LODLINE
EN / SV

compliance-sanctions-cyber

The cyber security act and the entities it covers: step by step

Working through the cyber security act and the entities it covers: step by step reduces to four checkpoints: sector classification, size assessment, essential-or-important designation, and registration with the competent supervisory authority. Each checkpoint changes the compliance obligations that follow, and skipping one early creates gaps that surface later during an incident report or an audit, under Swedish law as it currently stands.

Who this concerns

The cyber security act reaches operators in a defined list of sectors treated as essential or important: energy, transport, banking, financial market infrastructure, health, drinking water and wastewater, digital infrastructure, managed ICT services, public administration, space, postal and courier services, waste management, chemicals, food production and distribution, certain manufacturing, and digital providers such as cloud services, data centres and online marketplaces. An entity does not need to see itself as a technology company to fall inside this list; a regional water utility or a mid-sized logistics operator is as much in scope as a cloud provider.

Coverage is decided at group level, not at the level of the single Swedish entity. A Swedish subsidiary with a modest headcount can still be captured if its parent group, taken as a whole, crosses the relevant size threshold, or if the subsidiary performs a function the parent group cannot substitute elsewhere. This is the point at which boards, compliance functions, IT security teams and procurement all need a seat at the same table, because the obligations that follow touch governance, technical controls and supplier contracts at once. A broader map of how this practice treats classification, registration and enforcement sits on the cyber compliance practice hub.

What the law says

Sweden implements its cyber security obligations through domestic legislation that sets out who counts as an essential or important entity, what risk management measures those entities must maintain, how incidents are reported, and what a supervisory authority can do when an entity falls short. Specific provision numbers are not repeated here because the classification exercise depends on facts particular to the entity in front of it; what can be stated with confidence is the structure, under Swedish law as it currently stands: essential entities carry a heavier supervisory burden and are subject to proactive inspection, while important entities are supervised reactively, typically once an incident or a complaint brings them to the authority's attention.

Both categories share the same underlying duty: a documented, risk-based approach to network and information security, covering governance, incident handling, business continuity, supply chain security, and the security of systems acquisition and maintenance. The obligation sits with the entity, but management bodies carry personal accountability for approving and overseeing the risk management measures, which is a departure from older sector rules where compliance sat purely with a technical function.

The foreign element matters here in a specific way. Where the entity operating in Sweden has a parent company incorporated outside the EU, or where critical systems are managed from outside Sweden by a group-level IT function, the Swedish entity's obligations do not shrink to match. Reporting still runs through the Swedish entity, contracts with the foreign parent's IT function need to reflect the Swedish entity's own regulatory exposure, and a due diligence exercise on a foreign counterparty acquiring or investing in the Swedish entity should treat cyber classification as a substantive question, not a formality. The mechanics of that kind of check are covered in the review that applies before a deal with a foreign counterparty closes.

How it works in practice

The classification exercise runs in a fixed order. Working through it out of sequence is the most common reason entities miscalculate their own exposure.

Confirm the sector falls within scope

Start with the sector list, not with the entity's own description of its business. A company that sees itself as a manufacturer can still be captured through a digital infrastructure or ICT service management activity it runs internally for the wider group. Map every activity the entity performs, including internal shared services, against the sector categories, rather than mapping only the entity's primary registered activity.

Determine the entity's size classification

Size is assessed on workforce and financial figures calculated at group level where the entity belongs to a group, not on the standalone Swedish entity's own figures. This step is where foreign-owned entities most often under-classify themselves, because the Swedish subsidiary looks small in isolation while the group as a whole clears the relevant threshold with room to spare.

Establish essential or important designation

Once sector and size are settled, the entity falls into one of two designations, and the designation decides the intensity of supervision rather than the substance of the underlying obligations. Getting the designation wrong does not remove the duty to comply; it only means the entity discovers the correct designation at the point of an inspection or an incident, which is a worse moment to discover it.

Register with the supervisory authority

Registration puts the entity on the authority's record, with contact details, sector classification and a description of the entity's activity. This is also the point at which the entity should expect the authority's own supervisory calendar to apply to it, including the possibility of a scheduled inspection for essential entities. How a comparable supervisory inspection actually runs, step by step, in a related regime is set out in the walkthrough of a data protection supervisory inspection, which shares the same practical logic even though the underlying legal basis differs.

Build the required risk management documentation

The documentation that supports the risk-based approach needs to exist before an inspector asks for it, not be assembled in response to the request. At minimum this covers a risk assessment specific to the entity's own network and information systems, a business continuity and incident response plan, records of staff training on security procedures, and a supply chain risk assessment covering the entity's direct suppliers of ICT products and services.

Set up the incident reporting channel

Incident reporting is not a single filing; it runs as a sequence of notifications with different content requirements at each stage, starting with an early warning and closing with a final report once the incident is resolved and its root cause understood. An entity that treats the first notification as the only one required typically misses the follow-up deadlines that carry their own consequences. Where an incident also raises the prospect of a criminal offence, such as a targeted intrusion, the entity is often better served by opening an internal review before the authority initiates its own, along the lines set out in the approach to running an internal investigation before an authority arrives.

Address suppliers and other third parties

Supply chain security is one of the obligations most often left undocumented. It requires the entity to assess the cyber security practices of its direct ICT suppliers and to reflect that assessment in the contractual terms governing those relationships, not merely to trust a supplier's own marketing material about its security posture. Contracts signed before the entity understood its own classification frequently need renegotiation once the classification is settled.

What to verify before treating the classification as closed

  • Whether every activity the entity performs, not only its registered primary activity, has been checked against the sector list.
  • Whether size figures were calculated at group level, including entities outside Sweden, and not only for the Swedish legal entity.
  • Whether the essential-or-important designation has been confirmed in writing, rather than assumed from a sector description found elsewhere.
  • Whether the risk management documentation exists in a form an inspector could read on the day of a visit, not only in draft.
  • Whether the incident reporting channel has a named owner who is reachable outside office hours.
  • Whether supply chain contracts have been reviewed against the entity's own classification, not against a generic security clause.

Does the cyber security act apply to a Swedish subsidiary of a non-EU parent company?

Yes, and the parent's location outside the EU does not reduce the subsidiary's obligations. The subsidiary is assessed on the sector it operates in and on size figures calculated at group level, which usually means the group's global headcount and turnover are relevant even though the parent itself sits outside Swedish jurisdiction. The obligations, including registration and incident reporting, attach to the Swedish entity regardless of where governance decisions are actually made.

What happens if an entity is classified as important rather than essential?

An important entity carries the same underlying risk management and incident reporting duties as an essential entity, but the supervisory authority engages with it reactively rather than through scheduled inspection. In practice this means the entity is less likely to be checked proactively, but the obligations still apply in full, and a failure that surfaces through an incident or a complaint is assessed against the same standard an essential entity would face.

Can an entity outside the listed sectors still fall into scope through a supply relationship?

An entity outside the listed sectors is not brought into scope directly through a supply relationship with an in-scope entity, but it will feel the obligation indirectly. In-scope entities are required to assess their suppliers' security practices and to reflect that assessment in contract terms, which means a supplier outside the formal scope can still face security requirements, audits and reporting obligations imposed contractually by the in-scope customer.

The numbers

No timeframe, threshold or penalty figure is quoted here as a number, because a number quoted without checking it against the entity's own classification and against the current text of the guidance is more likely to mislead than to help. What can be said is the shape of the numbers that exist: a registration deadline that runs from the point the entity enters scope, a tiered incident reporting timeline with separate points for an early warning, an incident notification and a final report, and a penalty framework calculated by reference to the entity's turnover rather than as a fixed sum. Each of those figures is confirmable, and each should be confirmed directly against the entity's own classification and the supervisory authority's current guidance before it is relied on in a board paper or a client memo, rather than carried over from a source that was accurate when it was written and may not be accurate now.

Where it usually goes wrong

Three patterns account for most of the classification failures seen in practice.

The first is assessing size at the level of the Swedish entity alone. A foreign-owned entity that looks small on its own Swedish balance sheet is frequently part of a group that clears the threshold comfortably, and the group-level figure is the one that governs.

The second is assuming that a sector exemption covering the group's core business also covers a shared service the group runs through the Swedish entity for the rest of the group. Shared IT services, data processing centres and similar internal functions are assessed on what they do, not on the label attached to the rest of the group's business.

The third is treating enforcement as a domestic matter only. Where an entity's assets, insurance or parent company sit outside Sweden, an enforcement action for a failure to comply can end up running in parallel across more than one jurisdiction, and recovering a penalty or pursuing a claim against a foreign counterparty raises questions closer to asset tracing than to compliance. The mechanics of that kind of cross-border pursuit are covered separately in the asset tracing and recovery process across UK enforcement.

A fourth, quieter failure is treating classification as a one-off exercise. Group structures change through acquisitions and disposals, and an entity that classified itself correctly two years ago can drift into or out of scope without anyone re-running the assessment.

What to do next

This material gets an entity to the point of knowing which of the four checkpoints it has not yet cleared. It does not replace the document review that confirms a classification, drafts the risk management documentation, or sets up the incident reporting channel with the right internal owners named. That review is where the work becomes specific to one entity's contracts, group structure and existing security controls, and it is the point at which it makes sense to arrange a cyber compliance assessment rather than continuing to work from general guidance.

Request a preliminary assessment