Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

NIS-lagen

Swedish act SFS 2018:1174, in force since 2018-08-01: Lag om informationssäkerhet för samhällsviktiga och digitala tjänster. The responsible authority is Myndigheten för samhällsskydd och beredskap. The act is tied to EU legislation.

Share this page

Register

Reference
SFS 2018:1174
In force
2018-08-01
Responsible authority
Myndigheten för samhällsskydd och beredskap
Area
Data protection and cybersecurity
EU legislation
Genomför direktiv (EU) 2016/1148, efterföljt av direktiv (EU) 2022/2555
Read date
2026-08-16

Official text

Preparatory works

  • Prop. 2017/18:205Informationssäkerhet för samhällsviktiga och digitala tjänster
  • SOU 2017:36Informationssäkerhet för samhällsviktiga och digitala tjänster

Regulations

  • MSBFS 2018:8Föreskrifter om informationssäkerhet för leverantörer av samhällsviktiga tjänster
  • MSBFS 2018:9Föreskrifter om rapportering av incidenter för leverantörer av samhällsviktiga tjänster

Standards

  • Information security management systems, requirements

    SS-EN ISO/IEC 27001:2022Svenska institutet för standarder (SIS)

    The requirements for an information security management system: scope, risk assessment, risk treatment, statement of applicability and management review. It is the most common basis when a business must show appropriate technical and organisational measures.

  • Guidance on information security controls

    SS-EN ISO/IEC 27002:2022Svenska institutet för standarder (SIS)

    The catalogue of security controls that belongs with the management system: organisational, people, physical and technological controls, with the purpose and application of each.

  • Guidance on managing information security risks

    SS-ISO/IEC 27005:2022Svenska institutet för standarder (SIS)

    The method for identifying, analysing, evaluating and treating information security risks, and how that work connects to the management system and to decisions on acceptable risk.

  • Artificial intelligence management systems, requirements

    SS-ISO/IEC 42001:2023Svenska institutet för standarder (SIS)

    The requirements for governing AI systems: accountability, impact assessment, data, life cycle, logging and monitoring. It serves as a method when an organisation must show AI governance to customers and supervisors.

  • Business continuity management systems, requirements

    SS-EN ISO 22301:2019Svenska institutet för standarder (SIS)

    The requirements for continuity management: impact analysis, recovery times, continuity plans, exercises and review. Financial undertakings and public sector suppliers meet the same requirements again in supervisory rules on operations and outsourcing.

  • Information security incident management, principles

    SS-EN ISO/IEC 27035-1:2023Svenska institutet för standarder (SIS)

    The principles of incident management: preparation, detection, assessment, response and lessons learned. Used alongside the duty to report personal data breaches and incidents in essential services.

Questions resting on the act

Supervision

Other acts in the same area

Swedish law

Ready-made pack

DORA/NIS2 pack

€149, one-time purchase

Operational resilience and incident reporting in one pack: DORA, NIS2 and the Cyber Resilience Act with the duties in one structure.

Next step

Three ways to put the register to work in your own practice.

Start with your task