Regulation
Sweden's Cybersecurity Act: what it changes for security testing
Sweden was among the last EU member states to transpose NIS2. The Cybersecurity Act (cybersäkerhetslagen) entered into force on 15 January 2026, and the practical consequence for security teams is a shift from voluntary maturity work to supervised, evidence-backed obligations.

Swedish organisations had an unusually long run-up to NIS2. The directive's transposition deadline was 17 October 2024; Sweden's Cybersecurity Act entered into force on 15 January 2026. That gap produced a familiar pattern — a lot of readiness assessments, comparatively little tested evidence. The Act removes the ambiguity that made deferral comfortable.
What actually changed on 15 January 2026
The substance of the obligations is inherited from NIS2: risk-management measures, incident reporting, management accountability, supply chain security, and supervision with the possibility of sanctions. What changed is that they became Swedish law with named supervisory authorities and a registration duty, rather than a directive to be planned for.
- In-scope entities must register with their supervisory authority. Registration is what makes you visible to supervision — it is not a formality you can defer indefinitely.
- Sector supervision is distributed across several authorities rather than concentrated in one, with MSB holding a coordinating role and the national CSIRT function at CERT-SE.
- Management bodies carry approval and oversight duties, mirroring NIS2 Article 20.
- Incident reporting follows the NIS2 staged model: early warning, notification, final report.
- Supervisory authorities can request evidence, and administrative sanction charges are available for non-compliance.
Why Swedish organisations are unusually exposed on identity
Sweden has one of the highest rates of enterprise cloud adoption in Europe, and Swedish B2B and public-sector environments lean heavily on federated identity, BankID-adjacent flows, and SaaS-first architectures. That is operationally excellent and it concentrates risk in a specific place: the identity provider and the trust relationships hanging off it.
In practice this means a perimeter-focused test tells you almost nothing useful. There is very little perimeter left. The questions that matter are whether a compromised user account can be escalated, whether conditional access can be bypassed through a legacy or recovery path, whether service principals and OAuth grants are over-privileged, and whether a supplier's delegated access is scoped to what they actually need.
A testing programme that maps to supervision
| Obligation area | What supervision will likely ask | Evidence that answers it |
|---|---|---|
| Effectiveness of measures | How do you know your controls work? | Dated assessment reports with reproducible findings, plus retest results |
| Vulnerability handling | What is your process and does it close? | Remediation SLAs with measured actuals, and verification of fixes |
| Supply chain | What access do suppliers hold and who checks it? | Access inventory plus a test of at least one high-privilege supplier integration |
| Incident handling | Can you meet the 24-hour early warning? | Timed exercise records showing detection, escalation and decision-to-report |
| Management oversight | Did the board approve, on what basis? | Minuted approval referencing a specific risk assessment and test results |
The evidence gap most readiness projects leave open
Readiness assessments produce gap analyses. Gap analyses describe intent. Supervision asks about outcome. The distance between the two is almost always in three places.
- Detection. Policies claim monitoring coverage; nobody has verified what the SOC actually sees for the attack paths that matter. An objective-led exercise resolves this in days.
- Recovery. Backup policies are documented; nobody has attempted to reach or damage backups from a compromised position. This is the control that decides whether an incident becomes significant.
- Closure. Findings are recorded and assigned; nobody has verified the fix. A remediation ticket marked done is not evidence that the vulnerability is gone.
Sequencing for the first supervised year
If you are starting from a gap analysis and want defensible evidence within two quarters, the order that works is: confirm scope and register, test identity and the systems carrying your most sensitive processing, remediate on a stated window, retest anything high or critical, then run one timed incident exercise that produces an awareness-to-notification record. Board approval comes last, referencing all of it — not first, referencing a plan.
That order matters because management approval under Article 20 is only meaningful if there is something factual to approve. A board that signs off a policy set has approved a document. A board that signs off a tested risk position has discharged an obligation.
Frequently asked questions
When did Sweden's Cybersecurity Act enter into force?
The Swedish Cybersecurity Act (cybersäkerhetslagen), which transposes NIS2, entered into force on 15 January 2026. It replaced the earlier NIS regime and introduced registration duties, distributed sector supervision and sanction powers.
Does the Swedish Cybersecurity Act require penetration testing?
The Act inherits the NIS2 approach: it requires appropriate and proportionate risk-management measures, vulnerability handling, and procedures to assess whether measures are effective. It does not prescribe penetration testing by name. Sector supervisory authority guidance is where more concrete testing expectations tend to appear.
Who supervises NIS2 compliance in Sweden?
Supervision is distributed across sector authorities, with MSB holding a coordinating role and CERT-SE acting as the national CSIRT. Confirm which authority supervises your sector, because evidence expectations vary between them.
Talk to the team
Need this tested rather than described?
QuietHours is a European cybersecurity practice operated by the securIT team. Send us the system, service, or control you are concerned about and we will help turn it into a workable scope.
Discuss your scope