News
Insight

The Cybersecurity Act — who is covered

NIS2 5

It can still “appear unclear” who the NIS2 Directive’s obligations apply to, according to the government’s investigator. For those covered, the requirements apply to the entire organisation.

The Swedish Civil Contingencies Agency (MSB) and other authorities must now urgently help individual organisations understand whether they are covered by the NIS2 Directive. This is proposed by government investigator Annette Norman in her interim report Nya regler om cybersäkerhet, SOU 2024:18 (regeringen.se). In certain sectors there may be room for interpretation as to which type of operator is actually covered, the investigator notes. It remains to be seen who the government will task with clarifying the application in Sweden. It doesn’t have to be MSB, the agency points out in a response to Seclight.

The NIS2 Directive takes effect on 18 October 2024. By then, EU member states must have adopted national provisions at the latest. In Sweden, this means a new law, the Cybersecurity Act, which may enter into force in August 2025 if the government submits a bill during the spring.

Sweden may go further than the EU requires. The inquiry does not propose more sectors and sub-sectors than the directive, see below. But for those covered, risk management can become extensive.

NIS2 affects the entire organisation. The electricity sub-sector is covered as “essential”, within the energy sector. An electricity company that, in addition to electricity, also does something entirely different must meet the requirements there too. The inquiry finds no limitation in the directive and concludes that the entire organisation is covered. The inquiry points out that the whole company uses the same network and that incidents in one part can affect another part.

Previously, the EU let each country determine the criteria for who would be included within the sectors the EU had designated. Now the EU has a main rule based on size. The NIS2 Directive specifies at least 50 employees or an annual turnover of EUR 10 million.

The authorities — in Sweden, MSB according to the investigator’s proposal — may also designate individual operators regardless of size. The inquiry counts sole traders as well as limited companies, partnerships and associations as operators. They are covered if they meet the size requirement and operate within the EEA in a sector addressed by the directive.

The electricity company in the example above may belong to a group that also owns an entirely different company — which would then also be covered. This applies partly to affiliated companies, in practice within a group, and partly to partner companies, where one owns at least 25 percent of the votes or capital in the other. The inquiry proposes exemptions upon application and decision where grounds exist. One ground could be that, based on an overall assessment in light of the purpose of the law, coverage is not needed. It is not yet any clearer than that.

However, there will be no leniency for those who deliver critical IT, digital signatures and certificates. In that case, the size rule does not apply. Nor does it apply if the organisation is the sole provider of a service in Sweden that is essential, if it concerns critical societal functions and economic functions where a disruption could have a significant impact on life and health, or systemic risks, particularly with cross-border consequences.

For security-sensitive parts of an organisation, there will only be a duty to report, because they are already subject to other legislation that is at least as strict.

The Cybersecurity Act likewise stops there where other rules with equivalent effect already exist, such as for banks, where the Digital Operational Resilience Act (DORA) regulation takes effect on 17 January 2025.

Municipalities and regions are covered, but municipal councils and regional councils are exempted, the inquiry proposes. The majority of all municipalities are already covered by the NIS2 Directive’s requirements, since a large proportion of all municipalities provide home healthcare and all of them meet the size requirement. In sensitive areas, there will only be a duty to report, also for municipalities. But for the part of the operation that is not security-sensitive or related to law enforcement, the Cybersecurity Act should apply in full, the inquiry proposes.

Universities, university colleges and individual education providers authorised to award degrees should be covered by the Cybersecurity Act, the investigator assesses. Around 50 higher education institutions in Sweden, most of them public, hold degree-awarding powers. They do not conduct effective information security work to protect research data, the Swedish National Audit Office (Riksrevisionen) assessed in an audit report in December. This despite regulatory requirements having existed since 2008 and the shortcomings having long been known.

NIS2 covers the sectors of energy (electricity, district heating or district cooling, oil, gas and hydrogen), transport (air, rail, maritime, road), banking, financial market infrastructure, health care, drinking water, wastewater, digital infrastructure, ICT service management (business-to-business), public administration, space, postal and courier services, waste management, manufacturing (medical devices and in particular in vitro devices, computers, electronic goods and optics, electrical equipment, machinery, vehicles and other transport equipment), manufacture and distribution of chemicals, production, processing and distribution of food, manufacturing (of medicinal products), digital providers, and research.

Read more:
The NIS2 Directive — Seclight


Seclight — Together we help companies and organisations find the right level of security and do the right things in the right order.

Contact: David Hässler, +46 8 94 55 99 david.hassler@seclight.com