SWEDEN Law and Practice Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå AB
2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation The Swedish Cybersecurity Act Sweden’s primary cybersecurity framework for essen - tial and critical entities is the Swedish Cybersecurity Act, which entered into force on 15 January 2026, together with the accompanying Cybersecurity Regu - lation and implements the NIS2 Directive (Directive (EU) 2022/2555, (NIS2)). The Swedish Cybersecurity Act also repealed Sweden’s prior NIS implementation, Information Security for Critical and Digital Services Act (Sw. Lag (2018:1174) om informationssäkerhet för samhällsviktiga och digitala tjänster ). Public Sector Entities The Swedish Cybersecurity Act applies to state authorities with decision-making powers affecting rights concerning cross-border movement of per - sons, goods, services or capital, as well as to regions, municipalities and municipal federations. The gov - ernment may designate additional state authorities as covered, and the regulation specifies that state authorities listed in Annex 1 to the Regulation on the preparedness of government agencies (Sw. Förordn- ing (2022:524) om statliga myndigheters beredskap ) are within scope. Private Sector Entities Private entities are covered if they fall within NIS2 Annex I or Annex II, are established in Sweden, and are at least the size of a medium-sized enterprise. Even if the size threshold is not met, an entity meeting the sector and establishment criteria can be covered if it is the sole provider in Sweden of an essential service, if disruption could significantly affect life, health, public security or public health or create significant systemic risk, or if it is of particular national or regional importance for a sector or for other dependent sectors. Providers of trust services are also covered under this provision. The law also applies to providers that in Sweden provide public electronic communications networks or publicly avail - able electronic communications services.
Sectors The private-sector scope is anchored to the sectors and types of entities listed in NIS2 Annex I (sectors of high criticality) and Annex II (other critical sectors). NIS2 Annex I sectors of high criticality include ener - gy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastruc - ture, ICT service management (business-to-business), public administration and space. Annex II other criti - cal sectors include postal and courier services, waste management, manufacture and production of chemi - cals, food production and distribution, manufactur - ing of certain products (medical devices, computers, electronics, machinery, motor vehicles and transport equipment), digital providers, and research. Uncertainties Regarding Scope and Applicability Certain aspects are explicitly left for future supple - mentary rules. The regulation empowers MCF and PTS to issue such supplementary regulations in their respective sectors. So far, only one supplementary regulation on notification and identification has been decided on, with current proposals on incident report - ing and information obligations, and security meas - ures and training out for consultation. 2.2 Critical Infrastructure Cybersecurity Requirements Baseline Risk-Management Entities covered by the Swedish Cybersecurity Act must implement appropriate and proportionate tech - nical, operational and organisational measures to pro - tect the network and information systems they use in their operations and/or to provide their services, and the physical environment supporting those systems, against incidents. The approach is risk-based and aims to create a security level appropriate to the risks Management is expected to ensure the organisation can implement and maintain the required measures. Training is mandatory for persons in the entity’s lead - ership, and entities are encouraged to organise rel - evant training more broadly to support compliance in day-to-day operations. and the entity’s dependencies. Governance and Accountability
358 CHAMBERS.COM
Powered by FlippingBook