# Regulations

> NIS2 and the Swedish Cybersecurity Act, DORA and an overview of which regulations require an SBOM.

URL: https://sbom.se/en/regulations

- [Regulations that require an SBOM](https://sbom.se/en/regulations/overview): The CRA requires an SBOM from manufacturers from 11 December 2027. NIS2 and DORA do not mention SBOM but set requirements that an SBOM is used for. An overview of the regulations in the EU and the US.
- [NIS2 and the Swedish Cybersecurity Act](https://sbom.se/en/regulations/nis2): The NIS2 Directive is implemented in Sweden through the Cybersecurity Act, in force since 15 January 2026. This page covers who is in scope, what the act requires and how SBOM relates to the requirements.
- [DORA](https://sbom.se/en/regulations/dora): DORA has applied since January 2025 and covers most firms supervised by the Swedish financial supervisory authority. This page covers what the regulation governs and how SBOM relates to the requirements.
- [Cybersecurity certification](https://sbom.se/en/regulations/cybersecurity-certification): In November 2024 the Swedish Defence Materiel Administration (FMV) held an information meeting on cybersecurity certification of IT products and IT services. The presentation is listed under References.
