Vinge Insights

The Swedish Cybersecurity Act autumn 2026 – supervision so far and new requirements from 1 October

Upgrade

Over the summer, Vinge has assessed how supervision has been conducted so far through contacts with the supervisory authorities and by requesting copies of decisions taken. The assessment demonstrates that supervision has commenced but is still at an early stage, with the focus on the duty to notify and incident reporting. Meanwhile, the new regulations, which apply from 1 October, mean that more detailed requirements will be imposed on operators’ cybersecurity work and supplier relationships - requirements that may also have implications for agreements already in place.

Where do we stand now?

The Swedish Cybersecurity Act (2025:1506) came into force on 15 January 2026 and transposes Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (the NIS2 Directive) into Swedish law. The new Swedish Cybersecurity Act is accompanied by the Cybersecurity Ordinance (2025:1507), which, amongst other things, designates the supervisory authority responsible for each sector.

The regulatory framework is being developed gradually. The first regulations on the notification and identification of operators (MCFFS 2026:1) came into force as early as 2 February 2026. Subsequently, regulations on incident reporting and the duty to provide information (MCFFS 2026:8) have been issued, with effect from 1 July 2026. From 1 October 2026, regulations and general guidelines on security measures and management training (MCFFS 2026:11) as well as on security audits and security scanning (MCFFS 2026:12) will also apply.

A significant organisational change is that, on 1 July 2026, the Swedish Civil Defence and Resilience Agency’s (MCF) central cyber operations were transferred to the National Cyber Security Centre (NCSC) at the National Defence Radio Establishment (FRA). In connection with the transfer, the mandate for issuing regulations passed to the FRA and the coordinating role for the regulation to the NCSC at the FRA. However, the regulations issued by MCF prior to 1 July 2026 remain in force for the time being with their content unchanged. The change also means that notifications and incident reports shall now be submitted to the NCSC.

The regulatory framework in brief

The Swedish Cybersecurity Act has a sector-based scope and covers 18 designated sectors. For private operators, the Act essentially applies to organisations established in Sweden that are of a size equivalent to or larger than a medium-sized enterprise. Smaller organisations may also be covered, for example if they are the sole provider in Sweden of a service that is essential to critical societal or economic activities. Government agencies, regions, municipalities and municipal associations are also covered, with exceptions including activities covered by the DORA Regulation and certain security-sensitive or law enforcement activities.

Operators are classified as essential and important operators. The classification affects, amongst other things, the scope of supervision and the level of administrative fines. The key obligations under the Swedish Cybersecurity Act are to notify the operation and to implement appropriate and proportionate security measures based on an all-risk approach, which includes, amongst other things, risk management, incident, business continuity and crisis management, supply chain security, cyber hygiene and access control. In addition, there is a training requirement for the operator’s management, as well as an obligation to report significant incidents and, in certain cases, to inform service recipients of significant incidents and cyber threats.

Administrative fines may be imposed by a supervisory authority in the event of a breach of these obligations. For essential operators, the fine may amount to the higher of 2 per cent of total global annual turnover or 10,000,000 euros, and for important operators to the higher of 1.4 per cent of total global annual turnover or 7,000,000 euros. For public sector operators, i.e. government agencies, municipalities and regions, the maximum administrative fine is SEK 10,000,000.

The Cybersecurity Ordinance designates the thirteen supervisory authorities, including the Swedish Transport Agency, the Swedish Financial Supervisory Authority, the Swedish Post and Telecom Authority (PTS), the Swedish Food Agency, the Swedish Medical Products Agency, the Swedish Health and Social Care Inspectorate (IVO) and six county administrative boards.

Supervision – what has happened since the Act came into force?

For essential operators, supervision may be carried out proactively, whilst supervisory measures against important operators may only be taken when the supervisory authority has reason to believe that the regulations are not being complied with. The supervisory authorities are entitled to request information and documents, carry out security audits and security scans, and require operators to cooperate, if necessary subject to a conditional fine. Interventions in the event of a breach of obligations may take the form of a remark, an order, a ban on holding a management position, or an administrative fine.

During the summer of 2026, Vinge has, through contacts with the supervisory authorities and by requesting copies of decisions taken, reviewed how supervision has been conducted to date. The information reflects the status at the time of the review and does not claim to be exhaustive. Further cases may have been initiated or decisions taken since then, and parts of the material are subject to confidentiality.

Subject to these reservations, it can be noted that five out of thirteen supervisory authorities had initiated supervisory cases or taken decisions under the Swedish Cybersecurity Act. The remaining eight authorities - the Swedish Energy Agency, the Swedish Financial Supervisory Authority, the Health and Social Care Inspectorate (IVO), the Swedish Medical Products Agency, the Swedish Post and Telecom Authority (PTS), the County Administrative Board of Stockholm, the County Administrative Board of Örebro and the County Administrative Board of Östergötland - had, at the time of our audit, not taken any decisions under the Act. However, the Swedish Post and Telecom Authority (PTS) has carried out checks pursuant to Articles 20 and 21 of the eIDAS Regulation, which partly involve verifying compliance with the requirements of Article 21 of the NIS2 Directive.

At the time of our audit, the Swedish Transport Agency had initiated 16 supervisory cases, 14 of which concerned the notification obligation and two concerned incident reporting. All resulted in orders to provide information. The two decisions reviewed by Vinge concerned, on the one hand, an order to comment on a failure to notify, and, on the other hand, an order to submit a missing final or status report following an incident. The decisions state that a new order may be issued if the order is not complied with, and that such an order may be combined with a conditional fine.

The County Administrative Board of Norrbotten had made nine decisions. Four of these concerned cases initiated after operators themselves had reported significant incidents and were concluded without any further action being taken. The remaining five concerned orders to submit documents after the County Administrative Board had identified operations within its supervisory area for which no notification had been received under the Swedish Cybersecurity Act.

The County Administrative Board of Skåne had initiated four supervisory cases. In the two decisions reviewed by Vinge, information was requested regarding municipalities’ cybersecurity work, including risk analysis, cyber hygiene, incident management and supply chain security. Both cases were closed without further action after the municipalities had provided the requested information.  

The County Administrative Board of Västra Götaland had taken decisions in two cases concerning municipalities. The cases were concluded with remarks, which is one of the forms of intervention that, under the Swedish Cybersecurity Act, may be used when there are no grounds for intervening in any other way. The review was based on information provided by the operators themselves and did not involve any detailed examination of the content of the policy documents. It is not entirely clear what shortcomings lay behind the remarks, as parts of the supporting documentation are subject to confidentiality.  

At the same time, the Swedish Food Agency had sent a request for information to 98 operators whom the authority had deemed to be subject to the notification requirement. The aim was to ascertain whether the notification requirement had been met.

Differences between authorities

Supervisory activities differ markedly between the authorities. To date, the cases have mainly concerned the notification obligation and incident reporting, and public sector operators predominate among those examined. As far as could be ascertained from the documentation reviewed by Vinge, no supervisory authority had carried out any security audits or security scans.

Nor had any administrative fines been imposed in the cases reviewed. The orders issued have primarily concerned the obligation to provide information, documents or incident reports. Where security measures have been reviewed, supervision has mainly taken the form of desk-based supervision, based on information provided by the operator itself.

There may be several explanations for the differences in the authorities’ levels of activity. The regulatory framework is still new, and the more detailed provisions on security measures will first apply from 1 October 2026. Differences in the size and composition of the areas subject to supervision may also be a factor, as may the fact that certain authorities may have prioritised guidance and mapping over intervention. Furthermore, supervision of essential operators may be carried out proactively, whilst supervisory measures against important operators require grounds for suspecting non-compliance with the regulatory framework, which in itself may affect the caseload.

As the regulatory framework becomes established and the new regulations come into force, supervision may be broadened from notification and reporting issues to operators’ security measures, management training and supply chain security.

New regulations from 1 October

Security measures and management training

MCFFS 2026:11 contains more detailed provisions on security measures and management training and clarifies what the obligations already set out in the Swedish Cybersecurity Act actually entail. The regulation requires operators to carry out systematic and risk-based cybersecurity work from an all-risk perspective. This work must be carried out on an ongoing basis, monitored and improved where necessary, and integrated with the organisation’s existing methods of managing and governing its operations.

Among other things, the operator must appoint a coordinator, information owner and system owner. The regulation also specifies the requirements for information classification and risk management. Information must be assessed on the basis of the need for confidentiality, integrity and availability, whilst risk management must be based on established levels and criteria for impact, probability and risk acceptance. Selected security measures must be documented in an action plan.

Management must approve and monitor the implementation of the security measures and be informed of the operator’s cybersecurity level as required and at least once a year.

Existing supplier contracts may need to be reviewed

Supply chain security is already part of the requirements of the Swedish Cybersecurity Act, but MCFFS 2026:11 specifies how risks associated with suppliers are to be addressed.

Prior to the acquisition of systems or the outsourcing of data processing, risks must be assessed and managed through contractual requirements imposed on the supplier. Existing supplier agreements must also be assessed from a risk perspective. If they contain inadequate cybersecurity requirements, the risks must be managed. Consequently, agreements entered into before 1 October 2026 may also need to be amended.

Security audits and security scans

MCFFS 2026:12 also comes into force on 1 October. The regulation is primarily aimed at the supervisory authorities and specifies how security audits and security scans are to be conducted. For operators, it also provides a clearer picture of what more in-depth supervision may entail.

A security audit is intended to assess the operator’s level of cyber security and whether the security measures meet the requirements of the legislation. The audit covers both the design of the measures and how they are actually implemented, and may include document reviews, interviews, technical checks and, where necessary, inspections of premises.

Security scans are carried out by the supervisory authority, which may, however, engage an external party, and are intended to assess the effectiveness of the security measures implemented in the digital environment. The selection of operators and systems must be risk-based, and the implementation must be planned in such a way as to minimise the risk of operational disruption. Any deficiencies or vulnerabilities identified must be reported to the operator without delay.

What should operators do now?

In light of the supervision conducted thus far and the new regulations, there are a number of areas that warrant particular attention.

  • Ensure that the notification has been submitted. The assessment of whether the organisation is covered should be documented, and the notification under the Swedish Cybersecurity Act shall be submitted to the NCSC. Any changes in circumstances must be reported within 14 days. The obligation to notify has so far been a recurring theme in the supervision.
  • Be prepared to provide a written account of your cybersecurity work. To date, supervision has largely been carried out by the supervisory authority requesting written reports and basing its assessment on the operator’s own information. Up-to-date and quality-assured documentation makes it easier to provide such a report.
  • Ensure that the incident procedure works in practice. The reporting obligation comprises several stages with tight deadlines, and the initial notification must be submitted within 24 hours. You should therefore ensure that you have a procedure in place that enables you to meet these requirements in practice, and practise the procedure regularly so that the assessment of whether an incident is significant and the reporting process function effectively also beyond normal working hours. The procedure should also specify which internal and external contacts are to be alerted at an early stage, so that, for example, legal support can be accessed at short notice when the incident is to be assessed and the reporting is to be drafted.
  • Review the security measures against the specified requirements. From 1 October, the obligation to implement appropriate and proportionate security measures is clarified, including requirements regarding roles, information classification, risk management, risk acceptance, management approval and information on the level of cyber security. A comparison between existing policy documents and working practices and the new requirements can clarify which elements are already in place and which need to be supplemented.
  • Carry out a review of supplier contracts. Risks must be assessed and addressed even before systems are acquired or data processing is outsourced, and cyber security in the supply chain must therefore be managed both prior to new agreements and throughout the contractual relationship. As existing agreements with inadequate cyber security requirements also need to be addressed, agreements entered into before 1 October 2026 may need to be amended.

Conclusion

The first months since the Swedish Cybersecurity Act came into force have shown that supervision has so far focused primarily on the fundamental obligations to notify the organisation and report incidents. From 1 October, the requirements regarding the practical cybersecurity work will become more detailed, whilst the supervisory authorities will be given a clearer framework for security audits and security scans.

This suggests that supervision may gradually be extended to cover matters such as risk management, governance, security measures and supplier relationships. Therefore, it is becoming increasingly important for operators to be able to demonstrate not only that processes and policy documents are in place, but also how the requirements are implemented in practice.

The Swedish Cybersecurity Act and the surrounding regulatory framework are extensive and affect different organisations in different ways. The overview above is therefore general in nature and reflects the supervisory activities and decisions which Vinge had access to at the time of the review.

Vinge continuously monitors developments and regularly assists operators both in their preparatory work and in critical situations, not least when assessing and reporting significant incidents and in contacts with supervisory authorities. We welcome you to contact us for further information and for an assessment of what the regulatory framework means for your specific organisation.

If you have any questions or would like to establish a point of contact before an incident occurs, please get in touch with our cybersecurity team at Vinge.