NIS2 in Sweden — the Cybersäkerhetslagen in force, and an authority that moved mid-regime.
Sweden's Cybersäkerhetslagen (SFS 2025:1506) passed the Riksdag on 10 December 2025 and entered into force on 15 January 2026, with the registration portal opening on 2 February 2026. Supervision is sectoral — each sector answers to its own supervisory authority under the law — with national coordination first held by the MSB, the civil-contingencies agency.
Then the structure moved underneath a running regime: on 1 July 2026, national coordination transferred to a National Cyber Security Centre seated at the FRA — Sweden's signals-intelligence agency — and the MSB was renamed the MCF. Entities that mapped their supervisory relationships in January have had to redraw them once already.
Who it applies to
Essential and important entities across the NIS2 sectors, supervised sectorally under the Cybersäkerhetslagen, with the NCSC at the FRA holding national coordination since 1 July 2026. Registration runs through the national portal that opened on 2 February 2026; entities crossing thresholds later register without delay. Incident reporting follows the directive's three stages — 24 hours, 72 hours, one month.
The clock
Competent authority: NCSC Sweden (at FRA) for coordination, with sectoral supervisory authorities. Transposition: Cybersäkerhetslagen (SFS 2025:1506).
| When | What happens |
|---|---|
| 10 Dec 2025 | Riksdag adopts the Cybersäkerhetslagen (SFS 2025:1506) |
| 15 Jan 2026 | Law enters into force · obligations apply |
| 2 Feb 2026 | Registration portal opens |
| 1 Jul 2026 | National coordination moves to the NCSC at the FRA · MSB renamed MCF |
A supervisory map redrawn mid-regime
Most member states set their authority structure once. Sweden has now changed it while the regime runs: the Cybersäkerhetslagen came into force in January 2026 under MSB coordination, and on 1 July 2026 that coordination moved to a National Cyber Security Centre at the FRA — placing national cyber coordination inside the signals-intelligence agency — while the MSB became the MCF. Sectoral supervision continues through each sector's own authority regardless. For entities, the lesson is structural: supervisory facts are records that can change, which is exactly how TruSecure holds them — the coordinator, the sectoral supervisor and the CSIRT routing stored as dated facts on the entity and updated when the state reorganizes, so reports route correctly on the first attempt.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Sweden transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register through the national portal | Entity profile · classification, sector and supervisor held as records |
| Identify your sectoral supervisory authority | Applicability engine · supervisor resolved by sector, post-1-July structure |
| Meet the security-measures duty with evidence on demand | Control library · continuously monitored, evidence attached |
| Report significant incidents: 24 h, 72 h, one month | Incident workflow · clocked from awareness, routed to CSIRT and supervisor |
| Absorb authority reorganizations without redoing the program | Compliance workspace · supervisory facts as updatable dated records |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Classification
- essential · energy · sectoral supervisor confirmed
- Registration
- national portal · filed 9 Feb 2026
- Coordinator
- NCSC at FRA · record updated 1 Jul 2026
- Controls evidenced
- 78/95 · 17 open, each with an owner and a date
- Export
- sealed · sha256:5c7e...2d9b
Where teams usually start
With a demo walked through by TruSecure — your sectoral supervisor identified under the current structure, the controls you already operate mapped against the Cybersäkerhetslagen, and a sample incident run through the reporting clocks. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Sweden by NCSC Sweden (at FRA) for coordination, with sectoral supervisory authorities. TruSecure determines applicability against Sweden's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.