NIS2 is the EU's updated cybersecurity directive, and it is no longer on the horizon, it is in force. In Sweden it was transposed through the Cybersecurity Act (Cybersäkerhetslagen, SFS 2025:1506), which entered into force on 15 January 2026 and replaced the previous NIS Act. It widens the range of organizations that must meet strict cybersecurity requirements and places new duties on management, incident reporting, and supply chain security. For the short definition, see NIS2, and for how it fits into a wider program, see security awareness for compliance.
What is NIS2?
The NIS2 Directive, short for Network and Information Security Directive 2, is a European law designed to raise cybersecurity standards for organizations that provide essential and important services. As cyberattacks grow more frequent and more sophisticated, NIS2 requires in-scope organizations to protect their systems, respond effectively to incidents, and maintain public trust. In practice, that means adopting and maintaining strong, documented cybersecurity practices rather than treating security as a one-off project.
Who does NIS2 apply to?
NIS2 covers far more organizations than the original NIS Directive. It applies to both essential and important entities across a broad set of sectors, including energy, healthcare, transport, digital infrastructure, public administration, and many others. If your organization operates in one of these sectors above a certain size, it is likely in scope, and it is worth confirming your status early rather than assuming you are exempt.
Key requirements of NIS2
Broader scope: many more organizations now fall under the directive, across both essential and important entities.
Risk-based approach: organizations must run ongoing risk assessments and apply security measures proportionate to the risks they actually face.
Incident reporting: significant incidents must be reported to national authorities within strict timeframes, typically an early warning within 24 hours and a fuller report within 72 hours.
Supply chain security: organizations must assess and manage the cybersecurity risks introduced by their suppliers and third-party providers.
Stronger governance: boards and senior management must actively oversee cybersecurity, with clear accountability for compliance.
What NIS2 means in Sweden
Under the Swedish Cybersecurity Act, in-scope organizations must register with the relevant regulatory authority, implement appropriate security measures, provide security training for management, and report significant incidents. The management training requirement is notable: NIS2 makes cybersecurity a leadership responsibility, not just an IT one, so training and awareness need to reach the boardroom as well as the front line.
How to prepare
Preparation is mostly about closing the gap between what you do today and what the law now expects: confirm whether you are an essential or important entity, run a risk assessment, put incident reporting procedures in place, review supplier risk, and make sure management is trained and accountable. Because so much of NIS2 comes down to human behavior and governance, security awareness is central to staying compliant. See how Nimblr meets NIS2 requirements , and how phishing simulations and NIS2 fit together to build measurable, defensible readiness.
Frequently asked questions
What is NIS2?
NIS2 is the EU's updated cybersecurity directive. It raises security requirements for essential and important organizations and adds duties around risk management, incident reporting, supply chain security, and management accountability.
When does NIS2 apply in Sweden?
Sweden transposed NIS2 through the Cybersecurity Act (SFS 2025:1506), which entered into force on 15 January 2026 and replaced the earlier NIS Act.
Who does NIS2 cover?
Both essential and important entities across sectors such as energy, healthcare, transport, digital infrastructure, and public administration, generally above a defined size threshold.
Does NIS2 require security awareness training?
Yes. The Swedish law requires security training for management, and the directive's risk-management duties make broader awareness training a practical necessity, since people remain the most targeted part of any organization.
What happens if an incident occurs?
Significant incidents must be reported to the national authority within strict timeframes, usually an early warning within 24 hours and a more detailed report within 72 hours.
This information is provided for general guidance only and does not constitute legal or professional advice.
Sources:
Swedish Energy Agency, New Cybersecurity Act enters into force,