Checked on September 27, 2026
NIS2 in Sweden
How Sweden applies the NIS2 cybersecurity directive: the national law, who supervises, and how to register and report incidents.
- Transposition status
- In force
- National law
- Cybersecurity Act (2025:1506) and Cybersecurity Ordinance (2025:1507) · Cybersäkerhetslag (2025:1506) · from January 15, 2026
- National CSIRT
- CERT-SE (within NCSC)
- Registration
- Required
Registration (anmälan) under MCFFS 2026:1 opened 2 Feb 2026 on MCF's portal; since 1 Jul 2026 registrations go to FRA as single point of contact.
- Incident reporting
- Significant incidents to NCSC/CERT-SE via Cyberportal (cyberportal.ncsc.se, since 1 Jul 2026): initial report, update within 72h, final report within 1 month (MCFFS 2026:8).
- National specifics
- MCF's cyber functions transferred to NCSC at FRA on 1 Jul 2026.
Where does your company stand?
The free assessment applies these national rules to your answers and scores every area of the law.
Sources
- www.ncsc.se/sv/radgivning-och-stod/cybersakerhetslagen-nis2/incidentrapportering-enligt-cybersakerhetslagen/
- www.mcf.se/sv/aktuellt/nyheter/2026/juni/cyberverksamheten-samlas-hos-fra--overgang-till-nationellt-cybersakerhetscenter-den-1-juli-2026/
- www.mcf.se/sv/amnesomraden/informationssakerhet-och-cybersakerhet/krav-och-regler-inom-informationssakerhet-och-cybersakerhet/nis-direktivet/cybersakerhetslagen-nis2/att-anmala-en-verksamhet/
- lagen.nu/mcffs/2026:1
- www.mondaq.com/data-protection/1846810/cybers%C3%A4kerhetslagen-senaste-nytt-efter-sommaren
National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.