Cybersecurity 2026

SWEDEN Law and Practice Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå AB

1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy Sweden’s approach to cybersecurity regulation has historically been sector-based, with rules and super - visory arrangements adapted to the risks and condi - tions in different parts of society. This has enabled targeted requirements for specific sectors, while plac - ing clear responsibilities on both public and private actors. Against a deteriorating security environment and rap - idly increasing digital dependence, Sweden has now sharpened its national direction through the National Cybersecurity Strategy 2025–2029. The govern - ment’s vision is a resilient Sweden with a high level of cybersecurity, where societal vital services can be maintained even during cybersecurity incidents. The strategy is explicitly grounded in national needs and the NIS2 “all-hazards/all-risk” perspective, and it is accompanied by an action plan that is intended to be updated over time. In line with the strategy, Sweden’s cybersecurity efforts are organised around three pillars: • systematic and effective cybersecurity work; • strengthened knowledge and skills development; and • improved capability to prevent and manage cyber - security incidents. This direction is designed to strengthen prevention, resilience and incident-handling capacity across soci - ety, and it is intended to be mutually reinforcing with Sweden’s broader foreign- and security-policy work on cyber and digital issues. Overall, Sweden also emphasises co-operation with international partners, particularly in the EU and through security-policy co- operation such as NATO, to better address transna - tional threats while safeguarding Swedish security interests. 1.2 Cybersecurity Laws The Electronic Communications Act (Sw. Lag (2022:482) om elektronisk kommunikation ) and the Electronic Communications Regulation (Sw. Förordn-

ing (2022:511) o m elektronisk kommunikation ) trans - pose the Directive of the European Parliament and of the Council (2018/1972) of 11 December 2018 establishing the European Electronic Communica - tions Code (recast). The act and the regulation regu - late electronic communications, with a focus on the security and integrity of networks and services. The act covers entities providing electronic communica - tions networks or services within Sweden. The Elec - tric Communications Act is supplemented by binding Swedish delegated regulations. The Accounting Act (Sw. Bokföringslagen (1999:1078)) contains provisions on the secure handling and stor - age of financial data, which is crucial for cybersecurity in financial reporting. The act applies to natural and legal persons who are bookkeeping-obligated in Swe - den. A legally significant role is played by the Swed - ish generally accepted accounting practice (Sw: god redovisningssed ), which is a binding legal standard. The Camera Surveillance Act (Sw. Kamerabevakning- slagen (2018:1200)) regulates camera surveillance, balancing security needs with privacy rights, and ensuring that surveillance systems are secure against unauthorised access. The act applies where camera surveillance is carried out with equipment located in Sweden. The Protective Security Act (Sw. Säkerhetsskyddsla- gen (2018:585)) and the Protective Security Regula - tion (Sw. Säkerhetsskyddsförordningen (2021:955)) focus on protective security, and require organisations to protect information that concerns security-sensitive activities from cyber threats, thus playing an important role in the broader cybersecurity framework. It applies to any public or private operator conducting activities that are important to Sweden’s security or that are covered by an international security protection com - mitment binding on Sweden, and is supplemented by binding delegated regulations. The Swedish Cybersecurity Act (Sw. Cybersäkerhet- slagen (2025:1506)) – not to be confused with the EU Cybersecurity act, which is mentioned further below – transposes the NIS2 Directive (Directive (EU) 2022/2555). It establishes a NIS2-aligned national framework to achieve a high level of cybersecurity.

354 CHAMBERS.COM

Powered by