Cybersecurity 2026

SWEDEN Trends and Developments Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå

ceilings and a framework which can be deemed as rel - atively contained. The new NIS2-aligned model uses materially larger administrative fine ceilings, especially for large private groups. The maximum sanction fee is turnover-based for private operators (up to the higher of 2% of global turnover or EUR10 million for essential operators, and up to the higher of 1.4% of global turn - over or EUR7 million for important operators), while public operators are subject to a fixed maximum of SEK10 million. Authorities’ approach to the new legislation The supervisory authorities Sweden’s supervisory model under the new Swedish Cybersecurity Act is best understood as central co- ordination with sector supervision. The Cybersecu - rity Regulation designates MCF as Sweden’s single point of contact for NIS2 co-operation, and also as Sweden’s CSIRT (incident response function). This structure is designed to create one national situational picture of cyber risk and incident activity, while still allowing specialised regulators to supervise compli - ance within their sectors. Competent supervisory authorities are designated in the Cybersecurity Ordinance depending on the sector. The list is broad and includes both specialist regulators and, in certain areas, county administrative boards (Sw. länsstyrelse ). By way of example, compe - tent supervisory authorities include the Swedish Post and Telecom Authority (digital infrastructure and cer - tain digital providers), the Swedish Financial Supervi - sory Authority (financial sectors within its remit), the Swedish Transport Agency (transport sectors within its remit), and the Swedish Energy Agency (energy). In the health sector, supervisory responsibilities are allocated to authorities including the Health and Social Care Inspectorate and the Medical Products Agency, depending on the activity. Enforcement Enforcement under the new Swedish Cybersecurity Act is structured as a graduated set of measures. The toolkit at hand for supervisory authorities is as follows. • Information requests and investigations, including questions aimed at scoping, governance, and evi -

dence of implemented measures (not merely policy statements). • Orders (injunctions) requiring specific remedy within a set timeframe. • Penalty-backed measures where an authority requires compliance and attaches financial conse - quences for non-compliance with the order. • Administrative fines where the statutory conditions are met, with higher ceilings for private entities than under the Information Security for Critical and Digital Services Act. At this early stage of the new Swedish Cybersecurity Act, supervisory activity will likely focus on (i) whether an entity is correctly identified as in-scope, (ii) whether it has been registered, and (iii) whether it can demon - strate that risk management measures and incident- handling procedures are implemented in a way that is compliant with the legislation. As mentioned above, the enforcement framework is also structured to place cybersecurity on a management level. Where deficien - cies are identified, and supervisory action follows, it will inevitably affect how management evaluates cyber and security investments. This analysis also needs to be read against the Swed - ish system’s broader security regulation. As mentioned in the introduction, many organisations that interact with public authorities, critical infrastructure, or sensi - tive procurement may also be subject to the Swedish Protective Security Act in relation to security-sensitive activities. Also as noted, the Swedish Cybersecurity Act includes rules intended to avoid duplication for purely security-sensitive activities, but, in practice, organisations may still need to manage two regimes in parallel, one driven by cybersecurity compliance, and the other driven by protective security requirements. It should be noted that the Swedish Protective Secu - rity Act is a live enforcement regime, which involves requirements on information security and therefore cybersecurity. As an example, Stockholm’s District Court was ordered to pay a SEK2.5 million sanction fee due to deficiencies in the protective security work. Although this was not due to deficiencies specifically related to cybersecurity, it highlights Swedish authori - ties’ willingness to pursue enforcement and impose administrative sanctions where they consider that

371 CHAMBERS.COM

Powered by