This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Critical Infrastructure
Requirements for Security Measures that Strengthen Cybersecurity
The Cybersecurity Act that came into force in January 2026 imposes requirements on companies and authorities within critical societal functions to maintain a high level of cybersecurity. On October 1, the overall requirements of the law are supplemented with regulations that clarify what operators need to do to comply with the legislation. – Decisive leadership is required to build a robust cyber defense in an increasingly serious security policy situation, emphasizes Mikael Frisell and addresses especially decision-makers in the affected organizations. Since the EU's NIS2 directive was adopted in 2022, it has been known that more actors would be covered by stricter cybersecurity requirements. Through the new regulations on security measures and management training, it is now clearer what requirements apply to most operators covered by the Cybersecurity Act in Sweden. On July 1, the authority's cyber operations, including missions and expertise related to the Cybersecurity Act, will be transferred to the National Cybersecurity Center (NCSC) at the Swedish Defence Radio Establishment (FRA).