If you work in IT, security or compliance in Sweden, you’ve probably seen the messaging by now, “NIS2 becomes enforced on October 1st.” “The preparation period is over.” “Non-compliance can now cost you millions.”
Some of that is accurate. Some of it isn’t and the gap matters. If you believe the law “starts” on October 1, you may already be behind on obligations that have applied since January.
Here’s what’s actually happening and what to do about it whether you’ve been preparing since day one or are only now paying attention.
Key Takeaways
- NIS2 didn’t start on October 1: Sweden’s Cybersäkerhetslagen (Cybersecurity Act) entered into force on 15 January 2026. In-scope organisations have already had to register with the Swedish Civil Defence and Resilience Agency (MCF) and demonstrate risk management since then.
- What actually happens on October 1, 2026: MCF’s supplementary regulations on security measures, management training, security audits and security scanning take legal effect, turning the law’s general requirements into specific, checkable ones.
- NIS2 covers 18 sectors: Generally applies to medium and large organisations (roughly 50+ employees or €10 million+ annual turnover) split into “essential” and “important” entities with different levels of scrutiny.
- Fines reach €10 million or 2% of global annual turnover for essential entities (€7 million / 1.4% for important entities) whichever figure is higher, applied per infringement.
- Most real breaches still start with an email: Phishing and business email compromise remain the most common way attackers get their first foothold exactly why NIS2’s risk-management measures lean so heavily on access control, incident handling and staff training.
- Compliance built only for the audit tends to fail the same way real attacks succeed: Organisations that hold up under both a regulator’s review and an actual attack treat this as an operational capability, not a paperwork exercise.
NIS2 Didn’t Begin on October 1 Here’s the Real Timeline
Take a regional healthcare provider or a mid-sized municipal IT department as an example. If they identified themselves as in scope earlier this year, their year has actually looked like this:
| Date | What happened / happens |
| 11 December 2025 | Sweden’s Cybersäkerhetslag (2025:1506) is adopted by the Riksdag |
| 15 January 2026 | The law enters into force – NIS2 obligations become legally binding in Sweden |
| 16 February 2026 | Deadline for in-scope entities to register/notify MCF (or their sector authority) |
| 1 July 2026 | Regulations on incident reporting (the 24-hour/72-hour/1-month timeline) take effect; MCF’s cyber remit transfers to the new National Cybersecurity Center (NCSC) at the Swedish National Defence Radio Establishment (FRA) |
| 1 October 2026 | Regulations on security measures, management training, security audits and security scanning take effect |
By February, that healthcare provider or municipality should already have registered and completed an initial risk assessment. What October 1 adds is precision, MCF’s new regulations spell out, in much more concrete terms, what an acceptable incident handling plan looks like, what counts as adequate management training and what a security audit or scan needs to cover. Before October 1, “appropriate and proportionate measures” was a general legal standard. After October 1, it comes with a specific rulebook to be measured against.
That’s a real, meaningful deadline but it’s not when NIS2 “starts.” It’s when the fine print stops being vague.
One caution if you operate outside Sweden too, don’t assume October 1 is an EU-wide date. Belgium has enforced its NIS2 law since October 2024. Germany’s registration deadline was April 2026. Italy separately set its own October 1, 2026 deadline for adopting security measures under different national legislation. If you have operations in multiple EU countries, check each country’s specific timeline rather than applying one date across the board.
Who Actually Has to Comply with NIS2?
NIS2 applies across 18 sectors, generally to organisations with 50 or more employees or over €10 million in annual turnover though some smaller organisations fall in scope anyway if they’re considered critical to their sector (for example, a sole regional service provider).
In-scope organisations are classified as either:
- Essential entities broadly, larger organisations in the highest-criticality sectors including energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management (B2B), public administration and space. Qualified trust service providers, top-level domain registries and DNS providers count as essential regardless of size and unusually, so do medium-sized providers of electronic communications networks or services which don’t get the “medium = important” treatment most other sectors do.
- Important entities broadly, medium-sized organisations in those same sectors, plus organisations in sectors like postal and courier services, waste management, chemicals, food production, manufacturing, digital marketplaces and research.
The exact classification depends on both sector and size and it directly affects your fine exposure (more on that below) so it’s worth getting a proper assessment rather than guessing.
It’s also worth remembering that NIS2 reaches beyond directly regulated organisations, if you supply digital services, IT or other critical inputs to an in-scope entity, you may be pulled into their supply chain security requirements even if you’re not directly covered yourself.
What You Should Already Have Done and What Changes on October 1

If you’re only starting your NIS2 work now, the practical priority order is confirm your scope and entity classification, register if you haven’t, complete a documented risk assessment and then work through the October 1 requirements rather than treating October 1 as the first item on the list.
Where the Real Risk Sits: How Organisations Actually Get Breached
Regulatory deadlines aside, NIS2’s security requirements exist because of how organisations are actually compromised and email remains the dominant route in. Estimates vary by methodology and source but figures in the 68 – 90%+ range for cyberattacks originating through email or phishing show up consistently across industry and government reporting. Business email compromise is particularly dangerous because it often requires no malware. A convincing impersonation of a CEO, supplier or colleague can be enough.
That’s not the only risk NIS2 asks organisations to manage supply chain compromise, unpatched or exposed systems, stolen credentials and ransomware all feature heavily in incident data too but it explains why so much of Article 21’s risk-management framework centres on things like access control, multi-factor authentication, incident handling and staff cyber hygiene training. The regulation isn’t asking for security theatre, it’s asking organisations to close the gap that attackers use most.
What Happens If You Don’t Comply

Two nuances worth flagging because they’re commonly oversimplified in marketing materials are fines are calculated per infringement, not as a single blanket annual cap and the temporary executive ban applies specifically to essential entities, not every organisation in scope.
Building NIS2 Compliance That Actually Holds Up
Article 21 of the NIS2 Directive sets out ten minimum areas every in-scope organisation needs to address. They’re intentionally outcome-based the law tells you what to achieve not which specific product to buy:
| Measure | In practice | |
| 1 | Risk analysis & security policy | Documented, kept current not a one-time exercise |
| 2 | Incident handling | Detection, response and reporting aligned to the 24h/72h/1-month timeline |
| 3 | Business continuity | Backup, disaster recovery, crisis management |
| 4 | Supply chain security | Assessing and managing risk from direct suppliers and service providers |
| 5 | Secure system acquisition & development | Security built into procurement and development including vulnerability handling |
| 6 | Effectiveness assessment | Auditing whether your measures actually work, not just that they exist |
| 7 | Cyber hygiene & training | Awareness training for staff and management alike |
| 8 | Cryptography & encryption | Policies for when and how encryption is used |
| 9 | HR security, access control & asset management | Who can access what, and why |
| 10 | Multi-factor authentication & secure communications | MFA and secure channels for voice, video and text |
The organisations that pass both a regulator’s review and a real attack attempt are the ones that treat these as an ongoing operational programme continuous monitoring, tested response plans and staff who’ve actually been trained rather than just emailed a policy document instead of a folder of documents assembled once a year.
This is where eBuilder Security fits in. Our MDR/SOC operates 24/7 to cover incident detection and handling (measures 2 and 6), our vulnerability management and penetration testing address secure systems and supply chain risk (measures 4 and 5), our security awareness training platform, Complorer, builds the staff-level cyber hygiene NIS2 explicitly requires (measure 7), and our CISO advisory service helps translate all of this into the governance and management-body accountability Article 20 expects. None of this replaces your own compliance judgment or legal advice but it does mean you’re not building each of these ten measures from scratch.
Conclusion
October 1, 2026 isn’t when NIS2 starts for Swedish organisations it’s when “we’re working on it” stops being an adequate answer to a regulator’s question. The law has applied since January. Registration has been required since February. What changes on October 1 is that the specific yardstick for security measures, training, audits and scanning becomes law which means gaps that were previously a matter of interpretation become straightforward findings.
If you’re not yet confident where your organisation stands, that’s the right question to answer before October, not after.
Frequently Asked Questions
Does NIS2 apply to us if we’re not in an obviously “critical” sector?
Possibly. NIS2 covers 18 sectors, some of which like manufacturing, food production, digital services and research aren’t traditionally thought of as critical infrastructure. Size thresholds (50+ employees or €10M+ turnover) bring many mid-sized organisations into scope even outside sectors like energy or health.
We’re already ISO 27001 certified does that mean we’re NIS2 compliant?
It covers a meaningful part of it but not all of it. ISO 27001 overlaps significantly with Article 21’s risk-management measures but NIS2 adds specific obligations incident reporting timelines, management-body personal accountability and supply chain security requirements that aren’t automatically covered by certification alone.
Are the fines calculated per year or per incident?
Neither, precisely. Fines are set per infringement of the relevant obligations (security measures or reporting duties) which means a single organisation could face multiple penalties if multiple obligations are breached not one capped annual figure.
What’s the next deadline after October 1?
National regulations under Cybersäkerhetslagen are still being issued in stages through 2026 with further MCF guidance expected. Organisations already in scope should treat compliance as an ongoing programme rather than a one-time deadline to clear.
This post is also available in:
Svenska