What the law actually says
On 15 January 2026, Sweden's new cyber security act came into force. It implements the EU NIS2 directive and imposes stricter requirements on risk management, incident reporting and governance for organisations in 18 designated sectors, including energy, transport, health, water, digital infrastructure and public administration.
The requirements have teeth. For the most critical organisations, penalties can reach 10 million euro or 2 percent of global turnover, whichever is higher. Management also carries explicit personal responsibility, which according to PwC is one of the bigger changes from before.
You are probably not covered
Let us be straight, because there is a fair amount of fear being sold on this topic right now. If you are a services company with 15 employees in Gothenburg and you do not supply any of the designated sectors, you are most likely not covered by the law. You do not need to get certified, you do not need to hire someone for a large compliance project, and you certainly do not need to panic-buy a product because somebody called and said NIS2.
That is the honest picture. We would rather say it than sell you something you do not need.
But the chain reaches you anyway
Here comes the part that does affect you. The law requires covered organisations to take responsibility for security across their entire supply chain. They cannot protect themselves and ignore who they buy from.
In practice that means, as CGI and FAR describe, new security requirements in procurement, security clauses in contracts and recurring audits of subcontractors. Those who are covered will ask you for evidence.
So the question is not whether the law covers you. The question is whether you supply someone it covers. If you do, the questionnaire is coming, and it will probably come from your largest customer.
This is what they will ask about
We have seen this kind of supplier review land with clients who had never heard of NIS2. The questions are rarely advanced, but they are hard to answer after the fact if nobody wrote anything down:
- Do you have a designated person responsible for IT security, and who is it?
- How do you handle incidents, and within what time do you report them to us?
- Do you have multi-factor authentication on all accounts, including administrators?
- How often is backup taken, and when did you last test that it restores?
- Which subcontractors have access to our data?
- Do you have documented routines for how employees gain and lose access?
A company that can answer yes and show a document for each point keeps the business. One that answers "we will sort that out" does not.
What we recommend
- Find out whether any of your customers are covered. Do you supply energy, healthcare, transport, municipalities or digital infrastructure? Then it is only a matter of time.
- Write down what you already do. Most companies have backup, MFA and routines. What is missing is the documentation, and that is free to create.
- Appoint someone responsible. It does not have to be a security officer. It has to be a name.
- Do not wait for the questionnaire. Answering within two weeks when a customer asks is a very different thing from starting from zero under pressure.
This is exactly the kind of work included in our IT consulting: documented routines in plain language, without a certification project you do not need. And it is kept alive over time through Managed IT. Want to know how you would fare in a supplier review today? Book a free consultation and we will go through the questions together.