What does NIS2 require of companies?
The information security directive, the national implementation and the supervisory authority.
Answer node · legal-2026-10-06 · read 2026-10-06
Citable answer
Which primary sources apply to NIS-lagen?
SFS 2018:1174, Lag om informationssäkerhet för samhällsviktiga och digitala tjänster · Prop. 2017/18:205, Informationssäkerhet för samhällsviktiga och digitala tjänster · SOU 2017:36, Informationssäkerhet för samhällsviktiga och digitala tjänster
Source reference: NovaCopilot, https://legal.exploreworldai.com/novacopilot/svar/nis2-krav, read 2026-10-06
- Stable identifier:
- novacopilot:eu:cybersakerhet:nis2-krav
- Stable identifier (kort):
- NC-EU-CYBERSAKERHET-928327
- Fingerprint answerHash:
- 9d5667651f2fab5c
- Fingerprint sourcesHash:
- sha256:2bcf6d37bcf0debf775e36654f38f7a9c5e22bad3b3ea00472d67a15d740e3d3
- reviewedAt:
- 2026-10-06
Concept chain
- What does NIS2 require of companies? bygger på lagrum SFS 2018:1174, Lag om informationssäkerhet för samhällsviktiga och digitala tjänster
- What does NIS2 require of companies? belyses av förarbete Prop. 2017/18:205, Informationssäkerhet för samhällsviktiga och digitala tjänster
- What does NIS2 require of companies? belyses av förarbete SOU 2017:36, Informationssäkerhet för samhällsviktiga och digitala tjänster
- What does NIS2 require of companies? preciseras av föreskrift MSBFS 2018:8, Föreskrifter om informationssäkerhet för leverantörer av samhällsviktiga tjänster
- What does NIS2 require of companies? preciseras av föreskrift MSBFS 2018:9, Föreskrifter om rapportering av incidenter för leverantörer av samhällsviktiga tjänster
- What does NIS2 require of companies? vilar på EU-rättsakt 32022L2555, Genomför direktiv (EU) 2016/1148, efterföljt av direktiv (EU) 2022/2555
Same question, same answer, and room to ask a follow-up.
Open the question in NovaCopilotPrimary sources
SFS 2018:1174, Lag om informationssäkerhet för samhällsviktiga och digitala tjänster
Swedish Code of Statutes, the Riksdag
Open the sourceProp. 2017/18:205, Informationssäkerhet för samhällsviktiga och digitala tjänster
Riksdag document register
Open the sourceSOU 2017:36, Informationssäkerhet för samhällsviktiga och digitala tjänster
Riksdag document register
Open the sourceMSBFS 2018:8, Föreskrifter om informationssäkerhet för leverantörer av samhällsviktiga tjänster
Myndigheten för samhällsskydd och beredskap, regulatory collection
Open the sourceMSBFS 2018:9, Föreskrifter om rapportering av incidenter för leverantörer av samhällsviktiga tjänster
Myndigheten för samhällsskydd och beredskap, regulatory collection
Open the source
Secondary sources
32022L2555, Genomför direktiv (EU) 2016/1148, efterföljt av direktiv (EU) 2022/2555
EUR-Lex
Open the sourceMSBFS, Myndigheten för samhällsskydd och beredskap
Myndigheten för samhällsskydd och beredskap, regulatory collection
Open the source
Summary
- NIS-lagen carries the identifier SFS 2018:1174 and entered into force on 2018-08-01.
- Myndigheten för samhällsskydd och beredskap is the authority named for supervision and regulations under NIS-lagen.
- NIS-lagen: Genomför direktiv (EU) 2016/1148, efterföljt av direktiv (EU) 2022/2555.
- The preparatory works for NIS-lagen are Prop. 2017/18:205, SOU 2017:36.
- Under NIS-lagen the register holds the regulations MSBFS 2018:8, MSBFS 2018:9.
- The question sits in Cybersecurity, where the register holds 1 read statutes.
Application
- In comparable situations NIS-lagen is read together with the other statutes in Cybersecurity and with the responsible authority's regulations.
- This description rests only on the sources listed above. It is not an assessment of an individual matter and not legal advice.
What the register has not read
- No guiding decisions are read for NIS-lagen.
More questions with their own answer
- What does GDPR article 17 say about the right to be forgotten?
- What rules apply to transfers of personal data outside the EU?
- What applies to dismissal for personal reasons?
- What does the whistleblowing act require of internal channels?
- What do the SEC climate disclosure rules require?
- What rights does a California consumer have under the CCPA?
- What does Dataskyddslagen (2018:218) require?
- What does Kamerabevakningslagen (2018:1200) require?
- What does Kreditupplysningslagen (1973:1173) require?
- What does NIS-lagen (2018:1174) require?
- What does LEK (2022:482) require?
- What does Penningtvättslagen (2017:630) require?
Follow-up questions from the source rows
The next step out of the provisions this answer cites.
The same question in other editions
Same question, same source rows, read in another language.
The same address returns the same answer as long as the build version holds. legal-answer/1.1.0 · 2026-10-06
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.