NIS2 in Sweden
Sweden's Cybersäkerhetslagen (SFS 2025:1506) entered into force on 15 January 2026, over a year after the EU deadline. MSB coordinates, issuing sector-specific binding regulations.
Key Deadlines
Competent Authority
Sweden distributes supervision across sector authorities. MSB (Swedish Civil Contingencies Agency) handles broad coordination; MSBFS issues binding regulations per sector. Entities must self-register with their relevant sector authority.
Registration Process
Register via the competent authority for your sector. Most entities use the MSB registration portal at msb.se/nis2. You will need your Swedish organisation number (organisationsnummer) and sector classification.
Find out if your company is in scope
Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?
Key Requirements
- 1Self-registration with the relevant sector competent authority
- 2Incident reporting within 24 hours (early warning) and 72 hours (full notification) to NCSC-SE
- 3Implementation of MSBFS 2024:x security measures (based on NIST CSF and ISO 27001)
- 4Annual internal audit of cybersecurity measures
- 5Management accountability: board must receive annual cybersecurity training
- 6Supply chain risk management programme
- 7Encryption and key management requirements
National Additions
FAQ: NIS2 in Sweden
Which Swedish authority is responsible for my sector?
Are Swedish fines capped in SEK or EUR?
Ready to assess your NIS2 compliance?
Use our free tools to check your NIS2 scope and run a gap assessment.
Currency and sources
The legal details on this page were last checked on 25 July 2026. Some details rest on a single secondary source and are not verified against the national authority or official journal. Confirm with the competent authority before relying on them for a compliance decision.