Does NIS2 apply to your organisation?
Sweden's cybersäkerhetslagen has been in force since 15 January 2026. Nine questions, about two minutes, and you get a plain answer: whether you are covered, whether you count as an essential or an important entity, and what that actually obliges you to do.
- About two minutes
- No account, and no email needed for the result
- Free, and stays free
Question 1 of 9
Which sector do you operate in?
NIS2 names eighteen sectors. Pick the one that best describes what your organisation actually does. If none of them fit, say so, that is a real answer.
Cybersäkerhetslagen: the dates that matter
Sweden implemented NIS2 through cybersäkerhetslagen (2025:1506). The duties arrived in stages.
- 2026-01-15The law enters into force.
- 2026-02-02Registration with NCSC opens. Covered organisations register as soon as possible from this date, not by a later deadline.
- 2026-07-01The incident-reporting regulations apply. The 24-hour, 72-hour and 30-day clocks start counting.
- 2026-10-01The security-measure, management-training and security-audit regulations apply. This is the milestone most organisations are working towards.
Common questions
- Who does cybersäkerhetslagen actually apply to?
- Organisations active in one of the eighteen sectors NIS2 names, that meet the medium-enterprise threshold: at least 50 employees, or turnover above 10 million euro. A few activities are covered regardless of size, including DNS and top-level domain operators, trust service providers and providers of public electronic communications. Those figures are measured across the whole group where a parent company controls the organisation, so a small subsidiary of a large group counts as large. Sector authorities can also designate individual organisations that fall outside the general rule.
- Does NIS2 apply to a subsidiary of a large group?
- Often yes, and on the group's figures rather than its own. NIS2 borrows the EU definition of a medium-sized enterprise, and article 6 of that definition adds a controlling parent's headcount and turnover to the subsidiary's before the thresholds are applied. Article 6(3) then adds the companies linked to that parent, so sister companies count as well: a three-person holding company that owns several large operating companies takes the whole group over the line, even though the parent on its own is tiny. A twenty-person subsidiary of a four-thousand-person group is therefore a large enterprise for this purpose, so if it works in one of the eighteen sectors it is covered, and in an Annex I sector it is an essential entity. The parent's own line of business makes no difference to any of this: your sector is decided by what you do, and only the size figures travel up a group. A minority holding of 25% to 50% counts only pro rata, and some owners, such as venture capital funds, universities and small local authorities, leave a company autonomous regardless. Where the subsidiary's own sector is not one of the eighteen it stays outside the law, but a covered company in the same group has to secure its suppliers, and that usually reaches the group's shared service companies through the contract.
- What is the difference between an essential and an important entity?
- The security requirements are the same. Supervision and penalties are not. Essential entities (väsentliga verksamhetsutövare) face proactive supervision and a sanction ceiling of 2% of global turnover or 10 million euro. Important entities (viktiga verksamhetsutövare) are supervised reactively, with a ceiling of 1.4% or 7 million euro. Large organisations in the Annex I high-criticality sectors are essential; most others in scope are important.
- What are the reporting deadlines?
- An early warning within 24 hours of becoming aware of a significant incident, a fuller incident notification within 72 hours, and a final report within a month. Some sectors have tighter clocks: six hours for state agencies under beredskapsförordningen, and 24 hours for trust service providers.
- What happens if we do nothing?
- Fines run up to 2% of global annual turnover or 10 million euro for essential entities, whichever is higher, and 1.4% or 7 million euro for important ones. Beyond the money, NIS2 makes the management body accountable for approving and overseeing the risk-management measures, and that accountability is personal.
- We already have ISO 27001. Are we done?
- It is a substantial head start, not a finish line. An ISO 27001 management system covers most of what NIS2 asks for in risk management, access control, cryptography and business continuity. What it does not give you is the registration duty, the statutory incident-reporting timelines, or the specific management-training and accountability requirements. Those have to be added deliberately.
This check applies the general rules in cybersäkerhetslagen (2025:1506) and the NIS2 directive to the answers you gave. It cannot see the national carve-outs, individual designations or sector-specific rules that decide borderline cases, and it is not a legal determination. Confirm your status with your sector authority, or with Nationellt cybersäkerhetscenter (NCSC) if you are not sure which one supervises you.