top of page
ICON-Final-05_edited.png

Two weeks left to register with the MSB – have you missed NIS2?

11 hours ago
2 min read

If you operate within one of the 18 sectors covered by Sweden’s Cybersecurity Act and still haven’t heard a word about NIS2 from your IT department over the past month, it may be worth raising an eyebrow.


The Cybersecurity Act (SFS 2025:1506) came into force on January 15 this year, but what is actually urgent right now is the registration deadline with the Swedish Civil Contingencies Agency: September 30. That is just two weeks away.



Sweden expects around 8,000 organizations to be affected – more than Denmark (around 5,000) and Finland (around 4,500), both of which completed their national implementation earlier. If you have at least 50 employees or an annual turnover exceeding €10 million and operate within one of the 18 sectors – ranging from energy and transport to food production and digital infrastructure – there is a good chance you are covered, regardless of whether you consider yourself a “critical infrastructure” company or not.


What makes this legislation different is that responsibility does not stop with the IT department. The board and CEO are personally responsible for approving and monitoring cybersecurity measures, and in serious cases, supervisory authorities can temporarily suspend management personnel from their roles. The fines are significant too: up to €10 million or 2% of annual turnover.


The most common mistake we see is not that companies completely ignore NIS2, but that they think registration is something they can deal with “when they have time to properly look into it.” However, registration and full compliance are two separate deadlines. Essential entities have until December 31 to achieve full compliance, while important entities have until March 31, 2027. Registration on September 30 is only the first step, but it is also the step that is easiest to miss by accident, since it does not require everything else to already be in place.


If you are unsure whether your organization is covered, or simply want help mapping out where you currently stand before the deadline, get in touch. This is exactly the kind of gap analysis we work with.


Sources:

 
 
bottom of page