SWEDEN Trends and Developments Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå
The new cybersecurity legislation In comparison to the Information Security for Critical and Digital Services Act, the new Swedish Cyberse - curity Act sets out new requirements on technical, operational and organisational measures to manage risks that threaten the network and information sys- tems they use for operations or for providing services, and the physical environment of those systems. These measures should include risk analysis, business con - tinuity measures, supply chain security measures and personnel security measures. The measures should be based on an overall risk perspective and risk analy - sis and be proportionate to the risk. They should be evaluated regularly and include specific elements, including supply-chain security. Supply-chain security encompasses the security aspects of the relationship between the operator and its direct suppliers or service providers. This means that each operator must implement risk management measures in relation to its suppliers, making it respon - sible for its direct suppliers, which will influence con - tracting and vendor oversight. Another clear change in the new legislation is sector expansion. The Information Security for Critical and Digital Services Act targeted a smaller set of sectors; energy, transport, banking, financial market infrastruc - ture, health care, drinking water, digital infrastructure, and certain digital services. NIS2, and thus the Swed - ish Cybersecurity Act, is built around a far larger sec - tor map, and the Swedish implementation covers both private and public actors depending on sector, size and other factors. Below is the sector list that the new Swedish Cybersecurity Act covers: • energy; • transport; • banking; • financial market infrastructures; • health; • drinking water; • waste water; • digital infrastructure; • ICT service management (business-to-business); • public administration; • space; • postal and courier services;
Compliance in Transition: Interpreting the Swedish Cybersecurity Act and Its Interaction With Parallel Regimes Introduction Cybersecurity has moved from being a technical con - cern to a core business and governance issue. Digital systems now underpin almost every sector and the digital supply chains that connect them. At the same time, a more challenging geopolitical environment has increased both the frequency and the sophistication of cyber threats targeting European states and busi - nesses. Against this backdrop, Sweden’s regulatory frame - work has undergone notable changes regarding cybersecurity. The new Swedish Cybersecurity Act (2025:1506) entered into force on 15 January 2026 and implements the Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 Decem - ber 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS2). The new Swedish Cybersecurity Act also repeals Sweden’s prior NIS implementation; Information Security for Critical and Digital Services Act (2018:1174) and the Information Security for Critical and Digital Services Ordinance (2018:1175). In addition, it should be noted that businesses operat - ing in Sweden must take note of the Swedish national security legislation, most notably the Swedish Protec - tive Security Act (2018:585). While this act covers a narrower set of actors than the Swedish Cybersecurity Act, it covers more than just cybersecurity and infor - mation security, and the obligations in the cybersecu - rity space can be daunting. Hence, for those in scope, it can have a significant impact on the cybersecurity and compliance burden of a business. It should also be noted that the supervisory authorities handling protective security matters have been taking a much more proactive stance during the last year. However, the following overview will focus on (i) the new Swedish legislation concerning cybersecurity, (ii) the likely future approach taken by the supervisory authorities, and (iii) possible developments concern - ing practice and implementation of the new legislation.
369 CHAMBERS.COM
Powered by FlippingBook