SWEDEN Trends and Developments Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå
compliance has not been achieved. In other words, businesses that realise that they may be in scope of both the new Swedish Cybersecurity Act and the Pro - tective Security Act should seek specialised advice covering both acts, to ensure comprehensive compli - ance across both domains. This is also relevant giv - en that there is no case law under the new Swedish Cybersecurity Act, which is why it is likely that both supervisory authorities and courts will look to related regimes, ie, the Swedish Protective Security Act, for guidance when interpreting compliance requirements relating to information security and cybersecurity. This overlap can also be considered concerning the Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resil - ience of critical entities and repealing Council Direc - tive 2008/114/EC (CER). In the Swedish Government Official Report “Resilience in services essential to society (SOU 2024:64)” on the Swedish implementa - tion of CER, the inquiry notes that a remaining task is to adjust the Protective Security Act’s rules on super - visory powers and sanctions to the supervisory pow - ers and sanctions under the CER as well as NIS2. The inquiry assesses that it would not be desirable if the protective security framework were to provide less intrusive powers or less stringent sanctions than the regimes implementing NIS2 and CER. This also reflects a broader tendency in Swedish administrative enforcement, where supervision in several legislative areas has shifted from being primarily guidance-ori - ented to becoming more interventionist. The language in the new Swedish Cybersecurity Act evidences this in that the supervisory authority shall (Sw. ska ) inter - vene in response to breaches, in contrast to the word - ing in the Information Security for Critical and Digital Services Act where the supervisory authorities merely may (Sw. får ) do so. Legislation, practice and development Regarding Swedish security-related regulations, there have been a number of district court and administra - tive court decisions in recent years, but few have been tested all the way to the Swedish Supreme Court or the Swedish Supreme Administrative Court. The result is that developments have been relatively fragment - ed and there have been inconsistencies from case to case and between sectors. This is likely to remain
the position for some time under the new Swedish Cybersecurity Act as it entered into force in January 2026 and practice will develop over time before case law is established. For this reason, application problems may surface. Questions may arise concerning, eg, which legal entity is the “operator” under the legislation, which services fall within the regulated sectors, and whether only parts of the business are in scope (for example, where a group combines regulated and non-regulated activities, or where critical functions are outsourced). Many organisations will look for regulations from supervisory authorities in order to understand require - ments under the legislation in their relevant sectors. In the early stages of the new Swedish Cybersecu - rity Act, it should be expected that guidance from supervising authorities will be sparse and that it may take time before further regulations detailing how to interpret the new legislation are issued. However, implementing regulations have been given preliminary dates of entry into force, with regulations on notifi - cation and identification in February 2026, followed by regulations on security measures and training as well as incident reporting and information obligations in April 2026, and regulations on security audits and security scanning in June 2026. As noted above, the Swedish Cybersecurity Act should be understood alongside parallel regimes. In SOU 2024:64, it was proposed that the Swedish CER legislation should enter into force on 1 August 2025. The government bill regarding the implementation of CER into Swedish law is expected during the Spring of 2026. The Swedish Protective Security Act will also undergo changes. There are a number of ongoing pro - posals to amend the legislation, including proposals in SOU 2024:64 (concerning the CER, as mentioned above) and in the inquiry “The Swedish Protective Security Act – further additions (SOU 2025:42)”. This underscores that organisations should expect a developing and increasingly detailed regulatory land - scape in parallel to the implementation of the Swedish Cybersecurity Act. Cybersecurity compliance should therefore not be implemented in organisations’ com - pliance structures in an isolated sense, but structured to fit into a broader resilience and security framework
372 CHAMBERS.COM
Powered by FlippingBook