Legal sources with official primary sources

Printed ·

Skip to main content
Skip to the answer

What does NIS2 require of companies?

The information security directive, the national implementation and the supervisory authority.

Share this page

Answer node · legal-2026-08-25 · hash f9732d9bc9419cc9

Which primary sources apply to NIS-lagen?

Same question, same answer — and room to ask a follow-up.

Open the question in NovaCopilot

Primary sources

  • SFS 2018:1174Lag om informationssäkerhet för samhällsviktiga och digitala tjänster

    Swedish Code of Statutes, the Riksdag

    Open the source
  • Prop. 2017/18:205Informationssäkerhet för samhällsviktiga och digitala tjänster

    Riksdag document register

    Open the source
  • SOU 2017:36Informationssäkerhet för samhällsviktiga och digitala tjänster

    Riksdag document register

    Open the source
  • MSBFS 2018:8Föreskrifter om informationssäkerhet för leverantörer av samhällsviktiga tjänster

    Myndigheten för samhällsskydd och beredskap, regulatory collection

    Open the source
  • MSBFS 2018:9Föreskrifter om rapportering av incidenter för leverantörer av samhällsviktiga tjänster

    Myndigheten för samhällsskydd och beredskap, regulatory collection

    Open the source

Secondary sources

  • 32022L2555Genomför direktiv (EU) 2016/1148, efterföljt av direktiv (EU) 2022/2555

    EUR-Lex

    Open the source
  • MSBFSMyndigheten för samhällsskydd och beredskap

    Myndigheten för samhällsskydd och beredskap, regulatory collection

    Open the source

Summary

  • NIS-lagen carries the identifier SFS 2018:1174 and entered into force on 2018-08-01.
  • Myndigheten för samhällsskydd och beredskap is the authority named for supervision and regulations under NIS-lagen.
  • NIS-lagen: Genomför direktiv (EU) 2016/1148, efterföljt av direktiv (EU) 2022/2555.
  • The preparatory works for NIS-lagen are Prop. 2017/18:205, SOU 2017:36.
  • Under NIS-lagen the register holds the regulations MSBFS 2018:8, MSBFS 2018:9.
  • The question sits in Cybersecurity, where the register holds 1 read statutes.

Application

  • In comparable situations NIS-lagen is read together with the other statutes in Cybersecurity and with the responsible authority's regulations.
  • This description rests only on the sources listed above. It is not an assessment of an individual matter and not legal advice.

What the register has not read

  • No guiding decisions are read for NIS-lagen.

More questions with their own answer

The same address returns the same answer as long as the build version holds. legal-answer/1.1.0 · 2026-08-25

Next step

Three ways to put the register to work in your own practice.

Start with your task