Sweden's Cybersecurity Act moved accountability to the board. Which parts of a shared IT operation fall in scope, what the four capabilities behind the requirements are, and six questions to answer within a week.
English · Read this paper in Svenska
NIS2 in shared municipal IT
Sweden's Cybersecurity Act moved accountability up the organisation and made compliance a governance question. Whether a shared municipal IT organisation meets the requirements comes down to three answers: which parts of the operation are in scope, who owns each part, and what happens when one of them falls. All three are map questions before they are security questions.
Where things stand
The Swedish Cybersecurity Act entered into force on 15 January 2026 and replaced the 2018 NIS rules. Supervision is distributed by sector, with a coordinating role held centrally.
What follows
Accountability sits with management and the board. Penalties are higher than before, and the requirements extend into the supply chain.
What to do
Attach every requirement to a node with an owner and a status. A requirement without a named part of the operation behind it can be described, and that is all.
What applies, and where the fact comes from
| Fact | Status | Source |
|---|---|---|
| The Swedish Cybersecurity Act entered into force on 15 January 2026 and implements NIS2 in Swedish law. | verified | National Cyber Security Centre, Det här är cybersäkerhetslagen, retrieved 19 Aug 2026 |
| The act covers entities in 18 sectors, divided into essential and important entities. | verified | Same source |
| Entities must determine for themselves whether they are covered and register with their supervisory authority. | verified | Same source |
| Registration was to be filed through the authority's digital service by 2 February 2026. | industry source | Advisense, The Swedish NIS2 Implementation, 19 Jan 2026 |
| Supervision is distributed by sector across authorities, with a coordinating role centrally. | verified | Compilation of authority information, retrieved 19 Aug 2026 |
| Penalties for essential entities can reach EUR 10 million or 2 per cent of global turnover, whichever is higher. | directive level | The NIS2 penalty framework, as reproduced in several industry summaries |
Read all of NIS2 in shared municipal IT
The rest of the paper is sent as a link to your address. It opens the text directly — no account, no password, and the address is used for nothing else unless you tick the box below.
Your address is stored so the paper can be sent, and to know which areas are being asked for. Nothing else is sent unless the box is ticked, and it can be stopped at any time.
Where this goes next
Want this applied to your organisation?
One call is enough to know if we're a fit.