NIS2 is the EU’s main cybersecurity law for organisations that society depends on. In Sweden it is implemented through the Cybersecurity Act (cybersäkerhetslagen), which took effect on 15 January 2026 and replaced the earlier NIS rules. It covers far more sectors and organisations than the regime it replaced, and it places responsibility for cyber risk firmly with management.
Many leadership teams are still unsure whether the law applies to them, and some assume that if it doesn’t, they can ignore it. Both positions are risky. Scope decides what you are legally required to do, and even organisations outside it will feel the requirements through their customers. This guide covers how to work out where you stand, what the law actually asks for and how to use your first 90 days.
Are you in scope?
Scope depends on what you do, how big you are and, in some cases, what kind of organisation you are. Work through the three questions in order.
- Sector: The law covers 18 sectors. Those of high criticality include energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. Other critical sectors include postal and courier services, waste management, chemicals, food, manufacturing of certain products, digital providers and research. Read the descriptions carefully: manufacturing, for example, means specific product categories, not all manufacturing.
- Size: As a rule, small and micro enterprises are outside scope. If you operate in a listed sector and have at least 50 employees, or an annual turnover and balance sheet that both exceed EUR 10 million, you are generally covered. Group structures can affect the calculation, so check how partner and linked companies are counted.
- Type of organisation: Some entities are covered regardless of size, such as certain providers of digital infrastructure. In Sweden, regions, municipalities and municipal associations are covered regardless of size under public administration.
If you are in scope, you are either an essential or an important entity. Essential entities are typically the larger organisations in the high-criticality sectors, plus some specific types of entity. Most other in-scope organisations are important entities. The obligations are broadly the same; the difference lies in supervision. Essential entities are subject to planned, proactive supervision, while important entities are mainly supervised after the fact, for example following an incident or a complaint, and face lower maximum sanctions.
In-scope organisations must register. Registration and incident reporting go through a central national contact point, while supervision is carried out by sector authorities, such as the Swedish Post and Telecom Authority (PTS) for digital infrastructure and the Swedish Transport Agency (Transportstyrelsen) for transport. The responsibility for assessing whether you are covered is yours. Nobody will tell you first.
Out of scope does not mean unaffected
NIS2 requires covered organisations to manage security in their supply chain, including their relationships with direct suppliers and service providers. In practice, that means customers will ask you questions. Expect security questionnaires, contract clauses on incident notification, requests for evidence such as policies or certifications, and audit rights.
For an IT service provider, a component manufacturer or a logistics partner, this indirect effect can matter more than the law itself. Suppliers that answer clearly and quickly, with evidence, are easier to buy from. Those that cannot may lose tenders or face demands they have no plan for. If many of your customers operate in NIS2 sectors, treat their requirements as your own baseline.
What the law requires
The directive is principle-based rather than a detailed checklist, and regulations issued by the supervisory authorities add detail. At a high level, there are four areas every management team should understand.
- Risk-management measures: Appropriate and proportionate technical and organisational measures, based on an all-hazards approach. The minimum list covers risk analysis and security policies, incident handling, business continuity including backup and crisis management, supply-chain security, secure acquisition and development, vulnerability handling, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication where appropriate.
- Incident reporting: Significant incidents are reported in stages: an early warning within 24 hours of becoming aware of the incident, an incident notification within 72 hours and a final report within one month. That pace is only achievable if detection, escalation and decision-making are already in place.
- Management accountability: The management body must approve the risk-management measures, oversee their implementation and can be held responsible when the organisation falls short. Members of management are also required to undergo training, so they can identify risks and judge whether the measures are adequate.
- Supply-chain security: You must consider the vulnerabilities and security practices of your direct suppliers, including how they develop their products and services, and reflect this in how you select, contract and follow them up.
A sensible first 90 days
There is no need to start with a large programme. Start with clarity, then build momentum on the measures that reduce risk and show visible progress.
- Days 1–30, establish scope and ownership: Confirm whether and how you are covered, including which legal entities in the group are in scope and which sector authority supervises you. Register if required. Appoint one accountable owner and brief the management team on what the law expects of them personally.
- Days 31–60, find the gaps: Assess your current controls against the minimum measures, using a recognised framework such as ISO 27001 so the work can be reused. Map your critical services and the systems and suppliers they depend on. Check whether you could actually meet the 24-hour and 72-hour reporting deadlines: who decides that an incident is significant, and who submits the report?
- Days 61–90, plan and start fixing: Turn the gaps into a prioritised roadmap with owners, effort and budget, and have management formally approve it. Start the quick wins straight away, typically multi-factor authentication for all remote and privileged access, tested backups and an updated incident response plan. Schedule management training and a short exercise based on a realistic incident.
After 90 days you should be able to show a supervisor, a customer or your own board that you know where you stand and have a credible plan. That is a far stronger position than a perfect set of policies that nobody follows.
Common pitfalls
- Treating it as an IT project: The law is addressed to the organisation and its management. If accountability sits only with the IT manager, one of the central requirements is already missed.
- Writing policies before understanding risk: Documents copied from templates do not hold up for long. Controls should follow from the risks to the services you actually deliver.
- Running a separate track for every regulation: If DORA, GDPR or ISO 27001 also apply to you, map the requirements to one control set and collect evidence once.
- Forgetting the suppliers: Your managed service provider, cloud platforms and software vendors are part of your attack surface. Start with the few that matter most.
How Altechy can help
Our NIS2 Readiness Check is a fixed-scope, four-week assessment within our Security Strategy, Risk & Compliance service. It confirms whether and how NIS2 applies to you, maps your gaps against the risk-management measures and gives you a prioritised remediation plan, together with a briefing on what the law expects of management. If incident reporting is your weak point, our Incident Response & Cyber Recovery specialists can help you build and rehearse the process.
Would you rather talk it through first? Book a free 60-minute idea session and we will help you work out where to start.
