Law / Sweden

Cybersäkerhetslag, Cybersecurity Risk-Management Measures

Cybersäkerhetslag (2025:1506), 2 kap. 3-4 §§

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 8 months, effective 15 January 2026.

A sector security regimes rule binding public and private bodies.

As of 15 September 2026.

What it requires

  • This binds a väsentlig (essential) or viktig (important) verksamhetsutövare under a medium-or-large size gate; Chapter 1 §7(1) names a provider of cloud services, data-centre services, content-delivery networks, outsourced operational or security services, an online marketplace, a search engine or a social-networking-platform service among the digital providers the Act reaches, classified as important rather than essential absent a further ground under §9; the wider sector classes the Act also reaches (energy, transport, banking, health, drinking water, wastewater, public administration, top-level domain (TLD) registries and DNS providers) are a designation and sector class no activity in this vocabulary expresses, so they are not separately flagged here.
  • Take appropriate and proportionate technical, operational and organisational measures, on an all-hazards basis, to protect the network and information systems you use for your operations or to provide your services, and their physical environment, against an incident, at minimum covering risk-analysis strategy, incident handling, business continuity and crisis management, supply-chain security, security in system acquisition/development/maintenance, effectiveness-assessment procedures, basic cyber hygiene and staff training, cryptography and encryption policies, personnel security, access control and asset management, and, where relevant, authentication, secure communications and secure emergency-communication systems.
  • Have the individuals in your management undergo training on these security measures.
  • Register with the authority the government designates as soon as you can, per Cybersäkerhetsförordning (2025:1507) 5 §, and notify a change in what you registered within 14 days of the change.
  • Where you are a financial entity already covered by Regulation (EU) 2022/2554 (DORA), expect this duty to give way to that regime's own risk-management rules under Chapter 1 §11.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Chapter 4 §9's sanktionsavgift (sanction fee) is an administrative fine a tillsynsmyndighet imposes directly, appealable to the allmän förvaltningsdomstol (general administrative court) under Chapter 5 §1; no provision reviewed here makes a failure to take the Chapter 2 §3 measures, or to train under §4, a criminal offence.

Penalty structure

Chapter 4 §10(1) sets the essential-entity ceiling at the higher of 2 percent of the entity's total global turnover for the preceding financial year or an amount in kronor equivalent to EUR 10,000,000; §10(2) sets the important-entity ceiling at the higher of 1.4 percent or an amount in kronor equivalent to EUR 7,000,000, mirroring NIS2 Article 34(4)-(5). Both figures are for a private operator (enskild verksamhetsutövare); §10(3) instead fixes a flat SEK 10,000,000 cap, with no turnover component, for a public-sector operator (offentlig verksamhetsutövare), and the statutory floor for any sanktionsavgift is SEK 5,000.

Rule
Higher of
As of
15 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Split by sector under Cybersäkerhetsförordning (2025:1507) 7-15 §§: for the 'Digital infrastruktur' / 'Digitala leverantörer' (Digital infrastructure / Digital providers) sector, which is where an online marketplace, search engine or social-networking-platform provider is supervised, Post- och telestyrelsen (PTS, the Swedish Post and Telecom Authority) is the competent tillsynsmyndighet (supervisory authority) under Cybersäkerhetslag (2025:1506) Chapter 3; other sectors (energy, transport, banking, health, food and water, public administration, chemicals and manufacturing, and space) are supervised by a different named authority in the same table.

Settledness

As of
15 September 2026
Guidance link
https://www.ncsc.se/sv/radgivning-och-stod/cybersakerhetslagen-nis2/tidsplan-for-inforandet-av-cybersakerhetslagen-i-sverige/
Guidance body
Nationellt cybersäkerhetscenter (NCSC), Försvarets radioanstalt (FRA)
Open questions
Given that Cybersäkerhetsförordning (2025:1507) 37 § 1 lets Post- och telestyrelsen issue further security-measures regulations for its own tillsynsområden, has PTS issued a regulation under that power that sets requirements specific to an online marketplace, search engine or social-networking-platform provider it supervises as a digital provider?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Chapter 2 §3 requires a väsentlig (essential) or viktig (important) verksamhetsutövare (operator) to take appropriate and proportionate technical, operational and organisational measures, on an all-hazards basis, to protect the network and information systems it uses for its operations or to provide its services, and their physical environment, against an incident, covering at minimum risk-analysis strategy, incident handling, business continuity and crisis management, supply-chain security, security in system acquisition and development, effectiveness assessment, cyber hygiene and staff training, cryptography, personnel security and access control, and, where relevant, authentication and secure communications.

Chapter 1 §7(1) names a provider of cloud services, data-centre services, content-delivery networks, outsourced operational or security services, an online marketplace, a search engine or a social-networking-platform service expressly among the digital providers this duty reaches, classified as important under the Chapter 1 §9 catch-all absent a further ground.

Chapter 2 §4 additionally requires the operator's management to undergo training on these measures, and Chapter 2 §2 requires the operator to register with the designated authority. Chapter 1 §11 exempts a financial entity already covered by Regulation (EU) 2022/2554 (DORA) from this duty.

When LexLint raises it

  • operates_social_platform

Read the law

Cybersäkerhetslag (2025:1506), Svensk författningssamling, Sveriges riksdag, Chapters 1-2

Back to the example  ·  Lint your app