LODLINE
EN / SV

reports

NIS2-avgränsning: fixed-price assessment, what you get and when

A NIS2-avgränsning: fixed-price assessment, what you get and when (avgränsning is the Swedish term for scoping) answers three questions before you commit: whether an entity falls within the NIS2 framework, what the review covers and excludes, and how long delivery takes once documents are received.

Who this concerns

The product is built for management, group legal, or compliance functions that need a defensible answer to one question before spending time or budget elsewhere: is this entity, or any entity in the group, caught by the NIS2 framework as implemented in Sweden. It suits mid-size operators in energy, transport, health, digital infrastructure, and managed IT services, together with suppliers to those sectors that may fall into scope indirectly through a customer relationship rather than through their own activity.

Groups with several Swedish legal entities are the most common client for this assessment, because scope questions rarely apply uniformly across a group. A holding company, an operating subsidiary, and a shared-services entity can each land on a different side of the line, and the answer for one does not transfer automatically to the others.

Where the parent company sits outside Sweden, the scoping exercise still runs on the Swedish entity's own activity and size, but the assessment records how the group's reporting lines and shared infrastructure interact with that entity's obligations, because a foreign parent asking for a single group-wide answer is the most frequent source of confusion we see at intake. The compliance and sanctions practice hub sets out how this scoping work connects to the wider cyber and sanctions compliance picture.

What the law says

Under Swedish law as it currently stands, the test for whether an entity is subject to network and information security obligations turns on sector, size, and the role the entity plays in services that others depend on to operate. Sector classification decides whether an entity sits in scope of consideration at all; size and structure then decide whether it is treated as essential, important, or outside scope entirely.

The scoping test also reaches beyond the regulated sectors themselves. An entity that supplies a regulated operator, and whose failure would disrupt that operator's own compliance, can be pulled into scope through the supply relationship even where its own sector classification would otherwise place it outside the framework. This is the point most commonly missed by companies that scope themselves using sector lists alone, without checking who their customers are. A related deadline problem shows up in a different area of compliance, where the same sector-versus-activity confusion drives errors; see export control dual-use classification deadlines for the equivalent analysis there.

How it works in practice

What the assessment includes

The assessment produces a written scoping conclusion covering four elements: the sector classification applicable to each entity reviewed, the size test result under the criteria as they currently stand, an assessment of supply-chain exposure where the entity serves regulated customers, and a short statement of the practical consequence of that conclusion, meaning what obligations follow if the entity is in scope and what changes if it is not.

Where a group includes more than one Swedish entity, each entity is scoped separately and the conclusions are presented entity by entity, not as a single group-wide answer.

What is explicitly excluded

The assessment does not design a compliance programme, draft governance documents, or build an incident-reporting workflow. It does not test technical controls, review network architecture for weaknesses, or assess the maturity of existing security measures. Where the scoping conclusion is that an entity is in scope, the report tells you that a compliance programme is required and outlines its main components at a level sufficient to plan the next phase of work, but it does not build that programme.

Documents you provide before work starts

  • A current group structure chart identifying all Swedish and closely connected foreign entities
  • Revenue and headcount figures broken down by legal entity, not consolidated at group level
  • A short description of the services or products each entity provides
  • Copies of, or a summary of, contracts with customers that are themselves regulated operators
  • Any prior scoping work, whether done internally or by another adviser, so the assessment builds on it rather than repeating it

How the review is structured

The review runs in four steps. An intake call establishes the group structure and the entities to be covered. Document review follows, applying the sector and size tests entity by entity and checking supply-chain exposure against the customer contracts provided. A draft conclusion is then circulated for a review call, where questions about the reasoning are addressed before the memo is finalised. The final memo sets out the conclusion for each entity and the reasoning behind it, so it can be relied on if a supervisory authority or a customer asks how the entity classified itself.

Group structures and foreign parents

Where the ultimate parent sits outside Sweden, two questions come up at almost every intake call. The first is whether the parent's own compliance status abroad has any bearing on the Swedish subsidiary's scope; it does not, because the Swedish entity is scoped on its own activity, size, and customer base under Swedish law as it currently stands. The second is whether shared IT infrastructure, run centrally by the parent, changes the Swedish entity's classification; it can, where that shared infrastructure is itself a service the Swedish entity depends on to deliver a regulated activity, and the assessment records that dependency explicitly rather than leaving it implied.

If a scoping review shows a listed group entity is in scope, who decides what the market is told?

The scoping assessment does not make that decision and is not designed to. Disclosure obligations for a listed company sit with the board and its disclosure committee, applying separate market-conduct rules to the underlying facts. Media disclosure for a listed company sets out how that decision is actually made once the underlying facts, including a scoping conclusion, are on the table.

Does the answer change if the entity being scoped is a joint venture with a foreign partner?

The scoping test applies to the joint venture entity itself, using its own sector, size, and customer base, regardless of who sits on the other side of the shareholder agreement. What does change is who has the authority to instruct the assessment and who receives the conclusion, which is a governance question rather than a scoping one. Joint ventures with a Swedish partner covers how that authority is usually allocated when the counterparty is foreign.

Is återvinning relevant to a NIS2 scoping exercise?

No. Återvinning is a Swedish legal term used in insolvency and recovery contexts, unrelated to network and information security scope. It comes up in this list only because clients researching one Swedish legal term often search for others in the same session. The återvinning glossary entry explains where that term actually applies.

The numbers

Delivery time is fixed in the engagement letter once the scope of the assessment is agreed, but that figure varies from one engagement to the next because it depends on factors that are only known once the intake call has happened: the number of legal entities included in the group scoping exercise, the volume of contract documentation that needs to be checked for supply-chain exposure, and whether earlier scoping work exists to build on rather than start from a blank page.

A single-entity review with a straightforward customer base and complete documentation on hand moves through the four steps described above faster than a review covering several entities with overlapping shared services and incomplete contract records. The fee is fixed regardless of which of these applies; the delivery date quoted at intake reflects which one your group actually is.

Where it usually goes wrong

Four mistakes account for most of the scoping errors we see corrected in a formal review.

  • Scoping by sector name alone, without applying the size test that actually determines whether an entity in that sector is essential, important, or outside scope
  • Ignoring the supply-chain route into scope, on the assumption that only entities with direct sector classification can be caught
  • Treating a group-wide answer as sufficient, when the size and customer-base tests apply entity by entity and rarely produce the same answer twice
  • Reading an in-scope conclusion as a compliance programme in itself, rather than as the starting point for one

The assessment corrects the first three by design. The fourth is a reading error on the client's side, and it is worth naming directly: a scoping conclusion is not a compliance programme, a policy set, or an incident-reporting workflow. It is the answer to a narrower and prior question.

What to do next

This report answers whether an entity is in scope and what that means in outline. It does not build the programme that follows from an in-scope conclusion, including the internal reporting workflow that most in-scope entities need to put in place. Where the next step is establishing that workflow, setting up whistleblowing channels and running the internal investigations that follow is usually where the work continues.

Where the question is narrower, meaning whether your specific structure is actually in scope before any of that work starts, that is where a direct assessment call is the more useful next step. Get in touch with the group structure and entity list described above and we will confirm what the assessment covers for your case.

Request a preliminary assessment