NIS 2 — Sweden
NIS 2 IN SWEDEN
Cybersäkerhetslagen (SFS 2025:912) — the national act transposing Directive (EU) 2022/2555 in Sweden. Supervised by Myndigheten för cybersäkerhet (MCF).
TRANSPOSED — IN FORCE
Key facts
In force
15 January 2026
National law
Primary supervisor
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Covered entities must register with the relevant sector supervisor within three months of becoming subject to the law.
Scope and national nuance
Sweden's transposition explicitly brings municipal entities (kommun) and regional bodies into scope where they operate covered services, alongside the eighteen sectors listed in NIS 2. The Cybersäkerhetsmyndigheten (MCF) was constituted from MSB's former NIS function and took over as primary supervisor when the law entered into force.
Sector supervisors
| Sector | Authority | Acronym |
|---|---|---|
| Energy | Energimyndigheten | EM |
| Drinking and waste water | Livsmedelsverket | SLV |
| Banking and financial market infrastructure | Finansinspektionen | FI |
| Health | Inspektionen för vård och omsorg | IVO |
| Transport | Transportstyrelsen | TS |
| Digital infrastructure and ICT service management | Post- och telestyrelsen | PTS |
What is specific to Sweden
- Supervisory function was carved out of MSB and given to a new dedicated agency, MCF — entities previously dealing with MSB on NIS 1 now route through MCF.
- Sector supervisors retain operational tillsyn — energy entities are supervised by Energimyndigheten, water by Livsmedelsverket, telecom and digital infrastructure by PTS — coordinated by MCF.
- Incident reporting goes through the sector supervisor and is forwarded to CERT-SE; the 24-hour early warning and 72-hour notification follow the directive verbatim.
- Public administration entities, including municipalities, are explicitly in scope where they deliver covered services — a wider net than several other member states.
DSI Advisory — NIS 2 Programme
Move from reading the law to evidencing compliance
Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to MCF’s supervisory expectations.