NIS-lagen
Swedish act SFS 2018:1174, in force since 2018-08-01: Lag om informationssäkerhet för samhällsviktiga och digitala tjänster. The responsible authority is Myndigheten för samhällsskydd och beredskap. The act is tied to EU legislation.
Register
- Reference
- SFS 2018:1174
- In force
- 2018-08-01
- Responsible authority
- Myndigheten för samhällsskydd och beredskap
- Area
- Data protection and cybersecurity
- EU legislation
- Genomför direktiv (EU) 2016/1148, efterföljt av direktiv (EU) 2022/2555
- Read date
- 2026-08-16
Official text
Preparatory works
- Prop. 2017/18:205Informationssäkerhet för samhällsviktiga och digitala tjänster
- SOU 2017:36Informationssäkerhet för samhällsviktiga och digitala tjänster
Regulations
- MSBFS 2018:8Föreskrifter om informationssäkerhet för leverantörer av samhällsviktiga tjänster
- MSBFS 2018:9Föreskrifter om rapportering av incidenter för leverantörer av samhällsviktiga tjänster
Standards
- Information security management systems, requirements
SS-EN ISO/IEC 27001:2022Svenska institutet för standarder (SIS)
The requirements for an information security management system: scope, risk assessment, risk treatment, statement of applicability and management review. It is the most common basis when a business must show appropriate technical and organisational measures.
- Guidance on information security controls
SS-EN ISO/IEC 27002:2022Svenska institutet för standarder (SIS)
The catalogue of security controls that belongs with the management system: organisational, people, physical and technological controls, with the purpose and application of each.
- Guidance on managing information security risks
SS-ISO/IEC 27005:2022Svenska institutet för standarder (SIS)
The method for identifying, analysing, evaluating and treating information security risks, and how that work connects to the management system and to decisions on acceptable risk.
- Artificial intelligence management systems, requirements
SS-ISO/IEC 42001:2023Svenska institutet för standarder (SIS)
The requirements for governing AI systems: accountability, impact assessment, data, life cycle, logging and monitoring. It serves as a method when an organisation must show AI governance to customers and supervisors.
- Business continuity management systems, requirements
SS-EN ISO 22301:2019Svenska institutet för standarder (SIS)
The requirements for continuity management: impact analysis, recovery times, continuity plans, exercises and review. Financial undertakings and public sector suppliers meet the same requirements again in supervisory rules on operations and outsourcing.
- Information security incident management, principles
SS-EN ISO/IEC 27035-1:2023Svenska institutet för standarder (SIS)
The principles of incident management: preparation, detection, assessment, response and lessons learned. Used alongside the duty to report personal data breaches and incidents in essential services.
Questions resting on the act
Supervision
Other acts in the same area
- LEK · SFS 2022:482
- Dataskyddslagen · SFS 2018:218
- Kamerabevakningslagen · SFS 2018:1200
- Kreditupplysningslagen · SFS 1973:1173
Swedish law
Ready-made pack
DORA/NIS2 pack
€149, one-time purchase
Operational resilience and incident reporting in one pack: DORA, NIS2 and the Cyber Resilience Act with the duties in one structure.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.