Law / Sweden

Cybersäkerhetslag, Incident Notification

Cybersäkerhetslag (2025:1506), 2 kap. 5-10 §§

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 8 months, effective 15 January 2026.

A vulnerability and incident reporting rule binding public and private bodies.

As of 15 September 2026.

What it requires

  • This binds a väsentlig (essential) or viktig (important) verksamhetsutövare under a medium-or-large size gate; Chapter 1 §7(1) names a provider of cloud services, data-centre services, content-delivery networks, outsourced operational or security services, an online marketplace, a search engine or a social-networking-platform service among the digital providers the Act reaches, for the reason given on this jurisdiction's companion risk-management row.
  • Inform the authority the government designates (in practice the CSIRT-enhet at Försvarets radioanstalt) of a significant incident as soon as you can, and no later than 24 hours after becoming aware of it.
  • Follow with a formal incident notification to the same authority as soon as you can; if you provide a trust service, no later than 24 hours after becoming aware, and otherwise no later than 72 hours after becoming aware.
  • On the authority's request, submit an interim report with relevant status updates on the significant incident.
  • No later than one month after your incident notification, submit a final report; if the significant incident is still ongoing at that point, submit a progress report instead and a final report within one month after you have resolved it.
  • Where appropriate, inform your service recipients, as soon as you can, of a significant incident likely to adversely affect the service you provide to them.
  • For a significant cyber threat, inform affected service recipients, as soon as you can, of the protective and remedial measures they can take, and, where appropriate, of the threat itself.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Chapter 4 §9's sanktionsavgift (sanction fee) for a failure to notify, drawn from Chapter 4 §1 read with Chapter 2 §§5-8, is an administrative fine a tillsynsmyndighet imposes directly, appealable to the allmän förvaltningsdomstol under Chapter 5 §1; no provision reviewed here makes a missed or false notification a criminal offence.

Penalty structure

Chapter 4 §10(1) sets the essential-entity ceiling at the higher of 2 percent of the entity's total global turnover for the preceding financial year or an amount in kronor equivalent to EUR 10,000,000; §10(2) sets the important-entity ceiling at the higher of 1.4 percent or an amount in kronor equivalent to EUR 7,000,000, mirroring NIS2 Article 34(4)-(5). Both figures are for a private operator (enskild verksamhetsutövare); §10(3) instead fixes a flat SEK 10,000,000 cap, with no turnover component, for a public-sector operator (offentlig verksamhetsutövare), and the statutory floor for any sanktionsavgift is SEK 5,000.

Rule
Higher of
As of
15 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Notification itself is submitted to Försvarets radioanstalt (FRA), acting as the CSIRT-enhet under Cybersäkerhetsförordning (2025:1507) 6 § and 31 §; a sanction for a failure to notify is imposed by the sector's own tillsynsmyndighet under Cybersäkerhetslag (2025:1506) Chapter 3-4, which for the 'Digital infrastruktur' / 'Digitala leverantörer' (Digital infrastructure / Digital providers) sector, an online marketplace, search engine or social-networking-platform provider, is Post- och telestyrelsen (PTS) per Cybersäkerhetsförordning 7 §.

Settledness

As of
15 September 2026
Guidance link
https://www.ncsc.se/sv/radgivning-och-stod/cybersakerhetslagen-nis2/tidsplan-for-inforandet-av-cybersakerhetslagen-i-sverige/
Guidance body
Nationellt cybersäkerhetscenter (NCSC), Försvarets radioanstalt (FRA)
Open questions
Given that Cybersäkerhetsförordning (2025:1507) 37 § 2 lets Post- och telestyrelsen further define what counts as a betydande incident (significant incident) for its own tillsynsområden, has PTS issued a regulation under that power that sets a threshold specific to a digital provider's own incidents?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Chapter 2 §5 requires a väsentlig or viktig verksamhetsutövare to inform the designated authority of a significant incident (betydande incident) as soon as it can and no later than 24 hours after becoming aware of it; an incident is significant if it has caused or could cause serious operational disruption or financial loss, or has affected or could affect other persons by causing significant harm.

Chapter 2 §6 requires the operator to follow with a formal incident notification, within 24 hours of awareness for a trust service provider and within 72 hours for others; §7 requires an interim status report on the authority's request, and §8 requires a final report within one month of the notification, or a progress report followed by a final report within a month of resolution if the incident is still ongoing.

Chapter 2 §9-10 add duties to inform affected service recipients, where appropriate, of a significant incident and of protective measures against a significant cyber threat. This is NIS2 Article 23's own clock; Cybersäkerhetsförordning (2025:1507) 6 § routes the notification itself to Försvarets radioanstalt acting as the CSIRT-enhet.

When LexLint raises it

  • operates_social_platform

Read the law

Cybersäkerhetslag (2025:1506), Svensk författningssamling, Sveriges riksdag, Chapter 2

Back to the example  ·  Lint your app