisations will also be covered.

NIS2 Directive, European Comission

+

What is the current status of NIS2 in Sweden?

In Sweden, the NIS2 Directive will be implemented through national legislation expected to enter into force on 15 January 2026. The procedure for registration of operators of essential services is yet to be confirmed.