SWEDEN Law and Practice Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå AB
ish Central Bank, share responsibilities for the TLPT process. The Swedish Financial Supervisory Authority determines which entities must undergo testing and the frequency of tests, while the Swedish Central Bank co-ordinates and monitors the tests, ensuring compli - ance and certifying that the tests meet the required standards. Selection of entities to undergo testing is based on the extent to which their services impact the financial sector, potential financial stability concerns (including systemic character at Union or national lev - el), and specific ICT risk profile, level of ICT maturity, or technology features involved. Microenterprises are excluded from advanced testing requirements. Testers must be of the highest suitability and repu - tability; possess technical and organisational capa - bilities demonstrating expertise in threat intelligence, penetration testing and red team testing; be certified by an accreditation body or adhere to formal codes of conduct; provide independent assurance on sound risk management; and be fully covered by profes - sional indemnity insurance. After completing the tests, entities must submit results, corrective action plans, and receive certification. This certification facilitates mutual recognition of tests across EU member states. On 10 December 2024 the Cyber Resilience Act entered into force. Its full implementation is phased across three key dates. The main obligations will apply from 11 December 2027, with the exception of Arti - cle 14 which will apply from 11 September 2026 and Chapter IV (Articles 35-51) which will apply from 11 June 2026. Swedish Legislative Status (Supplementary Measures) Sweden has initiated national work to put in place supplementary enforcement and institutional arrange - ments for the CRA. On 28 November 2024, the gov - ernment appointed a special investigator and the assignment was reported in December 2025 through the Swedish Government Official Report (SOU) “Sup - 4. Cyber-Resilience 4.1 Cyber-Resilience Legislation The CRA
plementary provisions to the EU Cyber Resilience Regulation (SOU 2025:115)”. The SOU proposes a Swedish supplementary act and regulation to support enforcement of the CRA in Sweden, including national provisions on supervision and sanctions, and proposes institutional designa - tions, including: (i) Swedac as notifying authority, and (ii) PTS as the market surveillance authority (with an express note that, for products that are high-risk AI systems under the AI Act, the AI Act market surveil - lance authorities apply). The SOU also notes that MCF is the Swedish CSIRT function in the context of the The CRA is a product-focused regime, it applies to “products with digital elements” (hardware and soft - ware) made available on the market whose intended purpose or reasonably foreseeable use includes a direct or indirect data connection. It also covers a product’s “remote data processing solutions” where they meet the CRA definition. Standalone software can be in scope. By contrast, standalone SaaS/ cloud solutions developed outside the responsibility of a product manufacturer are not themselves “prod - ucts with digital elements”; however, where a service meets the definition of “remote data processing” for a product, it falls within scope. 4.2 Key Obligations Under Legislation Scope of Application The CRA applies to “products with digital elements” whose purpose or use involves a logical or physical data connection to a device or network. The CRA covers a wide range of software and hard - ware products that connect, either directly or indi - rectly, to other devices or networks. This includes smart home devices, wearable technology, internet- connected toys, and industrial Internet of Things (IoT) devices. Non-commercial open source software prod - ucts are not covered by the CRA. The CRA targets manufacturers, producers, and importers, requiring them to ensure that their products are safe to use, resilient to cyber threats, and that their security fea - tures are properly disclosed. CRA framework. Coverage/Scope
363 CHAMBERS.COM
Powered by FlippingBook