NIS2 Directive 2025 – New Cybersecurity Requirements in Sweden

Starting in 2025, the NIS2 Directive will be incorporated into Swedish law through the new Cybersecurity Act. This means stricter requirements for how both private and public sector organizations work with information and network security. In this article, we explain what NIS2 is, what the requirements entail, and how you can prepare.

What is the NIS2 Directive?

NIS2 (“The Directive on Security of Network and Information Systems”) is an EU directive adopted in December 2022, replacing the previous NIS Directive from 2016.
Its purpose is to raise the overall level of cybersecurity across the EU by introducing:

 

  • Stricter supplier security

  • Clearer management responsibility

  • Tougher incident reporting requirements

  • Enhanced supply chain security

To ensure compliance, the directive introduces significant penalties and increased supervision.

How NIS2 Affects Swedish Organizations

In March 2024, the Swedish government presented a proposal to implement NIS2 through the Cybersecurity Act 2025.
The new law covers 18 essential sectors and applies to nearly all public sector activities in Sweden. Its goal is to create a cultural shift in information and cybersecurity practices.

The Nine Security Areas of NIS2

The Cybersecurity Act sets requirements in the following areas:

 

  1. Incident handling

  2. Business continuity management

  3. Supply chain security

  4. Secure development and maintenance of IT systems

  5. Cryptography and encryption strategies

  6. Personnel security

  7. Access control and asset management

  8. Secure communication

  9. Authentication

How to Prepare for NIS2

Implementing NIS2 requirements involves both strategic and practical measures:

 

  • Map existing processes and compare them with NIS2 requirements

  • Identify gaps and risk areas

  • Develop an implementation plan

  • Train management and key staff

  • Test and improve security routines

Seadot Cybersecurity – Support Throughout the NIS2 Process

At Seadot Cybersecurity, we help you meet NIS2 requirements in a structured and cost-effective way. Our services include:

 

  • Analysis and current state assessment

  • Consulting and implementation planning

  • Project management and execution

  • Training for management and boards

  • Review and internal audit

Ready to take the next step?

Do you have questions or want to know more about how Seadot can help your organization?
We are ready to support you in strengthening your information security.

Contact us

Email:
info@seadot.se
For general inquiries

Emma Stewén, Deputy CEO
emma@seadot.se
+46 76 601 15 10
For questions about our services