NIS2 and the Swedish Cybersecurity Act
Cybersecurity requirements for organisations in 18 sectors
NIS2 is the EU directive on cybersecurity for organisations that society depends on, Directive (EU) 2022/2555. A directive does not apply directly. Each member state transposes it into national law. Sweden did so through the Cybersecurity Act (cybersäkerhetslagen, 2025:1506), which entered into force on 15 January 2026.
Who is in scope
The act applies to essential and important entities in 18 sectors, among them energy, transport, banking, health, drinking water, digital infrastructure, public administration, food and manufacturing. That is considerably more sectors than under the earlier NIS Directive.
The National Cyber Security Centre (NCSC) coordinates the work nationally, and each sector has one or more supervisory authorities. The NCSC pages under References describe which organisations are in scope.
What the act requires
An organisation in scope must:
- identify that it is in scope and register
- run systematic cybersecurity work and take appropriate measures
- train management and staff
- report incidents that cause significant disruption
Under the directive, a significant incident is reported in three steps: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month.
NIS2 and SBOM
NIS2 does not mention SBOM. Article 21 of the directive does list risk management measures that an SBOM is used for in practice:
- Supply chain security. The organisation must handle security in its relationships with suppliers. An SBOM from the supplier shows which components a delivered piece of software contains.
- Security in the acquisition, development and maintenance of systems, including vulnerability handling. An SBOM makes it possible to monitor known vulnerabilities in the components, in software you build and in software you buy.
- Incident handling. When a vulnerability in a component is being exploited, the SBOMs show which systems contain it.
SBOM in public procurement describes how SBOM requirements can be put to suppliers.
The difference from the CRA
NIS2 sets requirements for organisations. The Cyber Resilience Act (CRA) sets requirements for products and for those who manufacture them. An organisation can be covered by both: by NIS2 as an entity, and by the CRA as the manufacturer of a product with digital elements.
References
- NCSC: Det här är cybersäkerhetslagenncsc.se
The Swedish National Cyber Security Centre's overview of the Cybersecurity Act and its obligations (in Swedish).
- NCSC: Cybersäkerhetslagen för berörda verksamheterncsc.se
Which organisations are in scope and what they need to do (in Swedish).
- NCSC: Tidsplan för införandet av cybersäkerhetslagen i Sverigencsc.se
The timeline for introducing the act (in Swedish).