Free tool · Swedish Cybersecurity Act
Does the Swedish Cybersecurity Act (NIS2) apply to you?
In short
The Swedish Cybersecurity Act (cybersäkerhetslagen, SFS 2025:1506) has applied since 15 January 2026 and transposes NIS2 in Sweden. You are generally in scope if you operate in one of its 18 sectors and are at least medium-sized: 50 or more employees, or more than EUR 10 million in both turnover and balance sheet. Some entities, such as DNS providers, trust service providers, telecom operators and public bodies, are covered regardless of size. Answer three questions below for an indicative assessment.
Last reviewed: September 2026
- Sector
- Size
- Exemptions
- Result
Who is covered by the Swedish Cybersecurity Act?
The Act covers entities in 18 sectors across two annexes. Annex I holds the sectors of high criticality: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, B2B ICT service management, public administration and space. Annex II holds other critical sectors: postal and courier services, waste management, chemicals, food, certain manufacturing, digital providers and research.
For SMBs the sector that most often surprises is ICT service management: managed IT operations, hosting and security services sold to other companies count. An IT consultancy with 50 employees that runs customer environments is therefore normally an important entity.
The size thresholds
The main rule is that medium-sized and large enterprises in the listed sectors are in scope. Size follows the EU SME definition, counting the whole group.
- Medium-sized: at least 50 employees, or both turnover and balance sheet above EUR 10 million.
- Large: at least 250 employees, or turnover above EUR 50 million and balance sheet above EUR 43 million.
- Below these thresholds you are normally out of scope — except DNS and TLD providers, qualified trust services, public electronic communications networks and services, public bodies and sole providers of services essential for society.
Essential or important entity
Large enterprises in Annex I sectors are essential. Medium-sized enterprises in Annex I and medium or large enterprises in Annex II are important. The difference is mainly supervision and sanctions: essential entities get planned supervision, important entities get reactive supervision. Day-to-day duties are largely the same.
What applies and when
- 15 January 2026: the Act and ordinance entered into force.
- 2 February 2026: the regulations on registration and identification took effect and the registration service opened. Entities register with the supervisory authority for their sector, for example the Swedish Post and Telecom Authority (PTS) for digital infrastructure and ICT services.
- 1 July 2026: incident-reporting regulations took effect — early warning within 24 hours, incident notification within 72 hours and a final report within one month.
- 1 October 2026: regulations on security measures, management training, security audits and security scanning take effect.
You are out of scope — but your customers are not
Entities in scope must manage security risks in their supply chains. In practice, a 200-employee entity sends a security annex or supplier questionnaire to its 20-employee supplier. That is how the requirements reach most small companies: not through the supervisory authority but through the contract. A structured information security management system, usually ISO 27001, is the most common way to be able to say yes.
Frequently asked questions
- Does the Swedish Cybersecurity Act apply to us?
- Generally yes if you provide services in one of the 18 listed sectors and are at least a medium-sized enterprise: 50 or more employees, or more than EUR 10 million in both turnover and balance sheet. DNS providers, qualified trust services, telecom operators and public bodies are covered regardless of size. The tool above gives an indicative assessment in a minute.
- What size thresholds apply to NIS2 in Sweden?
- The same as in the NIS2 Directive: the EU SME definition. Medium-sized is at least 50 employees or more than EUR 10 million in both turnover and balance sheet; large is at least 250 employees or more than EUR 50 million turnover and EUR 43 million balance sheet. The whole group counts.
- What is the difference between an essential and an important entity?
- Essential entities are large enterprises in sectors of high criticality plus certain specifically designated services. They get planned supervision and higher fines. Important entities get reactive supervision. Duties on risk management, incident reporting and management accountability are essentially the same.
- We supply a company that is in scope — are we affected?
- In practice, yes. Entities in scope must manage supply-chain security risk and therefore impose requirements on suppliers through contracts, security annexes and supplier assessments. You need to be able to show policies, risk analysis, an incident routine and access control — often in the form of an ISO 27001 management system.
- What must we do if we are in scope?
- Register with the supervisory authority for your sector, implement risk-management measures under the regulations applying from 1 October 2026, train management, report significant incidents within 24 and 72 hours, and be able to show the measures work under supervision.
- Do we need ISO 27001 certification to comply with NIS2?
- No, the Act does not require certification. But the NIS2 risk-management measures overlap heavily with ISO 27001, and a certificate is the evidence customers and supervisory authorities accept most readily. Many companies use ISO 27001 as the framework to meet the Act and answer customer requirements with the same material.
Primary sources
Read next
Ready to take control of compliance with requirements?
Try Isodora in practice – see how AI agents help you from documents to certification-ready.