ITER/SESweden
What the record establishes for Sweden: the bodies an insider event is reported to, the channel each takes, and the act that transposes the NIS2 Directive, Directive (EU) 2022/2555.
Recipients
| Reached under | Body | Channel | Source |
|---|---|---|---|
| Data protection authorityGDPR, article 33 | Integritetsskyddsmyndigheten reported | — | edpb members |
| CSIRT or competent authorityNIS2, article 23 | The act designates nobody by name. In practice the reports reach the Nationellt cybersäkerhetscenter, whose CERT-SE unit forwards them to the supervisory authorities reported | https://cyberportal.mcf.se/checked 2026-09-11 The Incidentrapporteringsverktyget inside the Cyberportalen. The regulations took effect on 1 July 2026 and the tool opened the same day. The Centre states that the tool is still in development and publishes a fallback procedure for use when it is unavailable. | se cybersakerhetslag 2025 · ncsc se incidentrapportering |
| Financial supervisorDORA, article 19 | Finansinspektionen reported | — | eba competent authorities |
| Market authorityMAR, article 17 | Finansinspektionen (FI) reported | — | esma mar nca |
Transposition of NIS2 binding
| Act | Cybersäkerhetslag (2025:1506) |
|---|---|
| In force | 15 January 2026, by the transitional provisions |
| Recipient | The authority the Government designates, which the act itself does not name |
| Moves a term | No. None in the terms. Section 5 owes the first notice «så snart det kan ske, dock senast 24 timmar efter det att verksamhetsutövaren har fått kännedom om incidenten»; section 6 gives trust service providers twenty-four hours and everyone else «senast 72 timmar efter sådan kännedom»; section 8 puts the final report «senast en månad efter incidentanmälan», with a situation report instead where the incident is still running. What the act does not do is name the recipient: sections 5 and 6 owe the report to «den myndighet som regeringen bestämmer». |
| Standing | Read in the act as published in Svensk författningssamling. The act designates the recipient by reference rather than by name; the designation is answered outside the act, by the National Cybersecurity Centre that receives the reports. The act also repeals the 2018 act on information security for essential and digital services. |
| Source | se cybersakerhetslag 2025 |
An event in Sweden
The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.
