The Swedish Cybersecurity Act (2025:1506)
SFS 2025:1506 (Govt bill 2025/26:28) · In force since 15 January 2026 — replaces the 2018 NIS Act (2018:1174)
The Cybersecurity Act (cybersäkerhetslagen) is Sweden's transposition of the NIS2 Directive. It entered into force on 15 January 2026 and replaces the old NIS act from 2018. It sets concrete requirements on security measures, incident reporting and management accountability — backed by substantial penalty fees.
// In brief
- SFS 2025:1506, issued 11 December 2025, in force since 15 January 2026 (Government bill 2025/26:28).
- Transposes the NIS2 Directive and repeals the 2018 act on information security for essential and digital services (2018:1174).
- Covers Swedish central government agencies, regions and municipalities, plus entities in the NIS2 sectors that are medium-sized or larger.
- Classifies operators as essential or important entities (Chapter 1, Section 9).
- Security measures and incident reporting: early warning within 24 h, incident notification within 72 h, final report within one month.
- Penalty fees from SEK 5,000 up to €10 million or 2% of global turnover (essential) / €7 million or 1.4% (important).
What the Act is and what it replaces
The Swedish Cybersecurity Act (2025:1506) transposes the NIS2 Directive into Swedish law. Its purpose (Chapter 1, Section 1) is to achieve a high level of cybersecurity in society. It entered into force on 15 January 2026, repealing the old act (2018:1174) at the same time. The responsible ministry is the Ministry of Defence.
Note: this is a Swedish national law — not to be confused with the EU Cybersecurity Act (Regulation (EU) 2019/881), which deals with ENISA and European cybersecurity certification.
Who is covered?
The Act applies to, among others, Swedish central government agencies, regions, municipalities and municipal associations, as well as operators that fall under Annex I or II of NIS2, are established in Sweden and are at least the size of a medium-sized enterprise (Chapter 1, Section 4). Providers of public electronic communications networks, cloud, data centre, DNS and top-level domain registry services and others are also in scope.
Operators are classified as essential or important entities (Chapter 1, Section 9). Some are exempt — including activities covered by the DORA regulation and predominantly security-sensitive or law-enforcement activities.
Obligations (Chapter 2)
- Register with the competent authority, and report changes within 14 days (Section 2).
- Security measures (Section 3) taking an all-hazards approach — at minimum: risk analysis, incident handling, business continuity and crisis management, supply chain security, secure development, cryptography/encryption, cyber hygiene and training, access control and, where appropriate, multi-factor authentication.
- Management must be trained in security measures (Section 4).
- Incident reporting: an early warning within 24 hours (Section 5), an incident notification within 72 hours (24 h for trust services, Section 6), an interim report on request (Section 7) and a final report within one month (Section 8).
- Inform recipients of significant incidents and cyber threats (Sections 9–10).
Supervision and penalties (Chapters 3–4)
The supervisory authority may request information, gain access to premises, carry out security audits and security scans, and attach financial penalties to its orders. Interventions range from formal notices and orders to bans on holding a managerial position, and administrative penalty fees.
The penalty fee (Chapter 4, Section 10) is set at no less than SEK 5,000 and at most:
- Essential private entities: the higher of 2% of global annual turnover or the equivalent of EUR 10,000,000.
- Important private entities: the higher of 1.4% or the equivalent of EUR 7,000,000.
- Public-sector entities: SEK 10,000,000.
In serious cases, an individual in management can be banned from exercising a managerial function for 1–3 years (Chapter 4, Sections 6–8).
How ZORC helps
We help you determine whether you are in scope, build the security measures into your systems and put incident-reporting routines in place that meet the deadlines. Talk to us about your compliance →
This page is informational and fact-checked against the primary source, but it does not constitute legal advice. For a binding assessment of your specific organisation — talk to us or your legal counsel.
Frequently asked questions
When did the Swedish Cybersecurity Act enter into force?
The Cybersecurity Act (2025:1506) entered into force on 15 January 2026, replacing the old act (2018:1174).
Who is covered by the Swedish Cybersecurity Act?
Swedish central government agencies, regions and municipalities, as well as operators in the NIS2 sectors that are established in Sweden and at least medium-sized. They are classified as essential or important entities.
What is the difference between an essential and an important entity?
The classification determines the intensity of supervision and the maximum penalty fees. Essential entities (e.g. government agencies and larger operators in the most critical sectors) face stricter proactive supervision and higher fee caps than important entities.
How large can the penalty fees be?
From SEK 5,000 up to the higher of 2% of global turnover or €10 million for essential entities, and 1.4% or €7 million for important private entities. For public-sector entities, up to SEK 10 million.
How quickly must incidents be reported?
An early warning must be submitted as soon as possible and no later than within 24 hours, an incident notification within 72 hours (24 hours for trust services) and a final report no later than one month after the notification.
// Primary sources
- Cybersecurity Act (2025:1506) — Riksdagen/SFS (in Swedish) ↗
- Government bill 2025/26:28 (in Swedish) ↗
- The NIS2 Directive (EU) 2022/2555 — EUR-Lex ↗
Last fact-checked: 2026-06-02.
// More laws
Need help complying with Cybersecurity Act?
We build secure, compliant solutions and help you map exactly what applies to your organisation.