Cybersecurity Act – the implementation of NIS2 in Sweden

In 2022, the EU adopted a directive on measures for a high common level of cybersecurity within the Union, the NIS2 Directive. The directive has been implemented in Swedish legislation through the Cybersecurity Act and Cybersecurity Ordinance.

Whether your business is covered depends on the following criteria:

  • The business must be provided or carried out in Sweden within the energy sector as specified in the NIS2 Directive Annex 1. The energy sector also includes the sub-sectors of electricity, district heating or cooling, oil, gas and hydrogen.

  • The business must also meet a size requirement.

Requirements

The Cybersecurity Act requires business entities within its scope to:

  • register with the regulatory authority

  • implement appropriate security measures

  • provide management training

  • report significant incidents.

As a business you must identify if you are covered by the Cybersecurity Act and register with the Swedish Civil Defence and Resilience Agency. The Agency will forward the registration to the Swedish Energy Agency.

+

What is the NIS2 Directive?

The NIS2 Directive establishes a unified legal framework to uphold cybersecurity in critical sectors across the EU. The proposal introduces more stringent supervisory measures for national authorities, stricter enforcement requirements and aims at harmonising sanctions regimes across all member states. A significantly larger number of organisations will also be covered.

NIS2 Directive (digital-strategy.ec.europa.eu)

+

What is the current status of NIS2 in Sweden?

In Sweden, the NIS2 Directive was implemented through national legislation that entered into force in January 2026. Find out more about the timeline at the Swedish Civil Defence and Resilience Agency’s website.

Timeline for the implementation of the Cybersecurity Act in Sweden (mcf.se, in Swedish)