After years of preparation, it's time to go.The Cybersecurity Act (2025:1506)entered into force on15 January 2026and implements the EU's NIS2 directive (directive (EU) 2022/2555 of 14 December 2022) in Swedish law. At the same time, the old NIS law was repealed from 2018. The difference from before is dramatic: the number of sectors and businesses covered multiplies, the requirements become more detailed, and for the first time personal management responsibility and tangible penalty fees are introduced. This guide goes through what the law requires - and what you concretely need to do in 2026.

Are you covered? Significant and important operators

The big change is the range. The law is based on the sectors listed in the NIS2 Directive's Annex 1 (sectors of high criticality, e.g. energy, transport, banking, healthcare, drinking water, digital infrastructure and public administration) and Annex 2 (other critical sectors, e.g. post, waste management, food production, manufacturing and digital suppliers).

The basic rule is onesize threshold: the law applies to operators in these sectors who are established in Sweden and whoin terms of size corresponds to or is larger than a medium-sized company(according to the EU definition: as a rule at least 50 employees or more than 10 million euros in turnover/balance sheet total). Smaller companies can still be caught in special cases - for example, if they are the only supplier of a socially important service in Sweden, or provide trusted services, DNS services, top-level domains or general electronic communication networks, regardless of size.

The law divides those covered into two classes:

  • Significant operators- i.a. government agencies, major municipalities and regions, businesses in Annex 1 sectors above the size threshold, qualified trusted service providers and DNS and TLD operators.

  • Important operators– others that are covered but not considered essential (typically Annex 2 sectors and medium-sized players).

The difference is not cosmetic: essential actors stand underneathproactive supervision(the authority can audit without suspicion of deficiency), while important actors are mainly auditedreactive- when the supervisory authority has reason to assume that something is not being followed. The penalty caps also differ (see below).

Registration obligation: register with the right authority

One of the most urgent tasks is toreport the activity. The law requires operators to register "as soon as possible". Registration is done via an e-service atThe Authority for Civil Defense (MCF)- the successor to MSB's civil defense duties - whose portal opened on February 2, 2026. The notification states, among other things, sector, classification as essential or important and contact person. If the conditions change, it must be reported no later than 14 days after the change took place.

Which authority is the supervisory authority depends on the sector and is specified in the cyber security regulation and regulations - for different industries sector authorities are singled out (e.g. the Swedish Energy Agency, PTS, the Swedish Transport Agency, the Financial Supervisory Authority and the Swedish Food Agency), with MCF in a coordinating role.

The requirements for risk management: ten areas of action

The heart of the law is the duty to takeappropriate and proportionate technical, operational and organizational security measuresfrom an all-risk perspective. The measures must include at least:

  • Strategies for risk analysis and information systems security

  • Incident management

  • Continuity management and crisis management (incl. backups)

  • Security in the supply chain- also your suppliers and subcontractors

  • Security when acquiring, developing and maintaining systems

  • Routines for assessing the effectiveness of measures

  • Basic cyber hygiene and cyber security training

  • Strategies for cryptography and, where appropriate, encryption

  • Personnel security, access control and asset management

  • If necessary, multi-factor authentication as well as secure communication and emergency communication systems

Note especially the supply chain requirement: the responsibility does not stop at the own IT environment. You need to understand and manage risks with the suppliers you depend on – cloud services, operating partners and system developers.

Incident reporting: 24 hours, 72 hours, one month

The law introduces a clear and pressured timeline forsignificant incidents(incidents that have caused or may cause serious operational disruption, financial damage or significant harm to others). The process looks like this:

  • Within 24 hours- an initial notification ("early warning") to the supervisory authority as soon as possible, but no later than one day after you become aware of the incident.

  • Within 72 hours– a full incident report. (For trusted service providers, 24 hours applies here.)

  • Interim report– status updates at the authority's request.

  • Within a month- a final report after reporting the incident. If the incident is still ongoing, a progress report is submitted, followed by a final report within one month after the incident has been dealt with.

In addition to reporting to the authorities, you may be obliged toinform your customers/usersabout a significant incident affecting the service – and in the case of significant cyber threats inform about protection and countermeasures. Failure to report on time is expressly considered a serious breach.

Board and management responsibility

NIS2 explicitly moves cyber security up to management level, and the Swedish law follows suit.Management must undergo training on security measures.It is no longer something that can be delegated away entirely to the IT department – ​​the management body is expected to understand and be able to assess the risk management measures.

The law also gives the supervisory authority a powerful power: for significant operators, a court can, on the application of the authority,temporarily ban a person from holding a management function(minimum one and maximum three years) in case of serious, repeated violations caused intentionally or by gross negligence. Personal responsibility is thus no longer a theoretical risk.

Supervision and penalty fees

The supervisory authorities are given extensive powers: request information, gain access to premises, carry out security audits (regularly for significant actors, targeted for special reasons for others) and security scans. Injunctions can be combined with a fine.

The financial consequences are significant and are directly stated in the law. A penalty fee is set at a minimum of SEK 5,000 and a maximum of:

  • Significant (individual) operator:the highest of2% of the total global annual turnoverprevious financial year or equivalent10,000,000 euros.

  • Important (individual) operator:the highest of1.4% of global annual turnoveror equivalent7,000,000 euros.

  • Public business operator:up to10,000,000 kroner.

When choosing an intervention, the authority considers the seriousness of the violation, its duration, whether it was intentional and what financial benefit it provided. Decisions are appealed to the general administrative court.

An important demarcation: DORA and safety protection

Not everything is regulated by the Cyber ​​Security Act. Financial actors covered byDORA Regulation (EU 2022/2554)are exempt from the law's security and reporting requirements – DORA applies instead. Correspondingly, special rules apply to activities covered bythe Security Protection Act. If there are other statutes with at least equivalent requirements for safety measures and incident reporting, they may take precedence. It is therefore important to map out exactly which regulations apply to your business.

What you should concretely do in 2026

  • Determine if you are covered– sector (appendix 1/2), size and any special cases. Classify yourselves as essential or important.

  • Report the businessto the right authority via MCF's portal - and keep the information up to date.

  • Conduct a gap analysisagainst the ten action areas and document the current situation.

  • Establish incident procedureswho can handle the 24h/72h/1-month timeline, with clear responsibilities and contact routes.

  • Review the supply chain- set security requirements in agreements with cloud providers and operating partners.

  • Train the managementand anchor cyber security in board work.

For many organisations, this means a proper lifting of both technology, processes and documentation – often starting with a structured analysis of the current situation. At ZORC, we work with secure architecture, robust operation and incident preparedness for digital services. If you want to know what a concrete arrangement could look like for your particular business, you can describe the need inthe quote calculatoror get in touch viacontact- then we help you translate the legal requirements into practical measures.

Does your organization need support with technical information security and NIS2 compliance?See how ZORC helps regulated businesseswith security architecture, penetration tests and documentation that adheres to an oversight.