Alessandro AleddaInsider Threat and Risk

ITER/SESweden

What the record establishes for Sweden: the bodies an insider event is reported to, the channel each takes, and the act that transposes the NIS2 Directive, Directive (EU) 2022/2555.

Recipients
4 of 4
Reporting address
Recorded
NIS2
In force 15 January 2026, by the transitional provisions
Terms moved
No
Sources cited
5
Last read
3 SEPTEMBER 2026

Recipients

Reached underBodyChannelSource
Data protection authorityGDPR, article 33Integritetsskyddsmyndigheten reportededpb members
CSIRT or competent authorityNIS2, article 23The act designates nobody by name. In practice the reports reach the Nationellt cybersäkerhetscenter, whose CERT-SE unit forwards them to the supervisory authorities reported

https://cyberportal.mcf.se/checked 2026-09-11

The Incidentrapporteringsverktyget inside the Cyberportalen. The regulations took effect on 1 July 2026 and the tool opened the same day. The Centre states that the tool is still in development and publishes a fallback procedure for use when it is unavailable.

se cybersakerhetslag 2025 · ncsc se incidentrapportering
Financial supervisorDORA, article 19Finansinspektionen reportedeba competent authorities
Market authorityMAR, article 17Finansinspektionen (FI) reportedesma mar nca

Transposition of NIS2 binding

ActCybersäkerhetslag (2025:1506)
In force15 January 2026, by the transitional provisions
RecipientThe authority the Government designates, which the act itself does not name
Moves a termNo. None in the terms. Section 5 owes the first notice «så snart det kan ske, dock senast 24 timmar efter det att verksamhetsutövaren har fått kännedom om incidenten»; section 6 gives trust service providers twenty-four hours and everyone else «senast 72 timmar efter sådan kännedom»; section 8 puts the final report «senast en månad efter incidentanmälan», with a situation report instead where the incident is still running. What the act does not do is name the recipient: sections 5 and 6 owe the report to «den myndighet som regeringen bestämmer».
StandingRead in the act as published in Svensk författningssamling. The act designates the recipient by reference rather than by name; the designation is answered outside the act, by the National Cybersecurity Centre that receives the reports. The act also repeals the 2018 act on information security for essential and digital services.
Sourcese cybersakerhetslag 2025

An event in Sweden

The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.