Cybersecurity 2026

SWEDEN Trends and Developments Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå

• waste management; • manufacture, production and distribution of chemi - cals; • production, processing and distribution of food; • manufacturing; • digital providers (including categories such as online marketplaces, search engines and social networking platforms, as well as cloud/data centre/ CDN and certain managed services depending on the legal definitions); and • research. Under the new Swedish Cybersecurity Act, entities are categorised within a two-tier model of either essential (Sw. väsentliga ) or important (Sw. viktiga ), with differ - ent enforcement intensity and different expectations regarding maturity and scrutiny. A further important change is that of incident reporting. While the Information Security for Critical and Digital Services Act required registration and incident report - ing, the new Swedish Cybersecurity Act requires that organisations have more structured reporting steps and stricter timelines. Under the new legislation, a significant incident must be reported in staged form, an initial notice within 24 hours of becoming aware of the incident, followed by an incident notification (within 24 hours for providers of trust services and within 72 hours for other operators), interim reporting upon request, and a final report within one month (or a status report if the incident is ongoing). A significant incident is one that has caused or may cause serious operational disruption or economic loss for the opera - tor, or significant harm to others. Depending on the circumstances, service recipients may also need to be informed of significant incidents. Sweden’s approach to incident reporting is cen - tralised. Rather than reporting incident information directly to the sector regulator in the first instance, it is reported to the Swedish Civil Defence and Resilience Agency (MCF), and then directed as appropriate. The new Swedish Cybersecurity Act also comes with the supporting Cybersecurity Ordinance, which, inter alia, designates the competent supervisory authorities and other practical arrangements for co-ordination and oversight in Sweden’s NIS2 implementation. In par - allel, MCF has already begun issuing implementing

rules, including the Regulations of the Swedish Civil Defence and Resilience Agency (MCFFS 2026:1) on notification and identification of essential and impor - tant entities. An important novelty in the new Swedish Cyberse - curity Act is governance on management level, as NIS2 is intended to bring cybersecurity into manage - ment accountability. The consequence is that super - visory authorities will assess whether cybersecurity is understood and taken seriously at a senior manage - ment level, rather than being delegated entirely to IT or security teams. Senior management is expected to monitor the implementation of risk management measures as operators are required to implement poli - cies and procedures to assess the effectiveness of the cybersecurity risk management measures across organisations and to address identified deficiencies. In the months following the entry into force of the new Swedish Cybersecurity Act, MCF will issue regulations on how management should be informed and edu - cated on cybersecurity. Further, the new Swedish Cybersecurity Act includes rules on when other regimes take precedence and specific carve-outs relevant to Swedish- and EU-reg - ulated sectors. There is interaction with Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regu - lations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (DORA), whereas if an entity is covered by DORA, the Swedish Cybersecurity Act’s obligations on security measures and incident reporting do not apply. Simi - larly, the new Swedish Cybersecurity Act does not apply to entities that only conduct activities that are “security-sensitive” under the Swedish Protective Security Act (2018:585), and for entities conducting both “security-sensitive” activities and other activi - ties, the new Swedish Cybersecurity Act only applies partially. Another change is that the new Swedish Cyberse - curity Act raises the enforcement stakes compared with the Information Security for Critical and Digital Services Act. The Information Security for Critical and Digital Services Act relied on Swedish-level sanction

370 CHAMBERS.COM

Powered by