SWEDEN Law and Practice Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå AB
CER Sweden’s implementation of the CER is expected to follow a sector-based supervisory model, aligned with the national structure proposed for NIS2. A sin - gle “common contact point” is to be designated for cross-border co-ordination and liaison at EU level, and MCF is proposed to take that role. Supervision and enforcement are intended to sit with sector com - petent authorities. CRA In Sweden, the official inquiry proposes a comple - mentary national framework in which the Swedish Board for Accreditation and Conformity Assessment (“Swedac”) is designated as the notifying authority responsible for notification/oversight arrangements for conformity assessment bodies. For market sur - veillance, the inquiry proposes that the PTS be des - ignated as the primary market surveillance authority for the CRA. For products that are also classified as high-risk AI systems, the CRA provides that the AI Act market surveillance authorities should carry out the CRA market surveillance tasks for those products. CRA also relies on a national CSIRT function as the recipient of vulnerability and incident reporting flows referenced in the regulation; where MCF is the pro - posed CSIRT in Sweden. DORA The Swedish Financial Supervisory Authority (Sw: Finansinspektionen ) is the supervisory authority that ensures that financial entities comply with DORA. The Swedish Financial Supervisory Authority has super - visory, investigatory and sanctioning powers, including access to documents and data, on-site inspections and investigations, deciding on the conducting of threat- led penetration tests, requiring corrective and remedial measures, cease-and-desist orders, and measures to ensure compliance. DORA provides for co-operation with CSIRTs designated under the NIS 2 Directive (in Sweden: MCF), including consultation, information- sharing, requests for technical advice and assistance, and establishment of co-operation arrangements for fast-response co-ordination. The Cybersecurity Act The ENISA is the key regulator for the Cybersecu - rity Act. ENISA develops cybersecurity certification
frameworks to enhance trust and security in the digital market. Their authority covers ICT products and ser - vices across the EU, promoting a common approach to cybersecurity certification. The Swedish Defence Materiel Administration (Sw: Försvarets materielverk , FMV) is the Swedish cybersecurity certification authority under the Cybersecurity Act, exercising supervisory powers including information requests, on-site inspections, enforcement orders with penalty fines, certificate withdrawal, and administrative sanc - tion fees. The AI Act The AI Act includes security requirements to ensure AI systems are safe and trustworthy, integral to cyberse - curity. Its scope covers AI systems and applications throughout the EU. No supplementary acts have yet been decided in Sweden. However, the Swedish Gov - ernment Official Report proposes a system for market surveillance, market control, governance, and compli - ance monitoring consisting of eleven market control authorities and two notifying authorities. Furthermore, the report proposes that the PTS be given primary responsibility for market control in accordance with PTS is the supervisory authority under the eIDAS, with a mandate to fulfil the supervisory body’s tasks under the eIDAS and related implementing acts and to super - vise compliance with Swedish supplementary legisla - tion. PTS has investigative powers to request infor - mation and documents, and access premises, and may issue enforcement orders and prohibitions with penalty fines to ensure compliance with the eIDAS and Swedish law. The Swedish Agency for Digital Govern - ment (Sw. Myndigheten för digital förvaltning , DIGG) fulfils Sweden’s co-operation obligations and serves as the common contact point for co-operation, and DIGG is responsible for managing security incidents and notifying electronic identification systems. the AI Act. The eIDAS
357 CHAMBERS.COM
Powered by FlippingBook