Sweden transposed NIS2 through the Cybersäkerhetslag (2025:1506, the Cybersecurity Act), issued by the government on 11 December 2025 and in force since 15 January 2026, which outright repealed the earlier lag (2018:1174) om informationssäkerhet för samhällsviktiga och digitala tjänster, Sweden's NIS1 transposition; a companion Cybersäkerhetsförordning (2025:1507) sets sector-specific supervisory authorities and, as amended, designates Försvarets radioanstalt (FRA), through its Nationellt cybersäkerhetscenter (NCSC), as the single point of contact, the CSIRT unit and the cyber crisis management authority, a role the government decided on 20 November 2025 to transfer to FRA from Myndigheten för samhällsskydd och beredskap (MSB) effective 1 July 2026.
The Law binds a väsentlig (essential) or viktig (important) verksamhetsutövare (operator) by sector and, for most sectors, a medium-or-large size gate (Chapter 1 §§3-9); Chapter 1 §7(1) names a provider of cloud services, data-centre services, content-delivery networks, outsourced operational or security services, an online marketplace, a search engine, or a social-networking-platform service among the digital providers the Act reaches, and the catch-all rule in §9 classifies such a provider as important rather than essential absent a further ground.
The Law also binds certain state authorities, regions, municipalities and kommunalförbund directly (Chapter 1 §3), so it reaches a government duty-bearer as well as a private one, while Chapter 1 §12 carves out an authority whose activity is predominantly security-classified under säkerhetsskyddslagen (2018:585) or predominantly law-enforcement, and Chapter 1 §11 exempts a financial entity already covered by Regulation (EU) 2022/2554 (DORA) from the Law's own Chapter 2 §§3-10 duties.
Chapter 2 §3 sets the core risk-management duty (appropriate and proportionate technical, operational and organisational measures on an all-hazards basis) and §4 requires management-level training; Chapter 2 §§5-8 set NIS2's own graduated significant-incident notification clock to the designated authority (a 24-hour early warning, a 72-hour initial report, or 24 hours for a trust service provider, and a one-month final report), which Cybersäkerhetsförordning (2025:1507) 6 § routes to Försvarets radioanstalt acting as the CSIRT-enhet.
Chapter 4 §§9-10 set NIS2's own two-tier administrative sanktionsavgift (sanction fee): up to the higher of 2 percent of an entity's global turnover or a kronor amount equivalent to EUR 10,000,000 for an essential private operator, up to the higher of 1.4 percent or an equivalent of EUR 7,000,000 for an important one, and a flat SEK 10,000,000 with no turnover component for a public-sector operator, imposed by the sector's own tillsynsmyndighet (supervisory authority) under Chapter 3-4, with no criminal offence and no private right of action; Cybersäkerhetsförordning (2025:1507) 7 § names Post- och telestyrelsen (PTS, the Swedish Post and Telecom Authority) as the tillsynsmyndighet for the 'Digital infrastructure' / 'Digital providers' sector, so PTS supervises an online marketplace, search engine or social-networking-platform provider specifically.
No instrument reviewed here sets a product-security or market-placement duty on a manufacturer independent of the directly applicable EU Cyber Resilience Act, which is documented at the European Union level and is not restated here, and Sweden has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation, and Sweden's personal-data breach notification under GDPR Articles 33-34 sits in the privacy topic rather than here.