Skip to main content
NIS2 · SWEDEN

NIS2 in Sweden — the Cybersäkerhetslagen in force, and an authority that moved mid-regime.

Sweden's Cybersäkerhetslagen (SFS 2025:1506) passed the Riksdag on 10 December 2025 and entered into force on 15 January 2026, with the registration portal opening on 2 February 2026. Supervision is sectoral — each sector answers to its own supervisory authority under the law — with national coordination first held by the MSB, the civil-contingencies agency.

Then the structure moved underneath a running regime: on 1 July 2026, national coordination transferred to a National Cyber Security Centre seated at the FRA — Sweden's signals-intelligence agency — and the MSB was renamed the MCF. Entities that mapped their supervisory relationships in January have had to redraw them once already.

Who it applies to

Essential and important entities across the NIS2 sectors, supervised sectorally under the Cybersäkerhetslagen, with the NCSC at the FRA holding national coordination since 1 July 2026. Registration runs through the national portal that opened on 2 February 2026; entities crossing thresholds later register without delay. Incident reporting follows the directive's three stages — 24 hours, 72 hours, one month.

The clock

Competent authority: NCSC Sweden (at FRA) for coordination, with sectoral supervisory authorities. Transposition: Cybersäkerhetslagen (SFS 2025:1506).

NIS2 in Sweden · timeline
WhenWhat happens
10 Dec 2025Riksdag adopts the Cybersäkerhetslagen (SFS 2025:1506)
15 Jan 2026Law enters into force · obligations apply
2 Feb 2026Registration portal opens
1 Jul 2026National coordination moves to the NCSC at the FRA · MSB renamed MCF

A supervisory map redrawn mid-regime

Most member states set their authority structure once. Sweden has now changed it while the regime runs: the Cybersäkerhetslagen came into force in January 2026 under MSB coordination, and on 1 July 2026 that coordination moved to a National Cyber Security Centre at the FRA — placing national cyber coordination inside the signals-intelligence agency — while the MSB became the MCF. Sectoral supervision continues through each sector's own authority regardless. For entities, the lesson is structural: supervisory facts are records that can change, which is exactly how TruSecure holds them — the coordinator, the sectoral supervisor and the CSIRT routing stored as dated facts on the entity and updated when the state reorganizes, so reports route correctly on the first attempt.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Sweden transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Sweden requirements · how TruSecure answers them
What the law asksWhere it is answered
Register through the national portalEntity profile · classification, sector and supervisor held as records
Identify your sectoral supervisory authorityApplicability engine · supervisor resolved by sector, post-1-July structure
Meet the security-measures duty with evidence on demandControl library · continuously monitored, evidence attached
Report significant incidents: 24 h, 72 h, one monthIncident workflow · clocked from awareness, routed to CSIRT and supervisor
Absorb authority reorganizations without redoing the programCompliance workspace · supervisory facts as updatable dated records

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Sweden NIS2 readiness file · excerptSample data
Classification
essential · energy · sectoral supervisor confirmed
Registration
national portal · filed 9 Feb 2026
Coordinator
NCSC at FRA · record updated 1 Jul 2026
Controls evidenced
78/95 · 17 open, each with an owner and a date
Export
sealed · sha256:5c7e...2d9b

Where teams usually start

With a demo walked through by TruSecure — your sectoral supervisor identified under the current structure, the controls you already operate mapped against the Cybersäkerhetslagen, and a sample incident run through the reporting clocks. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Sweden by NCSC Sweden (at FRA) for coordination, with sectoral supervisory authorities. TruSecure determines applicability against Sweden's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Who supervises NIS2 in Sweden?
Since 1 July 2026, national coordination sits with the NCSC at the FRA, while supervision is carried out by sectoral supervisory authorities named in the Cybersäkerhetslagen. The MSB — renamed the MCF — continues with civil-defence preparedness.