NIS2 — Tighter Cyber Requirements for Essential Services
The NIS2 Directive is implemented in Sweden mainly through the Cybersecurity Act and the Cybersecurity Ordinance, which entered into force on 15 January 2026. The Act replaces the previous NIS Directive and covers significantly more public and private operators.
NIS2 aims to create and maintain a high level of security for network and information systems across the EU for essential services and certain digital services. The underlying premise is that reliability and security are essential to the functioning of the economy and society in each member state, as well as the EU's internal market.
Affected companies and organisations must themselves identify and report that they carry out essential activities, conduct systematic, risk-based cybersecurity work, take appropriate technical, operational and organizational security measures, and report significant incidents. Management must undergo training on security measures.
Since 1 July 2026, regulations on incident reporting and information obligations have applied under the Cybersecurity Act and the Cybersecurity Ordinance. On 1 October 2026, regulations on security measures, management training, security audits and security scanning will enter into force.
Since 1 July 2026, the National Defence Radio Establishment (FRA), through the National Cyber Security Centre (NCSC), has served as the single point of contact, the security incident response unit (the national CSIRT, CERT-SE), and the cyber crisis management authority. This responsibility previously lay with the Swedish Agency for Civil Defence (Myndigheten för civilt försvar).
The Cybersecurity Act introduces stricter minimum requirements for operators to take security measures to manage risks to network and information systems. Requirements for operators to report disruptions are being tightened. Anyone who fails to meet the requirements will be subject to sanctions. Cooperation between member states, authorities and other actors is to be facilitated and strengthened. The EU is getting a joint vulnerability register and a European Cyber Crises Liaison Organisation Network (EU-CyCLONe), tasked with managing large-scale cyberattacks. The goal is for the EU to respond more effectively to growing cyber threats.
Who is covered?
NIS2 sets out criteria for assessing whether an operator, referred to in the directive as an "entity," is covered by NIS2. The directive focuses on the size of the operator and the sector in which it operates. Even small companies can be covered if they play a key role in society, the economy, or a relevant sector.
Essential and important entities
Operators are classified as essential or important. Essential entities play a more critical societal role in terms of their activity or size. Large actors operating in a highly critical sector are classified as essential. Medium-sized actors operating in a highly critical or critical sector are classified as important. Each member state must list and regularly report essential and important entities to the EU. Operators are obliged to identify and assess for themselves whether they are covered and to register accordingly.
Highly critical sectors
The following sectors are highly critical under Annex I of the NIS2 Directive.
Wastewater
Management of wastewater from households and industry
Banking
Credit institutions
Digital infrastructure
- Internet service providers
- DNS
- Top-Level Domain (TLD) registries
- Cloud computing services
- Data centres
- Content Delivery Network (CDN)
- Trust Service Providers
- Electronic communications and related services
Information and communication technology
ICT services and security services (business-to-business)
Drinking water
Production and distribution of drinking water
Energy
- Electricity
- District heating and cooling
- Oil
- Gas
- Hydrogen
Financial market infrastructure
Infrastructure for trading financial instruments
Healthcare
- Healthcare providers
- Laboratories
- Research and development of medicinal products
- Manufacturing of basic pharmaceutical products and preparations
- Manufacturing of medical devices that may become critical in a crisis or war
Public administration
- Certain government agencies
- Regions
- Municipalities
- Municipal associations
Space
Ground-based infrastructure
Transport
- Air transport
- Rail transport
- Maritime transport
- Road transport
Critical sector
The following sectors are highly critical under Annex II of the NIS2 Directive.
Waste management
Management of waste
Digital providers
- Online marketplaces
- Search engines
- Social networking platforms
Postal and courier services
Providers of postal and courier services
Food supply
Production, processing and distribution of food
Chemicals
Manufacturing, production and distribution of chemicals
Manufacturing
- Medical devices and in vitro diagnostic medical devices
- Computers, electronic and optical products
- Electrical equipment
- Other machinery
- Motor vehicles, trailers and semi-trailers
- Other transport equipment
Research
Primarily research aimed at commercial application of its results
Tightened requirements
NIS2 tightens the requirements for both essential and important entities. However, the requirements must be proportionate to the size of the entity and to the likelihood and impact of incidents. Entities must take technical, operational and organizational security measures to manage risks to network and information systems. Examples of the requirements imposed include procedures for risk analysis and the security of information systems, incident handling and encryption, and training for management as well as staff. Measures must also be in place to secure supply chains.
Incidents with a significant impact must be reported to the member state's Computer Security Incident Response Team (CSIRT). In Sweden, this is CERT-SE, operating through the NCSC at the National Defence Radio Establishment (FRA). A final incident report must be submitted no later than one month after a significant incident has occurred. FRA is also responsible for national coordination in the event of major cyber incidents and cyber crises, and represents Sweden in the European EU-CyCLONe network.
Supervision
Supervisory authorities are responsible for ensuring that entities meet the requirements. The Cybersecurity Ordinance sets out the supervisory authorities for all sectors. NIS2 sets out detailed requirements regarding the powers supervisory authorities must have and the sanctions they must be able to impose. For essential entities, the powers must be greater, and supervision must be carried out both proactively and reactively. For important entities, supervision is more limited in scope and primarily reactive.
Essential entities that, following supervision, have not implemented the security measures identified may temporarily have, for example, a certification or authorisation for their operations withdrawn. Furthermore, individuals in the management of an essential entity may be temporarily barred from managing the business. Sanctions for essential entities can amount to EUR 10 million or 2 percent of global annual turnover, and for important entities EUR 7 million or 1.4 percent of global annual turnover.
The National Defence Radio Establishment (FRA) is responsible for ensuring that authorities in Sweden supervise NIS2 consistently and effectively. FRA is also responsible for coordination with authorities in other EU countries.
What is the CER Directive?
It is worth knowing that, since 2023, the EU's Directive on the Resilience of Critical Entities (the CER Directive) has applied. The CER Directive is about strengthening the resilience of essential services as a whole, not just the network and information systems regulated under NIS2. Entities covered by the CER Directive must work to prevent, withstand and manage disruptions or outages, regardless of whether the cause is natural disasters, terrorist attacks, pandemics or other serious events. In Sweden, a government commission of inquiry (SOU) has examined how the CER Directive should be transposed into Swedish law. In the summer of 2026, the government submitted a bill to the Riksdag as the basis for a new act and ordinance.