NIS2 and the Cybersecurity Act: Does It Affect You?
By CodexierPublished 6 min read
NIS2 is the EU directive that widens cybersecurity obligations from a few critical operators to whole sectors, and Sweden has implemented it through a new cybersecurity act with MSB as coordinating authority. Most small companies are not directly covered. Many will still feel it, because a covered customer must manage risk in its supply chain and will ask its suppliers to show basic security. This guide explains who is in scope, what the obligations are, and what a small firm should do whether or not the law names it.
What NIS2 is
The first NIS directive covered a narrow set of critical operators. NIS2 replaces it with a longer sector list, a size-based rule instead of case-by-case designation, harder reporting deadlines and personal accountability for management. In Sweden it lands as the cybersecurity act, with sector authorities supervising their own areas and MSB coordinating and receiving incident reports. The law places the obligation on the covered organisation, but that organisation must in turn assess and manage the security of its suppliers, which is where most small firms meet it.
Sectors and size thresholds
Scope is decided by two tests: is the organisation active in a listed sector, and is it at least medium-sized under the EU definition, meaning roughly fifty employees or more, or a turnover above the medium-enterprise threshold. Both must be true for the general rule to apply.
| Category | Example sectors | Typical small-firm status |
|---|---|---|
| Essential entities | Energy, transport, banking, health, drinking water, digital infrastructure, public administration | Out of scope unless medium-sized or larger, or a named exception |
| Important entities | Postal services, waste, chemicals, food, manufacturing of certain goods, digital providers, research | Same size test; many mid-sized Swedish manufacturers are newly covered |
| Exceptions regardless of size | DNS providers, domain registries, trust service providers, some telecoms and cloud services | Covered even when small |
| Suppliers to covered entities | IT services, software, hosting, maintenance, logistics, any critical supplier | Not covered by law, but contractually required to meet the customer's security demands |
Sector definitions follow the directive's annexes; check with your sector authority if you are near a boundary.
Indirect effects on suppliers
A covered organisation must take supply chain security into account, which in practice means supplier questionnaires, security clauses in contracts and sometimes audits. If you build or host websites, run software for a hospital region, deliver components to a manufacturer or handle logistics for a food company, the requirements arrive through procurement rather than through the law.
- Expect a security questionnaire at contract renewal, covering access control, updates, backups, incident handling and who to call.
- Expect contract clauses requiring you to report incidents to the customer within a stated time so they can meet their own deadlines.
- Expect requests for evidence: a written security policy, a list of sub-suppliers, proof of two-factor authentication and backup tests.
- Suppliers who can answer quickly keep the contract; those who cannot are replaced at the next renewal, quietly.
Core obligations
For a covered organisation the law asks for a proportionate but documented set of measures. They are also a good description of what any company's security should look like.
Risk management
A written analysis of what could go wrong, and measures against it: access control, multi-factor authentication, encryption, patching, backups, network security and secure development.
Incident reporting
An early warning to the authority within twenty-four hours of becoming aware of a significant incident, a fuller notification within seventy-two hours and a final report within a month.
Management accountability
The board or management approves the measures, is trained in cybersecurity and can be held responsible for failures.
Supply chain and continuity
Security requirements on suppliers, business continuity and crisis plans, and registration with the supervisory authority.
First steps for small firms
Whether the law names you or a customer's questionnaire does, the first steps are the same and none of them is expensive. Turn on two-factor authentication everywhere, starting with email, the domain registrar and admin accounts. Keep every system updated on a schedule and remove what you do not use. Take backups off-site and restore one to prove it works. Keep a short log of who has access to what. Write a one-page incident routine: who notices, who decides, who calls the customer, who calls the authority. Then answer the questionnaire from that one page. Our performance and security optimisation service covers the technical part for web and app systems, and a health audit is a cheap way to find out where you stand today; the data protection side is in our website GDPR checklist.
When you do not need to do more: a small firm outside the listed sectors, with no covered customers, is not obliged to register or report, and should not buy a compliance programme it does not need. The basics above are still worth doing because they stop the ordinary attacks. If a customer has sent you a security questionnaire and you are unsure what to answer, book a free 15-minute call and bring it; most of the questions have short, honest answers once you know what they are asking for.
Frequently asked questions
We have ten employees. Are we covered by NIS2?
Almost certainly not directly, unless you provide one of the excepted services such as DNS, domain registration or trust services. You may still be asked by covered customers to meet security requirements as their supplier.
What counts as a significant incident?
One that causes or can cause serious operational disruption or financial loss, or that affects others significantly. For a supplier, the practical rule is to tell the customer about any incident that touches their data or service and let them judge.
Which authority supervises in Sweden?
Sector authorities supervise their own areas under the cybersecurity act, with MSB coordinating and running the incident reporting function. A covered organisation registers with its sector authority.
Is NIS2 the same as GDPR?
No. GDPR protects personal data and is supervised by IMY. NIS2 protects the availability and security of services in critical sectors. An incident can fall under both, with separate reports and deadlines.
Got a security questionnaire from a customer?
Send it over. In fifteen minutes we tell you which questions you can already answer, which need a small fix and which need a written routine, so you can respond before the renewal.
Book a free 15-minute call