Checked on September 27, 2026

NIS2 in Sweden

How Sweden applies the NIS2 cybersecurity directive: the national law, who supervises, and how to register and report incidents.

Transposition status
In force
National law
Cybersecurity Act (2025:1506) and Cybersecurity Ordinance (2025:1507) · Cybersäkerhetslag (2025:1506) · from January 15, 2026
National CSIRT
CERT-SE (within NCSC)
Registration
Required

Registration (anmälan) under MCFFS 2026:1 opened 2 Feb 2026 on MCF's portal; since 1 Jul 2026 registrations go to FRA as single point of contact.

Incident reporting
Significant incidents to NCSC/CERT-SE via Cyberportal (cyberportal.ncsc.se, since 1 Jul 2026): initial report, update within 72h, final report within 1 month (MCFFS 2026:8).
National specifics
  • MCF's cyber functions transferred to NCSC at FRA on 1 Jul 2026.

Where does your company stand?

The free assessment applies these national rules to your answers and scores every area of the law.

Sources

National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.

NIS2 in other countries

NIS2 in Sweden: national law, authority and registration | Parendum