Skip to content

NIS 2 IN SWEDEN

Cybersäkerhetslagen (SFS 2025:912) — the national act transposing Directive (EU) 2022/2555 in Sweden. Supervised by Myndigheten för cybersäkerhet (MCF).

TRANSPOSED — IN FORCE

Key facts

In force
15 January 2026
National law
Cybersäkerhetslagen (SFS 2025:912)
Primary supervisor
Myndigheten för cybersäkerhet (MCF)
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Covered entities must register with the relevant sector supervisor within three months of becoming subject to the law.

Scope and national nuance

Sweden's transposition explicitly brings municipal entities (kommun) and regional bodies into scope where they operate covered services, alongside the eighteen sectors listed in NIS 2. The Cybersäkerhetsmyndigheten (MCF) was constituted from MSB's former NIS function and took over as primary supervisor when the law entered into force.

Sector supervisors

SectorAuthorityAcronym
EnergyEnergimyndighetenEM
Drinking and waste waterLivsmedelsverketSLV
Banking and financial market infrastructureFinansinspektionenFI
HealthInspektionen för vård och omsorgIVO
TransportTransportstyrelsenTS
Digital infrastructure and ICT service managementPost- och telestyrelsenPTS

What is specific to Sweden

DSI Advisory — NIS 2 Programme

Move from reading the law to evidencing compliance

Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to MCF’s supervisory expectations.

NIS 2 Scorecard →Scope & gap assessment →NIS 2 reference page →