LODLINE
EN / SV

compliance-sanctions-cyber

NIS2 scoping and registration with the authority: what to do in the first ten

NIS2 scoping and registration with the authority: what to do in the first ten working days is short to state: confirm scope under the sector and size criteria, assign internal ownership, and file the registration information the supervisory authority requires before the internal deadline passes. Getting this sequence wrong early turns a routine filing into a lengthy correction.

Who this concerns

This is a live question for mid-size and large entities operating in sectors that the current cybersecurity framework treats as critical or important, including a number of firms that did not expect to be captured because they think of themselves as suppliers rather than infrastructure operators. Classification as an "important" entity rather than an "essential" one still triggers a registration obligation; the distinction changes the supervisory intensity that follows, not whether registration is required at all.

It is also, disproportionately, a question for subsidiaries of groups headquartered outside Sweden. A parent company's own cybersecurity governance, drafted for its home jurisdiction or for the group as a whole, does not substitute for a scoping decision made at the level of the Swedish entity. The assessment is done entity by entity. A foreign parent's regulatory status in its own country, whether it is already registered somewhere else or has concluded it falls outside scope there, has no bearing on whether the Swedish subsidiary itself must register here. Groups that assume the two questions are the same tend to discover the gap only when the supervisory authority asks for the Swedish entity's own filing and there isn't one.

This question sits inside the broader compliance, sanctions and cyber practice, and it is usually the first of several related questions a group asks once one entity has been through the exercise.

What the law says

Because the applicable provisions depend on how a given entity is classified, and because a specific norm reference cannot be cited here, the position is set out at the level of mechanism: under Swedish law as it currently stands, an entity that meets the sector and size criteria for inclusion is required to register with the supervisory authority and to keep that registration current as its own circumstances change.

Two features of the mechanism matter more than any single figure. First, the classification is self-assessed in the first instance: the entity itself decides whether it meets the sector and size criteria, and files on that basis. Second, self-assessment is not final. The supervisory authority can review the classification an entity has given itself and disagree with it, which means a registration filed once is not a closed matter, and neither is a decision not to register at all.

How it works in practice

Confirm the sector classification first

Everything downstream depends on getting the sector classification right before anything else is drafted. Entities frequently classify themselves by the sector they consider their primary commercial identity rather than by the activity that actually brings them within scope, which can be a supporting function rather than the headline business.

Establish the size category on standalone figures

Size is assessed on the entity's own figures, not on a budget forecast and not, for a subsidiary, on the consolidated figures of the wider group. Where a group has structured itself so that no single entity looks large in isolation, that structure is exactly what the supervisory authority is likely to test.

Map the group structure, including any foreign parent

Before registration is drafted, the group structure needs to be set out clearly enough to show which entity is the one making the filing, whether other Swedish entities in the same group face the same question separately, and whether a foreign parent's own position has been assumed, incorrectly, to cover the Swedish entity.

Assign internal ownership before the clock starts

Registration work drifts when no single person is named as responsible for it. Naming that person, and confirming they are authorised to sign on the entity's behalf, before the substantive work begins avoids the more common failure mode, which is not getting the classification wrong but having the correct classification sit unfiled because no one owned the next step.

Draft and file the registration submission

The submission itself should be treated as a formal filing that creates a supervisory record, not as an administrative form. What is stated in it, including the sector code and size category, becomes the baseline against which any later review is measured.

Use the first ten working days as an internal control period

There is no single moment at which every piece of information required for a defensible filing appears at once. Treating the first ten working days after the scope question is raised as an internal control period, during which sector classification, size figures, and group mapping are checked before anything is submitted, produces a materially better filing than submitting on day one and correcting later.

What to check before the registration is filed

  • Whether the entity's own sector code matches how the supervisory authority classifies that sector, rather than how the entity has historically described itself commercially
  • Whether the headcount and turnover figures used are the entity's own audited figures, not budget estimates or group-consolidated numbers
  • Whether a parent company outside Sweden has already reached a scope conclusion that conflicts with what the Swedish entity is about to file
  • Whether the named internal contact for the registration is formally authorised to sign on the entity's behalf
  • Whether any previous correspondence with the authority already contains a classification that the current filing would contradict

Does completing NIS2 registration protect directors from personal liability?

Registration reduces one specific category of exposure, which is the risk of being found to have ignored a known regulatory obligation. It does not amount to a general discharge. Where the underlying question is about the scope and limits of formal discharge from liability, that is a separate mechanism governed by its own conditions, set out here, and registration on its own does not satisfy it.

How does the incident-reporting deadline interact with the registration timeline?

Registration and incident reporting are governed by separate clocks that start from different triggers, one from the scoping conclusion and the other from the moment an incident is identified. An entity that has not yet completed registration is not exempt from reporting obligations if an incident occurs in the meantime; the two obligations run in parallel. How the incident-reporting deadlines compare to the alternative sets out that separate timeline in detail.

When does a scoping question turn into a kontrollbalansräkning question?

The two are unrelated in most cases, but they converge where the cost of remediating a scoping failure, including retrospective registration and any associated correction work, is large enough relative to the entity's own balance sheet to raise a solvency question. Where that convergence happens, the relevant Swedish mechanism is the kontrollbalansräkning, which is triggered by capital position, not by regulatory classification.

The numbers

The numbers that actually decide a scoping outcome are entity-specific: standalone headcount, standalone turnover, and the precise sector code that applies to the entity's own activity, not a generic industry benchmark and not a group-wide figure. Two entities in the same sector, one operating as a standalone company and one as part of a larger group, can reach opposite scoping conclusions on the same activity for that reason alone.

Cost is driven by the same variables. A single-entity business with clean, audited figures and a straightforward sector code carries a much smaller scoping and filing exercise than a group with several Swedish entities, mixed sector activity, and a foreign parent whose own compliance assumptions have to be untangled from the Swedish entity's position before anything is filed. Where a figure is quoted for this kind of work in the abstract, without reference to the entity's own structure, it is not a figure that means much.

Where it usually goes wrong

Groups classify themselves using consolidated figures where the correct test is standalone, and only discover the error when the authority asks for the entity-level basis of the filing. A registration is filed once and treated as settled permanently, when a change in ownership, activity mix, or sector focus is exactly the kind of event that should trigger a re-filing rather than being left against the original submission. A foreign parent's own registration or exemption elsewhere is relied on as if it covered the Swedish entity, which it does not.

The internal ten-working-day control period is sometimes treated as flexible because there is no hard statutory clock formally attached to it in isolation, but that flexibility does not remove the risk, it only postpones it to the point where a filing is challenged and the entity has to reconstruct, after the fact, work that should have been done before submission. Finally, the security requirements that apply to an entity's own suppliers and subcontractors are sometimes treated as a separate, later project rather than as an input to the scoping conclusion itself, when in practice the two are worked out together: the supplier and subcontractor security requirements are set out step by step here.

What to do next

Everything above is work a compliance function can do on its own: sector classification, standalone size figures, group mapping, internal ownership, and a first filing built during a defined control period rather than under time pressure. Where self-directed work ends is the point at which the internal classification needs to be tested against how the supervisory authority is likely to read the same group structure, particularly where a foreign parent is involved or where the entity sits close to a size threshold either way.

That is the point at which an outside review of the position, rather than a further internal check, is the more useful next step. Book a scoping assessment once the sector and size classification has been drafted internally, and bring the group mapping with it.

Request a preliminary assessment