Skip to content
The rules

Who NIS2 covers in Sweden, and who decides it

NIS2 scope in Sweden is settled by six provisions, and the assessment rests on the operator itself. The size threshold moves in both directions, and essential or important answers another question.

Andreas Olsson9 min read

A wall letter box with its hatch open and nothing inside, the inner edge of the empty opening the only gold in the picture.

Key insights


  • Sweden's Cybersecurity Act (2025:1506) sets out its scope in six provisions, Chapter 1, Sections 3 to 8, and size is a condition in only two of them: necessary in Section 4, one of two ways in under Section 7(1).
  • Identification rests on the operator. The guidance issued by Myndigheten för civilt försvar in February 2026 states that it is the operator that must analyse whether its own activity is covered.
  • The registration duty in Chapter 2, Section 2 has run since 2 February 2026 with no outer limit. The fourteen-day deadline in that provision covers changes to a registration already made.
  • The split between essential and important entities decides the form of supervision and the ceiling on penalties, not whether the law applies. An operator that is not essential is an important one.
  • The size threshold moves in both directions: Chapter 1, Section 5 removes it entirely for four criteria, and Chapter 3, Section 1 of MCFFS 2026:1 exempts operators that only clear it through their group.

Ask who NIS2 covers and the answer almost always arrives as two things: a list of eighteen sectors and a threshold at medium-sized enterprise. Both are in Swedish law and both are correct. Together they still do not settle the question.

NIS2 is a directive, so what binds an operator is the national law implementing it. In Sweden that is the Cybersecurity Act (2025:1506), in force since 15 January 2026, and its scope sits in six provisions. Size is a condition in only two of them. That threshold can move in either direction. And the step most readers reach for first, the split between essential and important operators, answers a different question from the one they asked.

No authority tells you the law applies

Identification rests with the operator. Myndigheten för civilt försvar, the Swedish civil defence authority, says so plainly in its guidance on registration and identification, published in February 2026: it is the operator that must analyse whether its own activity is covered by the legislation. No notice arrives from outside.

The duty that follows sits in Chapter 2, Section 2. An operator shall register with the authority the government designates as soon as this can be done, and where the circumstances stated in a registration have changed, the change shall be notified no later than fourteen days after it occurred.

The fourteen days therefore attach to the change, not to the first registration. For that first registration the Act sets no outer limit at all. What exists instead is a starting point: the regulations on registration and identification, MCFFS 2026:1, were adopted on 8 January 2026 and entered into force on 2 February 2026. The duty has run for six months without any day having been the last one.

An obligation with no closing date is never late, and that is exactly what makes it easy to postpone.

The recipient has changed, though. Registrations were first received by Myndigheten för civilt försvar, whose cyber activities transferred on 1 July 2026 to the Swedish National Cyber Security Centre at Försvarets radioanstalt. The Swedish Post and Telecom Authority states that registration goes there whatever sector the operator belongs to. A registration prepared in the spring and left unsent now has a different address.

NIS2 scope in Swedish law: six provisions, two with a size test

The scope provisions are Chapter 1, Sections 3 to 8. Each carries its own conditions.

ProvisionWho it reachesSize required
Ch. 1 s. 3Regions, municipalities and municipal associations, and state agencies with the power to take decisions affecting cross-border movement of persons, goods, services or capitalNo
Ch. 1 s. 4Operators covered by Annex 1 or Annex 2 to the NIS2 directive but not by s. 5(4), s. 6 or s. 7(1) to (3), and established in Sweden, and private education providers authorised to award degreesYes
Ch. 1 s. 5Operators meeting the conditions in Section 4(1) and (2), the annexes and establishment but not size, where the operator is the only provider in Sweden of a service essential to critical societal or economic activity, where a disruption could significantly affect life and health, public safety or public health or create systemic risk, where the operator carries particular importance nationally or regionally, or where it provides trust servicesNo
Ch. 1 s. 6Anyone providing public electronic communications networks or publicly available electronic communications services in SwedenNo
Ch. 1 s. 7Cloud services, data centre services, content delivery networks, managed services and managed security services, online marketplaces, search engines and social networking platforms, and top-level domain name registries, DNS services and domain name registration servicesSize or the criteria in Section 5(1) to (3), and only for the first item
Ch. 1 s. 8The state agencies the government designates, even where the conditions in Sections 3 to 7 are not metNo

Size returns in Section 7(1), but does different work there. That provision requires the operator to meet the condition in Section 4(3) or one of the criteria in Section 5(1) to (3). A small cloud provider that is the only provider in Sweden of an essential service is therefore covered without clearing the floor, while a large one is covered on size alone. In Section 4 size is necessary; in Section 7 it is one of two ways in; and in the remaining four provisions it is not tested at all.

Two details in Section 4 decide more cases than size does. The first is that the Act does not point at the sector but at the type of operator. The third column of the annexes lists types of operator, and an activity can sit in one of the eighteen sectors the Swedish National Cyber Security Centre counts without being any of the listed types. The second is the establishment requirement, which settles whether Swedish law or another Member State's is the one being tested.

The size threshold moves in both directions

The requirement in Chapter 1, Section 4(3) is that the activity is equivalent to or larger than a medium-sized enterprise, measured against Commission Recommendation 2003/361/EC. The guidance restates it: a medium-sized enterprise has fewer than 250 employees and turnover of up to 50 million euro or a balance sheet total of up to 43 million euro, while a small enterprise has fewer than 50 employees and no more than 10 million euro. The floor therefore sits on the boundary between small and medium.

Upwards, the floor moves through the group calculation. The guidance states that an operator not large enough on its own can still be covered where the size calculation includes linked enterprises or partner enterprises. A Swedish subsidiary with thirty employees can clear the floor because its group does.

Downwards, the floor moves through Chapter 3, Section 1 of MCFFS 2026:1. An operator that meets the size requirement only through its links to other undertakings shall be exempted from the Act's scope where the operation and management of its own production environment is conducted substantially independently of the production environment of those partner or linked enterprises, and where the operator is otherwise independent enough that being covered would be disproportionate.

And it disappears altogether in Chapter 1, Section 5. The criteria there refer back to the requirements in Section 4(1) and (2), meaning the annexes and establishment, but not to Section 4(3). Size is not tested. A small operator that is the only provider in Sweden of a service essential to critical societal activity is covered on the same footing as a large one.

Essential or important decides supervision, not application

The split in Chapter 1, Section 9 is often read as a third category alongside covered and not covered. It is not. The provision's last sentence closes the question: operators which are not essential are important operators. An operator inside is one or the other, and an operator outside is neither.

The difference lies in two other things. Supervision of essential operators is planned, while supervision of important ones can, according to the guidance, only follow an indication or an incident that has already occurred. And the penalty ceiling differs. Under Chapter 4, Section 10 the penalty is set at no less than 5,000 kronor and at most the higher of 2 percent of total global annual turnover in the preceding financial year or an amount corresponding to 10,000,000 euro for an essential private operator, the higher of 1.4 percent or 7,000,000 euro for an important one, and 10,000,000 kronor for a public operator.

The wording in Section 9 also differs from Section 4. Scope requires the activity to be equivalent to or larger than a medium-sized enterprise. The essentiality rule requires it to be larger than a medium-sized enterprise. A medium-sized enterprise in Annex 1 is therefore inside the Act and important, not essential, and an operator that looks for itself on the list of essential entities and fails to find it has been told nothing about whether the law applies.

The regulations name activities the Act does not

MCFFS 2026:1 was issued under Section 38 of the Cybersecurity Ordinance (2025:1507). It fills in four things: the exemption for partner and linked enterprises from the size requirement, what counts as the main establishment, which further operators are covered under Chapter 1, Section 5(1) to (3), and which operators count as essential under Chapter 1, Section 9, first paragraph, item 6.

Chapter 4 of the regulations is what makes the question concrete. In transport it covers all contingency airports, air traffic control services, quarantine ports and places of refuge. In drinking water it covers anyone producing or distributing drinking water under the Public Water Services Act (2006:412) to at least 20,000 people or to an emergency hospital. In chemicals it covers anyone manufacturing or processing more than one tonne a year of additives or inputs of decisive importance to large-scale chemical production for, among other things, drinking water treatment, wastewater treatment, food processing and plant protection products, and registered under Regulation (EC) No 1907/2006.

That is the kind of boundary that decides individual cases. Two municipal waterworks with the same headcount and the same budget land on opposite sides of 20,000 people, and the difference shows up in none of the figures an organisation normally benchmarks itself against.

Three provisions take activities out of the duties

The reading above could sound as though the set is open-ended and every organisation should assume it is inside. That conclusion does not hold.

Chapter 1, Section 5 creates no scope out of nothing. It expressly requires the conditions in Section 4(1) and (2), meaning the operator must be one of the types listed in the annexes and established in Sweden. What it removes is the floor, not the list.

Running the other way are three provisions. Chapter 1, Section 10 gives precedence to other legislation imposing security or incident reporting requirements where their effect at least matches the effect of the duties in Chapter 2, Sections 3 to 10. Chapter 1, Section 11 exempts operators covered by DORA from those same duties, a boundary that, together with the EU AI Act, is treated at length in Who reports what when NIS2, DORA and the AI Act overlap. And Chapter 1, Section 12 removes state agencies predominantly engaged in security-sensitive or law enforcement activity, together with private operators engaged solely in security-sensitive activity or offering services solely to such agencies, except where the operator provides trust services.

An operator that reads the exemptions properly usually has less to do afterwards than before.

What remains is not a wide set but a set with uneven edges. The error runs both ways. One organisation can spend a year on duties it does not have, another can be missing a registration that was due in February, and both have read the same list of sectors.

Two questions that give different answers in the same sector

The assessment is bounded and it is made on the operator's own figures. Two questions carry it, and they produce different answers for organisations that look alike from outside.

The first: do you come in through a provision that does not test size? That covers every region, municipality and municipal association, every provider of public electronic communications networks, every top-level domain name registry and every DNS service, and beyond them anyone meeting one of the criteria in Chapter 1, Section 5. The criteria in Section 5(1) to (3) are qualitative. Only provider in Sweden, or particular regional importance to a sector that depends on you: two operators of the same size in the same industry can answer differently, and nobody outside makes the call for them.

The second: if you clear the size threshold, do you clear it on your own? A subsidiary that only gets over the floor through its group has an exemption to test in Chapter 3, Section 1 of MCFFS 2026:1, and that exemption turns on how independently its own production environment is actually run. Two subsidiaries with identical turnover answer differently depending on where their operations sit.

The calendar puts a date on the question. The regulations on incident reporting and information duties, MCFFS 2026:8, took effect on 1 July 2026. The regulations on security measures and management training, MCFFS 2026:11, and on security audits and security scanning, MCFFS 2026:12, take effect on 1 October 2026. An operator that has not yet settled whether the law applies has two months left before the requirements on the security work itself begin to run.

The answer then belongs in one place: the provision you came in through, the date of registration, the classification as essential or important, and the name of the person who made the assessment. Without that document two people in the same organisation make separate assessments at separate times. An energy company or a grid owner and a municipality or region come in through different provisions but have the same document to write, and it belongs in the same AI governance and compliance work an organisation is already building for the EU AI Act.


Common questions

NIS2 is a directive, so scope is settled by the national law implementing it. In Sweden that is the Cybersecurity Act (2025:1506), and the scope provisions are Chapter 1, Sections 3 to 8. Regions, municipalities and municipal associations are covered regardless of size, as are state agencies with the power to take decisions affecting cross-border movement. Private operators are covered under Section 4 if they are one of the types listed in Annex 1 or Annex 2 to the directive, are established in Sweden, and are equivalent to or larger than a medium-sized enterprise. Cloud services, data centres, online marketplaces, search engines and social platforms are dealt with instead under Section 7, where size is one of two alternative ways in. The size requirement falls away entirely for anyone meeting one of the four criteria in Chapter 1, Section 5.

NIS2 is the EU directive on measures for a high common level of cybersecurity across the Union. A directive does not apply directly; it is implemented in national law, and in Sweden that has happened through the Cybersecurity Act (2025:1506) and the accompanying Cybersecurity Ordinance (2025:1507). An operator asking what applies to it in Sweden should therefore read the Act and the regulations issued under the Ordinance, not the directive text. The directive's Annexes 1 and 2 still matter, because the Act refers straight to them for which types of operator are covered.

In Swedish law the split sits in Chapter 1, Section 9 of the Cybersecurity Act, and it does not decide whether the law applies. The last sentence of that provision reads that operators which are not essential are important operators, so an operator inside the scope is one or the other. What the split decides is the form of supervision, which is planned for essential operators and only follows an indication or an incident for important ones, and the ceiling on penalties under Chapter 4, Section 10.

In Swedish law the duties sit in Chapter 2 of the Cybersecurity Act: registration of the activity, systematic and risk-based security work, and incident reporting to the CSIRT unit. The deadlines are an early warning within 24 hours under Section 5, an incident notification within 72 hours under Section 6 and 24 hours for trust service providers, and a final report within one month under Section 8. The detail sits in regulations: MCFFS 2026:8 on incident reporting and information duties, MCFFS 2026:11 on security measures and management training, and MCFFS 2026:12 on security audits and security scanning.

It can. The general rule in Chapter 1, Section 4 of the Swedish Cybersecurity Act requires the activity to be equivalent to or larger than a medium-sized enterprise, which leaves small companies out. Chapter 1, Section 5 then removes that requirement for operators that are the only provider in Sweden of a service essential to critical societal or economic activity, whose disruption could significantly affect life and health, public safety or public health or create systemic risk, that carry particular importance nationally or regionally, or that provide trust services. Those criteria refer back to the annexes and to establishment in Sweden, but not to size. The same criteria give a small cloud or data centre operator a way into Section 7 without meeting the size test.

The Cybersecurity Act (2025:1506) entered into force on 15 January 2026 and repealed the earlier Act (2018:1174) on information security for essential and digital services, which still governs infringements committed before that date. The regulations on registration and identification, MCFFS 2026:1, were adopted on 8 January 2026 and entered into force on 2 February 2026. The regulations on incident reporting took effect on 1 July 2026, and those on security measures, management training, security audits and security scanning take effect on 1 October 2026.

Yes. Under Chapter 1, Section 3 of the Swedish Cybersecurity Act the law applies to a region, a municipality or a municipal association, with no size requirement and without any test against the directive's annexes. A small rural municipality is covered on the same footing as a large city. Size still matters at a later step: under Chapter 1, Section 9 a municipality or region counts as an essential operator if it is larger than a medium-sized enterprise, and as an important one otherwise. That difference governs supervision and the penalty ceiling, not whether the law applies.

Registration is made under Chapter 2, Section 2 to the authority the government designates. Registrations were first received by Myndigheten för civilt försvar, the Swedish civil defence authority, whose cyber activities transferred on 1 July 2026 to the Swedish National Cyber Security Centre at Försvarets radioanstalt. The Swedish Post and Telecom Authority states that registration is made to the National Cyber Security Centre whatever sector the operator belongs to. What a registration must contain sits in Chapter 2 of MCFFS 2026:1: name, address, email address, company registration number and telephone number, internet identifiers in the form of IP addresses and domain names, and details of sector, type of activity and classification as essential or important.


If this lands on your desk, we should talk.

Ampliro Insights

New analysis, roughly weekly.

We write when the rules change and when something turns out to work in practice. One piece at a time, no sequences, and you can leave from any issue.

We store your address to send Ampliro Insights, and for nothing else. More in the privacy policy.