Cybersecurity 2026

SWEDEN Law and Practice Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå AB

Location of Data and Services Contracts must specify data storage and process - ing locations. Financial entities must ensure compli - ance with applicable data protection and localisation requirements. Concentration Risk Management Financial entities must identify and monitor concentra - tion risk arising from contractual arrangements with ICT third-party service providers, assess dependen - cies on critical providers, and implement mitigation measures including diversification strategies where feasible. 3.3 Key Operational Resilience Obligations Objectives DORA is directly applicable in Sweden and is intended to ensure that financial entities can withstand, respond to, and recover from ICT-related disruptions, thereby strengthening operational resilience and continuity of critical services. It also establishes a harmonised EU framework for ICT risk governance and controls across the financial sector, supporting consistent supervisory oversight by competent authorities such as the Swedish Financial Supervisory Authority. Key Obligations Financial entities must implement and maintain an ICT risk management framework with clear governance, defined roles and responsibilities, and management body oversight, supported by appropriate internal controls, continuous monitoring and resilience testing. They must also manage ICT third-party risk by identi - fying dependencies on external ICT service providers, ensuring contractual arrangements support security and resilience expectations, and maintaining required documentation (including a register of ICT third-party arrangements) in accordance with applicable super - visory requirements. Incident and Reporting Obligations Financial entities must detect, manage, and classify ICT-related incidents based on impact and severity, and report major ICT-related incidents to the Swedish Financial Supervisory Authority in line with DORA and the Regulatory Technical Standards (RTS), using the RTS materiality criteria and thresholds (including, for example, criteria relating to affected clients/transac -

in providing the ICT services, the reliance of finan - cial entities, the degree of substitutability and other relevant factors. While the definition of ICT service providers in Sweden is broad, the classification of ser - vices as critical is specific and based on the potential impact on financial operations and stability. Cloud Service Providers Not every cloud service provider will automatically be classified as critical. The criticality of a cloud service provider is assessed based on the same criteria men - tioned above. For instance: • if a cloud service provider supports a significant portion of a financial entity’s operations or hosts critical applications, it may be classified as critical; and • cloud service providers offering infrastructure as a service (IaaS) or platform as a service (PaaS) that are integral to the financial entity’s operations are more likely to be considered critical compared to Financial entities must ensure that contracts with ICT third-party service providers include provisions on subcontracting, requiring the provider to notify the entity of any intended subcontracting and to ensure that subcontractors meet the same informa - tion security standards. Critical ICT third-party service providers must provide information on subcontracting arrangements to the Lead Overseer. Access, Inspection, Audit and Testing Rights Contractual arrangements must grant financial enti - ties, their appointed third parties, and competent authorities full access and audit rights over the ICT third-party service provider’s performance, includ - ing access to data, premises, and personnel. Lead Overseers may conduct on-site inspections at critical providers’ premises. Exit Strategies and Data Portability Contracts must include appropriate termination rights and exit strategies, ensuring orderly transition and secure data retrieval upon contract termination. Finan - cial entities must develop transition plans for critical ICT services. those offering less essential services. Subcontracting and Chain Outsourcing

361 CHAMBERS.COM

Powered by