Cybersecurity 2026

SWEDEN Law and Practice Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå AB

Vulnerability Handling Manufacturers must run a documented vulnerability- handling process for the support period, including a co-ordinated vulnerability disclosure (CVD) policy and a clear point of contact for vulnerability reports, as well as processes to assess, remediate, and docu - ment vulnerabilities. Patching and Update Timelines Manufacturers must provide security updates dur - ing a declared support period (generally at least five years, unless the product’s expected use is shorter). Security updates must remain available long-term (at least ten years or the remainder of the support period, whichever is longer). Certain exploited-vulnerability/ severe-incident reporting has short statutory dead - lines (including a 24-hour early warning). Post-Market Surveillance/Ongoing Compliance Manufacturers must monitor products after placing them on the market, keep technical documentation up to date where needed, and take corrective measures when issues arise. Conformity Assessment Before placing a product on the market, manufactur - ers must perform conformity assessment and main - tain technical documentation. Many products can use internal control, but “important” and “critical” product categories may require stricter assessment routes, including third-party involvement and/or use of EU cybersecurity certification schemes where applicable. Marking and Certifications Compliant products require an EU declaration of con - formity and CE marking (and, where a notified body is used, the CE mark may be accompanied by the notified body number). EU cybersecurity certification may be relevant/required for certain categories where schemes exist. Recall/Withdrawal Duties If a product is non-compliant or presents a significant cybersecurity risk, manufacturers (and other econom - ic operators) must take corrective action and, where appropriate, withdraw or recall products and inform authorities/users.

Enforcement and Penalties Enforcement is carried out by Swedish authorities (with, as mentioned above, proposed roles includ - ing PTS for market surveillance, Swedac for notified bodies, and MCF for receiving reports). Penalties are structured as administrative fines with EU-level maxi - mum, that can reach EUR15 million/2.5%, EUR10 million/2%, or EUR5 million/1% of global turnover depending on the type of breach, alongside corrective actions such as restrictions, withdrawal, and recall. 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation The EU Cybersecurity Act The EU Cybersecurity Act entered into force on 27 June 2019. The primary goal of the Cybersecurity Act is to enhance protection against cybersecurity threats across the EU. The Cybersecurity Act also enables manufacturers and service providers to use one mutu - ally recognised certificate throughout the EU. Under the Cybersecurity Act, European cybersecu - rity certification schemes may define assurance lev - els at “basic”, “substantial”, and “high”. In general terms, “basic” targets lower-risk use cases and may allow supplier self-assessment or an EU statement of conformity, whereas “substantial” and “high” imply increased rigour, typically through stricter evalua - tion and/or independent conformity assessment in accordance with the relevant scheme rules. Certifica - tion under the Cybersecurity Act is voluntary. Main Elements The regulation has two main functions and purposes. • To give the EU Agency for Network and Information Security a permanent mandate, more resources and new tasks. • To create a framework for certifying cybersecurity products and services. This framework sets up a system to govern the issuance of European cyber - security certificates and declarations of conformity with security standards for ICT products, services, and processes. The purpose of the certification is

364 CHAMBERS.COM

Powered by