Regulation
NIS2 and the Cybersecurity Act: does it apply to you?
Sweden's new Cybersecurity Act has applied since January 2026. Most small businesses are not directly covered, but many are affected through their customers. Here is the straight answer.
The EU NIS2 Directive became Swedish law through the Cybersecurity Act (2025:1506). The Act has applied since 15 January 2026. It sets requirements for risk management, incident reporting and management responsibility. But only certain entities are covered.
Who is covered?
The Act applies to essential and important entities in designated sectors. This includes energy, transport, banking, healthcare, drinking water, digital infrastructure, post, waste, food, certain manufacturing of equipment, and digital services such as cloud providers.
As a rule, the company must be at least medium-sized. That is roughly 50 employees or EUR 10 million in turnover. A small agency, shop or consultancy is therefore usually not directly covered. Certain providers of digital infrastructure are exempt from the size requirement.
Supervision is handled sector by sector by several authorities. The Swedish Civil Contingencies Agency (MCF), formerly MSB, has a coordinating role.
How small businesses are still affected
Here is what is easy to miss. NIS2 requires affected organisations to have control over security in their supply chain. If you sell IT services, operations or software to a municipality, an energy company or a healthcare provider, you may get questions about your own security. This can involve incident routines, updates and where data is stored.
Answering those questions well becomes a competitive advantage. Here is what a reasonable minimum can look like for a small supplier:
- Use a proper password manager such as 1Password or Bitwarden so that no passwords live in spreadsheets or emails.
- Choose subcontractors with clear EU data storage and documented security. Our provenance labels and certificates are a shortcut.
- Document how you handle updates, passwords and access rights.
- Have a simple incident routine: who does what if something happens?
- For sensitive documents and collaboration: try self-hosted storage with Nextcloud.
In short
Are you directly affected? Probably not, if you are small and outside the sectors. Are you indirectly affected? More and more often, through your customers. Read more in our overview.
Sources
Tools mentioned
Bitwarden
Bitwarden Inc.
The open-source standard among password managers with low price and selectable EU region for data storage. The catch: the company is American, so the CLOUD Act applies regardless of where data is stored. If you want to avoid it completely you must self-host yourself.
- Open source with annual third-party audits
- EU server region can be selected at registration
- American company covered by the CLOUD Act even with EU storage
Best for: Cost-conscious small businesses that want open source and the option to self-host
Nextcloud
Nextcloud
German platform for files, collaboration, chat and calendar, Europe's great alternative to Google Workspace and Microsoft 365.
- Comprehensive: files, chat, calendar, documents
- German, can run on own EU servers
- Requires server operation
Best for: Companies that want control over files and collaboration within the EU.
1Password
AgileBits Inc.
The market's most polished password manager with the industry's broadest certification portfolio (ISO 27001/27017/27018/27701, SOC 2). The catch: Canadian company with American venture capital, no free tier, and not open source.
- Best in class on usability and design, which drives high adoption among employees
- EU data residency can be selected at account creation
- No free tier, only 14-day trial
Best for: Companies that prioritize usability and certifications over EU jurisdiction
Related articles
This is general information, not legal advice. See How we review.