News

Sofa by a window at Next’s office

Next Law is growing and is looking for even more lawyers – primarily a qualified lawyer and a newly graduated lawyer, but there may also be more.

27 jan 2026

If you have recently graduated or your notary service is coming to an end and you want to work with qualified law in a forward-looking business law environment, this could be the right opportunity for you. Next Law is looking for new colleagues with a particular interest in dispute resolution and qualified advice within the firm's areas of activity.

At Next Law, you will become part of a team of specialized business lawyers who offer value-creating and tailored advice in the Swedish and international business law market. The position gives you the opportunity to work with qualified legal issues from the start in a dynamic and developing environment with senior supervision in the business law craft. With us, you will have the opportunity to develop your own network and create long-term value for our clients and yourself.

Your profile

We are looking for someone who is curious and driven, with very good language skills in Swedish and English. You have good academic qualifications and a professional approach. We value personal qualities such as entrepreneurial spirit, responsibility, good teamwork and business acumen.

Your application

The application should include a CV, personal letter and grades from the law program and, where applicable, grades from notary work. Also attach any other documents that you consider relevant and indicate the approximate date you can start with us. We accept applications at contact@nextlaw.se.

Selection and interviews take place on an ongoing basis. If you match the requirements of the positions and proceed in the process, you will be contacted quickly by us to schedule a first interview.

More about us

As part of AGRD Partners, we challenge the traditional business law market. By being one of the first six firms within AGRD Partners, we can offer context in a larger business law context with central investments in AI and legal tech, as well as new career paths for lawyers. As an employee with us, you will also be given the opportunity to participate in training and talent programs within AGRD Partners, as well as unique investment opportunities of your own.

Welcome to apply!

Next Law has acted as legal advisor to SuperOffice

5 nov 2025

Next Law, through Thérèse Zinn (managing partner), Victor Holmberg, John Spiegel and Jenny Jilmstad, has acted as legal advisor to SuperOffice AS in SuperOffice's acquisition of i-Centrum AB.

SuperOffice, majority owned by the private equity firm Axcel, is one of Europe's leading providers of CRM solutions in the B2B market. Founded in 1990 in Oslo, Norway, where the company is still headquartered, the company offers scalable and modular Software as a Service (SaaS) solutions. These help organizations manage every customer contact in sales, marketing and service. SuperOffice has offices in Norway, Sweden, Denmark, Germany, the Netherlands and Switzerland, as well as a customer support center in Lithuania. The company also collaborates with a strong partner network in Europe and North America. Today, SuperOffice has almost 300 employees and continues to expand its reach and capabilities.

Next Law joins AGRD Partners

9 oct 2025

Today marks the start of AGRD Partners, a new group formed by six of Sweden's leading business law firms: Allié, Born, Morris Law, Next Law, Synch and TM & Partners.

Backed by Nordic private equity firm Axcel, AGRD Partners brings together around 250 professionals across nine offices to drive progress in a sector long shaped by tradition.

Each firm in AGRD Partners continues to operate under its own brand with full autonomy for client relationships and delivery. Joint initiatives - technology, training, and new services - are developed and rolled out under the AGRD Partners platform to benefit all clients.

Next Law will continue as a business law firm, offering the same legal expertise, quality and commitment as before. For us, this is a natural next step in our mission: assisting our clients with legal advice by combining deep expertise with technology and practical delivery.

The legal sector is undergoing a shift driven by evolving client needs and technological advancements. For business law firms, private equity ownership offers a model for navigating the opportunities of this evolving landscape.

To enable long-term investment and innovation, the firms within AGRD Partners will operate outside the Swedish Bar Association. This change is driven by regulatory requirements, not by a change in our commitment to quality.

All firms within AGRD Partners will continue to operate under their own brands and with full autonomy. For clients, the alliance means:

  • Access to a broader range of specialist expertise when needed
  • A wider international network of advisors
  • Enhanced capacity to handle complex and cross-border matters
  • To safeguard professional standards, independence and confidentiality, the group will operate under the AGRD Partners Code of Professional Conduct - an extensive ethical framework designed to meet the expectations placed on leading business lawyers. Client information will continue to be handled with strict confidentiality.

For more information, please contact:

Pia Nyblæus, +46 (0)70 769 73 07 | pia.nyblaeus@nextlaw.se

The incorporation of Article 21 of the NIS2 Directive into Swedish law

26 March 2025

By Roger Hellström

The NIS2 Directive (DIRECTORY (EU) 2022/2555 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 December 2022 concerning measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972 and repealing Directive (EU) 2016/1148) was to have been transposed into Swedish law on 18 October 2024, but has been delayed for various reasons. The NIS2 Directive thus replaces the so-called NIS Directive. A special investigation (the “Inquiry”) has, on behalf of the government, prepared a proposal for a cybersecurity law (the “Cybersecurity Act”) regarding the actual implementation of the NIS2 Directive (see SOU 2024:18 New rules on cybersecurity and in some parts also 2024:64 Resilience in essential services).

The inquiry has in many ways made a professional contribution and proposed legislation that is in many parts easy to understand in the short time they were given. Despite this, there are certain regulations that may need to be analyzed. I have chosen to only analyze the incorporation of Article 21 of the NIS2 Directive into the Cybersecurity Act. To some extent, this has already been done in some of the more than 160 consultation responses the inquiry received. For those interested, reference is made to the Consultation for SOU 2024:18 New regulations on cyber security - Regeringen.se.

Article 21 can be considered one of the more important regulations to incorporate into Swedish law as it contains the basic requirements for risk management measures for cybersecurity. These requirements are intended to comprehensively ensure or at least improve the protection of public and private operators against both cyber security incidents, antagonistic and otherwise, which often result in a number of undesirable consequences, such as lost trust, lost customers, costs for forensic investigation and restoration of systems and data, and in the worst case even the cessation of the entire operation. In addition to the consequences for the affected operator, these incidents can also lead to consequences for the nation's economy.

For reasons of space, I have not copied the entire article 21 in this article nor certain other text to which I partially refer. For those interested, these texts can be read in their entirety in the NIS2 Directive and in SOU 2024:18. It should of course be added that there will be regulations from both the MSB and the designated supervisory authorities, which can hopefully clarify some of the regulations I am analyzing, but the fact remains that the interpretations made by the Inquiry of the NIS2 Directive (and whether they become the actual legislation) will still be decisive for the upcoming regulations.

Directive-like or not

The Inquiry has not incorporated Article 21 of the NIS2 Directive in the proposal for the Cybersecurity Act in a directive-like manner. This is justified by the fact that, according to the government directive, the NIS2 Directive should not be “introduced in a directive-like manner, but that the proposals should be designed based on the systematics and terminology used in Swedish law. A normal use of language should be sought. It also explicitly follows from the government directive that the terminology used in the directives should be adapted to accepted concepts in national regulation”.

Contrary to the Inquiry, PTS considered in its response to the consultation “that it is important that the Cybersecurity Act uses formulations as close to the NIS2 Directive as possible”. To some extent, it is difficult to disagree with PTS’s opinion that the Cybersecurity Act should be more directive-like, especially when it comes to the writings regarding risk management measures. This is because these rules should be regulated as coherently as possible within the EU, among other things to avoid the differences created by the previous NIS Directive. It should be mentioned here that the NIS2 Directive, which replaces the NIS Directive, was introduced, among other things, to counteract significant differences for economically significant activities and in principle created at least some barriers to trade within the EU. It is also unlikely to create any major contradiction with the systematics and terminology used in Swedish law to incorporate Article 21 and it can probably be considered that even accepted concepts could have been used. The question therefore becomes how well such a “non-directive-like transposition” corresponds to Article 21 of the NIS2 Directive, which, it should be added, contains minimum requirements for measures for risk management and cybersecurity, i.e. at least the requirements stated in Article 21 must be incorporated and this should be done in as clear a manner as possible.

Article 21 of the NIS2 Directive has been incorporated into Chapter 3, Section 1 of the Cybersecurity Act. A comparison between these two regulations creates some doubt about how well the transposition has actually been successful.

Article 21(1) of the NIS2 Directive compared to Chapter 3, Section 1 of the Cybersecurity Act

The first question is whether the Investigation into the Cybersecurity Act encompasses all the requirements set out in Article 21(1) of the NIS2 Directive.

NIS2 Article 21(1) states:

Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to address risks to the security of network and information systems that they use for their activities or to provide their services and to prevent or minimise the impact of incidents on the recipients of their services and on other services.

Taking into account the latest and, where applicable, relevant European and international standards and the costs of implementation, the measures referred to in the first subparagraph shall ensure a level of security of network and information systems appropriate to the risk presented. In assessing the proportionality of those measures, due account shall be taken of the degree of risk exposure of the entity, its size and the likelihood of incidents occurring and their severity, including their societal and economic consequences.

The introductory text of Chapter 3, Section 1 of the Cybersecurity Act states:

The operator shall take technical, operational and organisational risk management measures to protect network and information systems and the physical environment of the systems against incidents. The measures shall be based on an all-risk perspective and a risk analysis and be proportionate to the risk. They shall be evaluated and in particular include the following:

When read in a comparative manner, it is clear that Article 21(1) of the NIS2 Directive is more detailed than the Cybersecurity Act. Of course, a more detailed text is not a better way to describe the measures to be taken, but in Chapter 3, Section 1 of the Cybersecurity Act, certain phrases have been omitted. The measures to be taken are not qualified as appropriate. Furthermore, the phrases “relevant European and international standards”, “size of the entity” and “taking into account the implementation costs” are missing, which is hardly covered by the last sentence of Chapter 3, Section 1 of the Cybersecurity Act, i.e. that “The measures shall be based on an all-risk perspective and a risk analysis and be proportionate in relation to the risk”. This may therefore give the impression that the meaning of Chapter 3, Section 1 of the Cybersecurity Act is more limited.

The concept of all-risk perspective incorporated in Chapter 3, Section 1 of the Cybersecurity Act may be considered a somewhat odd bird in Swedish law. The concept is certainly used in Article 21.2 of the NIS2 Directive, but as far as I know it is not used in Swedish legislation and probably not in normal language either. One therefore wonders why it was chosen to use that particular concept when, according to the government directive, the directive is not to be transposed in a directive-like manner. This is especially true in the portal regulation regarding risk management measures for cybersecurity. The concept of all-risk perspective is certainly used in the Government Bill (prop. 2024/25:34) Total Defence 2025-2030 and in the National Cyber Security Centre's (NCSC) paper A New Era of Cyber Security 2025-2029 and can therefore possibly be considered to have become, or at least will become, a concept that is becoming more common in both legislation and normal language.

The understanding of the concept of all-risk perspective is likely to be somewhat uncertain. In recital 79 of the NIS Directive, however, using the term all-risk approach, one can read:

Recital 79:

Since threats to the security of network and information systems can have different origins, cybersecurity risk management measures should be based on an all-risk approach aimed at protecting network and information systems and their physical environment against events such as theft, fire, flood, telecommunications or power outages or unauthorised physical access to, damage to or disruption of an essential or critical entity's information and information processing resources, which could undermine the availability, authenticity, accuracy or confidentiality of data stored, transmitted or processed or of the services offered by or accessible through network and information systems. Cybersecurity risk management measures should therefore also cover the physical security and environmental security of network and information systems by including measures to protect such systems against system failures, human errors, intentional malicious acts or natural phenomena in accordance with European and international standards, such as those included in the ISO/IEC 27000 series. In this regard, essential and important entities should also address personnel security as part of their cybersecurity risk management measures and establish appropriate access control strategies.

To understand the concept of an all-risk approach, according to the NIS Directive, one should therefore base one's risk analysis on, in simple terms, that network and information systems should be protected against physical attacks as well as against other attacks, which must be considered the very foundation of cybersecurity work. Anything else or more than that is difficult to interpret and one gets the impression that it is already stated in the Cybersecurity Act, Chapter 3, Section 1, first sentence.

The National Cybersecurity Centre's (NCSC) paper A New Era of Cybersecurity 2025-2029 states that "the national cybersecurity strategy is based on national needs and on the NIS 2 Directive and its all-risk perspective to address a range of challenges such as skills shortages, complex regulation, vulnerable supply chains and lack of systematic cybersecurity work". It may not be easier to understand what is meant by an all-risk perspective when reading this and interpretations will likely be very different until some form of standard is set for what is meant by an all-risk perspective. Note, however, that NSCS uses the lack of systematic cybersecurity work as one of the challenges, see more about this below.

In conclusion, it is noted that a directive-like regulation using normal language in the introductory text would probably have been experienced as more appropriate. In particular, the clarifications contained in the second paragraph of Article 21.1 of the NIS2 Directive disappear. It can also be mentioned in this context that Article 21.1 of the NIS2 Directive is reminiscent of the way security is regulated in connection with processing in Article 32 of the GDPR, which is certainly an EU regulation but, in accordance with our membership in the EU, is still Swedish law. In addition to this, the introductory text of the Cybersecurity Act, according to the Inquiry, should be understood as meaning that Strategies for risk analysis and information systems security should be established, see more about this below.

Strategies for risk analysis and information systems security

Article 21(2) of the NIS2 Directive lists ten points of measures to be taken to protect network and information systems. The corresponding list in Chapter 3, Section 1 of the Cybersecurity Act is nine, and yet the paragraph has chosen to split one of the points from the NIS2 Directive into two points, thus leaving only 8 points remaining from the NIS Directive in Chapter 3, Section 1 of the Cybersecurity Act.

One point that is completely excluded from the Cybersecurity Act is “strategies for risk analysis and information systems security”. The reason why the Commission chose not to introduce the measure as a separate point is justified by the fact that “With regard to this point, the Commission believes that it does not need to be stated separately, since it follows from the Commission’s proposal for comprehensive regulation.” After the comparative texts of the NIS2 Directive, Article 21.1, and the introduction to the Cybersecurity Act, Chapter 3, Section 1 (see above), it can be discussed whether it is really possible to understand that “strategies for risk analysis and information system security” really follow from the Commission’s overall regulation. A clearer regulation of this kind would have been desirable and it would not have contradicted systematics, terminology and normal language use – not least it would have made understanding easier.

As mentioned in the government directive, it was stated that normal language use should be strived for. According to the Swedish Academy’s Dictionary (SAOL), the word “strategies” means “orderly, planned”, i.e., in this case, an orderly and planned cybersecurity and information security policy. If for no other reason, it would have been an advantage for the operator to state more clearly that strategies should exist, as otherwise it would have had to be interpreted (possibly somewhat unnecessarily) into the overall regulation. One lesson that could have been learned is how several companies established a “starter package” with certain rules and documentation on personal data processing when the GDPR came into force but did not implement a strategy (orderly and planned policy for the processing of personal data) for the same.

The absence of an explicit requirement for a strategy for risk analysis and the security of information systems does not lead to particularly clear regulation. Given that what is stated in Chapter 3, Section 1 of the Cybersecurity Act are the requirements against which a supervisory authority can take action (see below), it would have made it easier for both operators and supervisory authorities to clearly state the requirement.

Security in the acquisition, development and maintenance of network and information systems, including vulnerabilities and vulnerability information

The fifth measure in Article 21(2) of the NIS2 Directive states “security in the acquisition, development and maintenance of network and information systems, including vulnerabilities and vulnerability information”.

The inquiry has here assessed the concept of acquisition as only referring to taking over something with ownership rights. This interpretation is of course the most likely, but in common usage it should be taken into account that one can acquire knowledge, acquire a license, acquire a lease and use similar expressions where none of the aforementioned implies any actual ownership rights. The English version of the NIS2 Directive states “security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure”. In the same way as in Swedish, one can acquire knowledge, acquire a license, acquire a lease where nothing implies any actual ownership rights.

In its response to the consultation, MSB suggested that acquisition could be replaced with procurement to signal that the requirements apply even when something has not been purchased, for example in the case of outsourcing. In response to this, the Inquiry states that when it comes to outsourcing, this is taken care of to some extent in the section on security in the supply chain (see Cybersecurity Act Chapter 3 Section 1 p. 3). Such uncertainty does not seem entirely desirable. Since it is a minimum directive, the Inquiry could have filled in the possible uncertainty by “extending” the requirement to include acquisitions in order to thereby more concretely ensure that it is also covered. Since the Inquiry nevertheless perceives that it is already covered by security in the supply chain to some extent, procurement instead of acquisition would probably not even have extended the requirements of the NIS2 Directive and thus would not have required any special justification (which an extension of a minimum directive usually requires). In addition to this, it would seem that if this point were to apply only to acquisitions that only concern ownership, it would probably not affect many people, as complete network and information systems are not often possible to "buy with ownership" and for many this is probably not a realistic way to go. The question can therefore be asked whether the NIS2 Directive only intended a complete transfer of rights or actually also includes outsourcing.

In accordance with the above, I am inclined to agree with MSB's proposal and include the word acquisition to refer to procurement.

Obliged to take into account the results of the coordinated security risk assessments of critical supply chains carried out in accordance with Article 22(1)

Article 21(3) of the NIS2 Directive states that Member States shall ensure that entities, when considering appropriate measures under point 2(d) of Article 21 (i.e. supply chain security), are obliged to take into account the results of the coordinated security risk assessments of critical supply chains carried out in accordance with Article 22(1) of the NIS2 Directive. This article states that the Cooperation Group may, in cooperation with the Commission and ENISA, carry out coordinated security risk assessments of specific critical supply chains for ICT services, ICT systems or ICT products.

The investigation believes that NIS2 Directive 21(1) – 21(3) have been implemented through Chapter 3, Section 1 of the Cybersecurity Act. As far as I have been able to read, there is no obligation to take into account the results of the coordinated security risk assessments stated, either in Chapter 3, Section 1 of the Cybersecurity Act or in any other section of the legislation, i.e. a requirement to take into account the results of these assessments. The absence of minimum regulation usually means that if you choose not to take this requirement into account, you must justify why you do not do so. Is the absence of this requirement an oversight or is it intended to be fulfilled in some other way? In any case, it does not become clearer when you choose to omit this wording entirely in the Cybersecurity Act.

Conduct systematic and risk-based information security work

The NIS2 Directive does not contain any explicit provision stating that information security work should be conducted systematically. Such a regulation is found in the previous Act (2018:1174) on information security for socially important and digital services (the “NIS Act”), the Swedish implementation of the predecessor to the NIS2 Directive, i.e. the NIS Directive. MSB stated in its response to the consultation that it is important to also stipulate in the Cybersecurity Act that information security work should be carried out systematically and risk-based in the same way as in the NIS Act. The investigation noted that this requirement does not follow from the NIS2 Directive but nevertheless chose to introduce it in the Cybersecurity Act, although not in Chapter 3, Section 1, but in a separate paragraph, namely Chapter 3, Section 2. This latter paragraph is not included among the paragraphs over which supervisory authorities shall intervene with supervision and possible sanctions (cf. Cybersecurity Act Chapter 5 Section 1 with Chapter 3 Section 2 and that the intervention of supervisory authorities is limited to disregarding the regulations issued with the support of, among others, Chapter 3 Section 1 of the Cybersecurity Act, but not Chapter 3 Section 2).

The above must therefore be understood as meaning that the supervisory authorities cannot intervene, which makes the obligation highly limited. An analogy, perhaps not entirely comparable but still, is that it has approximately the same effect as the ban on walking towards a red man, i.e. it is prohibited but it does not lead to any sanctions (other than if your walking towards a red man, for example, leads to a traffic accident). The truth is that this particular requirement is not explicitly and verbatim stated in the NIS2 Directive as one of the points in Article 21 of the NIS Directive, but the question is whether it can still be considered to be covered by Article 21.

As I have previously written (see above), the Inquiry believes that strategies for risk analysis and information security work are covered by the introductory text of Chapter 3, Section 1 of the Cybersecurity Act, while I believe that it should have been explicitly written in as one of the points. Regardless of which path one chooses, the section covers strategic work. If, as I have previously done, one uses SAOL to understand the normal language usage and its stated meaning of the words Strategy and Systematic, one gets the explanations that strategy means the art of waging a war; plan in general, while systematic means orderly, planned. This alone should lead to the idea that strategic work should be systematic work, otherwise how can it be strategic. Furthermore, the NIS2 Directive in Article 21.2 stipulates requirements for strategies and procedures for assessing the effectiveness of risk management measures for cybersecurity and in the same article specifies basic practices for cyber hygiene (practices has been somewhat dubiously translated from the English word practices in the Swedish version of the NIS2 Directive and should probably be translated with words such as methods or routines). The Inquiry chose not to include the latter point in the Cybersecurity Act on the grounds that “practices for cyber hygiene are, in the Inquiry’s assessment, unnecessary, since cyber hygiene is a collective term for what follows from the article as a whole”, i.e. a (rather advanced) interpretation is required by operators to understand Chapter 3, Section 1 of the Cybersecurity Act as a whole and to understand what is incumbent on them. An interpretation that I must admit, I might not have succeeded in coming up with if I had not read the NIS2 Directive. It should be recalled once again that Chapter 3, Section 1 of the Cybersecurity Act contains the measures against which supervisory authorities can intervene.

The above in any case leads me to understand the strategic work to also include systematic work. In the Government Bill 2024/25:34, page 129, the term is used in the sense of “The lessons from Ukraine show the importance of systematic cybersecurity work, access to redundant and diversified communication channels, high robustness in the central systems of electronic communications networks and well-functioning cooperation between private and public actors” and in the NCSC’s document A New Era of Cybersecurity 2025-2029, Systematic and effective cybersecurity work is used as one of the three most important measures required for a national cybersecurity strategy (see, among other things, page 26 ff. in the aforementioned document).

As is well known, a directive cannot be interpreted solely on its articles and an analysis of the reasons often provides a clearer picture of an article and its intended content. It is therefore appropriate to check what is written in two of the recitals of the NIS2 Directive, namely recital 49 and recital 122. Recital 49 states the following with regard to cyber hygiene.

Cyber hygiene policies provide the basis for protecting the infrastructure of network and information systems, hardware, software and security of online applications, as well as business or end-user data on which entities rely. Cyber hygiene policies, which include a common basic set of procedures, including software and hardware captioning, password changes, handling of new installations, restriction of user accounts at administrator level and data backup, enable a proactive framework for preparedness and overall safety and security in the event of incidents or cyber threats. ENISA should monitor and analyse the cyber hygiene policies of the Member States.

The second sentence in particular leads me to the idea that cyber hygiene requires systematic, or as SAOL puts it, orderly and planned work.

Recital 122, which is itself about supervision, states the following (I am only copying parts of recital 122, i.e. the parts I consider relevant).

[……..]. Significant entities should therefore be subject to a comprehensive supervisory system with ex ante and ex post supervision, while important entities should be subject to simpler supervision, ex post only. Important entities should therefore not be required to systematically document compliance with cybersecurity risk management measures, while competent authorities should apply a reactive ex post supervision and thus have no general obligation to supervise these entities. […..]

In recital 122, the NIS2 Directive distinguishes between essential and important entities. The essential entities should not be obliged to systematically document compliance with the risk management measures. Although the opposite conclusion is not always preferable, I am committed to precisely such a conclusion, i.e. my opinion is that the essential entities are obliged to systematically document compliance with the risk management measures. This is consistent with the fact that supervision of essential entities may only take place if the supervisory authority has reasonable grounds to assume that the Cybersecurity Act or regulations are not being complied with (see Cybersecurity Act Chapter 4 Section 3) while supervision of essential entities can take place regardless of whether there is reasonable grounds for it. Does systematically documenting compliance with the risk management measures mean the same as conducting systematic information security work? I am inclined to believe so, although possibly only for essential operators.

Conducting systematic and risk-based information security work is a requirement in the Cybersecurity Act that is not covered by the NIS2 Directive according to the Inquiry and has therefore not been subject to supervision or sanctions (see above). In my opinion, a lack of or non-existent systematic and risk-based information security work should be something that can actually be considered to follow from the NIS2 Directive and could lead to supervision and/or sanctions, if nothing else, at least for significant operators. It should be said that there are opportunities for supervisory authorities to exercise supervision and intervene against operators because the operator has failed in risk management measures (see Cybersecurity Act Chapter 5 Section 1), but such a deficiency does not in itself include a lack of or non-existent systematic and risk-based information security work but must be based on something else in Cybersecurity Act Chapter 5 Section 1.

Finally, I would like to mention that Commission Implementing Regulation (EU) 2024/2690 (the “Implementing Regulation”), a so-called delegated regulation/act which the Commission is empowered to adopt under the NIS2 Directive, which entered into force on 7 November 2024, in the Annex on Technical and Methodological Specifications in point 1.1.2 (under the heading Strategy for security of network and information systems) stipulates that the security strategy shall be reviewed and, where applicable, up-labelled by the management bodies at least once a year and when significant incidents or significant changes to operations or risks occur. The results of these reviews shall be documented. The Implementing Regulation does not apply to all operators but only to those that operate services of a cross-border nature (e.g. cloud service providers) and which are therefore considered particularly important for the security of Europe. Is what is stipulated in the Implementing Regulation an expression of systematic and risk-based information security work? I'll leave the question hanging in the air, but systematic doesn't necessarily mean daily, monthly or any other period of time, but it should involve orderly and planned work.

Some final words

Once the legislation has entered into force, it will probably not be a whole bunch of lawyers interpreting it, but CISOs, IT managers, etc. who will have to incorporate the regulation into practical work. With the, in my opinion, ambiguities contained in the Inquiry's proposal, these people will have at least the same problems with the interpretation as I have. The predictability of what measures a business operator should actually take will therefore be unclear. In addition, the supervisory authorities must take measures if a business operator violates Chapter 3, Section 1 of the Cybersecurity Act. In summary, it is therefore my opinion that the transposition of Article 21 of the NIS Directive could have been done in a clearer way. With the uncertainty I want to show above, I await the legislative council's referral and the bill to see whether the final legislation will change from the Inquiry's proposal.

Next Law has assisted Oral Care in further acquisitions in 2024

3 December 2024

Next Law, through lawyers Thérèse Zinn (partner in charge), Jenny Jilmstad and Victor Holmberg, has assisted the dental care chain Oral Care AB in connection with several acquisitions of dental clinics. Oral Care has expanded in 2024 through the acquisitions of:

  • White Tandvård (four clinics in Malmö, Lund and Helsingborg)
  • Citytandläkarna (Jönköping)
  • Tandläkarna på hörnet (Katrineholm)
  • Thule Tandvård (Umeå)
  • Compassen Tandläkarna (Sundsvall)

Next Law has assisted Axcel and XPartners in further acquisitions in 2024

3 December 2024

Through lawyers Thérèse Zinn (managing partner), Jenny Jilmstad, Joacim Öhlund and Victor Holmberg, Next Law has acted as legal advisor to the venture capital company Axcel and its portfolio company XPartners Samhällsbyggnad in further additional acquisitions in 2024. XPartners has expanded in the Swedish market in 2024 through:

  • Acquisition of XER Management AB and XER Projekt AB. Read more
  • Acquisition of EnSuCon AB. Read more
  • Acquisition of AceRail Consulting AB and AceRail Engineering AB. Read more
  • Acquisition of Consultive Västerås AB. Read more
  • Establishment of the subsidiary NordArk VVS Byrå AB and its acquisition of the assets in Umia Teknikkonsult AB

Next Law has acted as legal advisor to the venture capital company Axcel and its portfolio company XPartners community building

19 June 2024

Next Law, through attorneys Thérèse Zinn (managing partner), Jenny Jilmstad and Victor Holmberg, has acted as legal advisor to the venture capital company Axcel and its portfolio company XPartners community building in XPartners' acquisition of Teknikkonsulterna i Sundsvall AB.

Next Law has assisted Axcel and XPartners in the acquisition of Net Solution Partner Sweden AB

24 May 2024

Next Law, through lawyers Thérèse Zinn (managing partner) and Victor Holmberg, has acted as legal advisor to the venture capital company Axcel and its portfolio company XPartners Samhällsbyggnad in XPartners' acquisition of Net Solution Partner Sweden AB.

XPartners Samhällsbyggnad already includes 17 companies with a presence in large parts of Sweden. The group currently generates approximately SEK 950 million in sales and has approximately 600 employees. In April 2023, the investment fund Axcel took over as the new capital-rich main owner of XPartners to support XPartners in driving growth, including by adding additional technology consulting companies to XPartners.

Founded in 1994, Axcel is a Nordic private equity firm focused on mid-cap companies in four sectors: technology, industrials and services, healthcare and consumer. Axcel has a broad base of both Nordic and international investors and has raised six funds with total capital commitments of EUR 3 billion. These funds have made 70 platform investments, more than 300 add-on acquisitions and 49 divestments. Axcel currently owns 21 companies and is in the process of raising its seventh fund.

NSP logo

Next Law has advised Oral Care AB in the acquisition of Compassen Tandläkarna

13 Mar 2024

Through lawyers Thérèse Zinn (managing partner) and Victor Holmberg, Next Law has assisted Oral Care AB in connection with the acquisition of Compassen Tandläkarna AB. The acquisition of the clinic in Sundsvall strengthens Oral Care's offering in the area.

Oral Care is a growing dental care chain with clinic offices in Sweden and abroad. In addition to the clinics, Oral Care offers mobile home dental care in a number of regions for those covered by the special dental care support. The company is owned by the management and by Axcel, a Nordic venture capital company that focuses on medium-sized companies with great growth potential.

Next Law would like to thank Oral Care for the trust and to all parties and advisors for a good process.

Next Law has assisted Oral Care AB in the acquisition of Tandgruppen Kungsbacka

4 Oct 2023

Through lawyers Thérèse Dolck Zinn (responsible partner) and Victor Holmberg, Next Law has assisted Oral Care AB in connection with the acquisition of Tandgruppen Kungsbacka AB.

Oral Care is a growing Swedish dental care chain with 23 clinic clinics in Sweden and Norway. In addition to the clinics, Oral Care offers mobile home dental care in a number of regions for those covered by the special dental care support. The company is owned by the management and by the investment fund Axcel, a Nordic investment company that focuses on medium-sized companies with great growth potential.

Tandgruppen Kungsbacka, with around 30 employees, is one of West Sweden's largest private dental clinics that provides general and specialist dental care for both children and adults.

Next Law would like to thank Oral Care for the trust they have placed in it and all parties and advisors for a smooth process.

Next Law has assisted Ecolime in the acquisition of electrical product companies

3 Feb 2022

Next Law, through Joacim Öhlund and Victor Holmberg, has assisted Ecoclime Group AB in the acquisition of Miljöbelysning Sweden AB.

Miljöbelysning develops and provides electrical products and software that provide more efficient energy utilization in the real estate industry and reduces climate impact.

Ecoclime offers advanced solutions in property technology for recycling, charging, storage, extraction and distribution of recycled and renewable thermal energy and is listed on Nasdaq First North Premier.

Next Law assists Snek Aktiebolag

24 Nov 2021

The Norrbotten kitchen manufacturer Snek Aktiebolag has raised new capital to expand and has also taken on new owners, including Lundqvist Trävaru AB. Snek manufactures quality kitchens with all wooden parts from suppliers in Norrbotten and has a unique IT platform for the customer to design their own kitchen. Next Law, through Mikael von Schedvin (responsible partner) and Ann-Christine Kankaanranta at Next Law's Luleå office, has assisted Snek's founders Sandrine Peraldi and Fredrik Karlsson Peraldi in the case.

Snek AB

Joacim Öhlund has assisted the Palisander Group

6 Apr 2021

Next Law, through Joacim Öhlund, has assisted Palisandergruppen in entering into an agreement for the sale of property to the listed K-Fast Holding AB. The transaction is carried out through the transfer of all shares in Palisander Förvaltning AB. The underlying total property value amounts to approximately SEK 122 million and the estimated date of occupancy is provisionally 30 October 2021.

World Trademark Review

19 feb 2021

Next Laws IP-avdelning har blivit topprankade av World Trademark Review vilket vi är mycket stolta över.

In the words of one foreign associate: “Recommending local counsel in Sweden is never a challenge, as the answer is always immediately Next.” The commercial set breaks into the WTR 1000 this year as “a high-class provider of IP services, from prosecution to complex litigation and everything in between”. Department co-leads Magnus Tonell and Tom Kronhöffer set the tone for the troop. Thanks to his knowledge in ancillary disciplines such as IT and marketing law and trade secrets, Magnus “has made a name for himself as a fantastic litigator and one of the leading experts in the country”. Fellow all-rounder Kronhöffer “has a great business sense, is quick to respond and offers creative solutions to various problems. Anti-counterfeiting is one of his core specialities and his clients all love him as he is super-friendly, great to work with and achieves superb results at a reasonable cost”.

WTF logo

Next Law assists in the sale of Sendoline AB to the Lifco group

9 Dec 2020

Next Law, through Joacim Öhlund, has assisted the owner of Sendoline AB in the sale of all shares in the company to the Lifco group. Sendoline, a niche manufacturer of dental products, had sales of approximately SEK 38 million in 2019. The operations will be consolidated in Lifco's Dental business area.

Next Law signs agreement with the Swedish Real Estate Association

9 Sep 2020

Next Law enters into an agreement with the Swedish Association of Real Estate Agents, with the assignment to provide legal advice to the association's approximately 1,000 affiliated real estate agents. The assignment will begin in 2021 and the parties hope that the collaboration will be long-term. The press release about the collaboration is available here:

FMF logo

Next Law assists Spiffbet in acquisition of Metal Casino

10 June 2020

Through Joacim Öhlund, Next Law has assisted Spiffbet AB in the acquisition of just over 90% of the shares in Vrtcl Gaming Group Sweden AB, which, among other things, operates online casino and sports betting under the name Metal Casino, with a focus on, among other things, Sweden, the United Kingdom, Germany and Finland. Since its inception in the fall of 2017, Metal Casino has managed to establish itself as one of the gaming industry's most unique brands with world-renowned figureheads such as Ozzy Osbourne. The transaction provides tangible synergy effects in the short and long term and is expected to significantly increase Spiffbet's turnover and have a positive impact on earnings from 2021.

Spiffbet is listed on Nasdaq First North Growth Market and develops online casino and betting games that are marketed under the brands Spiffbet Casino, STHLMGAMING and Spiffbet Sports.

WTR 1000 2020 Edition

18 Feb 2020

Tom Kronhöffer has received an award in the World Trademark Review WTR 1000 2020 regarding, among other things, processes

WTF logo

Next Law in collaboration with Swedish Corporate Lawyers

14 Feb 2020

In collaboration with the Swedish Corporate Lawyers Association, Next Law will hold several seminars on intellectual property law issues for members of the Swedish Corporate Lawyers Association during the year.
Please see the calendar at the Swedish Corporate Lawyers Association.

Sveriges Bolagsjurister logotyp

Next Law has advised Hästkällaren Rid Trav & Western AB

17 Jul 2019

Next Law has advised Hästkällaren Rid Trav & Western AB in connection with the company's listing on NGM Nordic MTF. Hästkällaren is a Swedish retailer of equipment for horses and riders, as well as related products for horses, horse care and equestrian sports. The first day of trading in the company's shares is today, 17 July 2019. Next Law's team has consisted of Joacim Öhlund (managing partner) and associate lawyer Nejra Poljo.

Are you Next?

17 Jun 2019

Are you an experienced lawyer considering the next step in your career? Do you work or have you worked with securities law, corporate law and/or M&A?

Then you can become part of our corporate law, securities law and M&A practice group where we mainly work with issues related to corporate acquisitions, capital raising, stock market listings, regulatory compliance, general meetings and other corporate and securities law issues.

Contact Joacim Öhlund to find out more.

Next Law advisor on rights issue on Spotlight Stock Market

17 Jun 2019

Cleantech company Enrad, which develops energy-efficient and environmentally friendly cooling & heat pump systems, has decided on a rights issue of units consisting of shares and warrants with preferential rights for the company's existing shareholders. The issue is secured to 100 percent through subscription obligations and guarantee commitments.

Upon full subscription, Enrad will receive approximately SEK 11.1 million before issue costs. The rights issue comprises a maximum of 2,317,155 units.

Managing partner Joacim Öhlund and associate lawyer Nejra Poljo are Enrad's legal advisors in connection with the rights issue.

Next Law assists in the purchase of Fåfängan Restaurang och Evenemang

14 Sep 2018

Next Law, through partners Kristoffer Sparring and Joacim Öhlund and associate lawyer Nejra Poljo, has assisted the buyers in connection with the purchase of Fåfängan Restaurang och Evenemang from Nordic Trade Network AB. The purchase was carried out through the acquisition of all shares in Vanitybar AB, which owns and operates the restaurant business located on Södermalm in Stockholm.

Next Law assists Carlyle Group in its acquisition of Akzo Nobel's Specialty Chemicals business area

26 Jun 2018

Next Law, through partners Pia Nyblaeus and Joacim Öhlund and associate attorney Nejra Poljo, has assisted Carlyle Group with advice on employment and corporate law matters in connection with Carlyle Group and GIC's acquisition of the entire Specialty Chemicals business area from Akzo Nobel for EUR 10.2 billion, equivalent to approximately SEK 100 billion. The transaction is expected to be completed before the end of 2018.

Marketing law and "influencers"

25 Jun 2018

Magnus Tonell and Pia Järvengren Gerner have written extensively about the rules that influencers need to follow in the borderland of advertising, based on the so-called KISSIE ruling and rulings in RON, in the latest issue of BrandNews.

Next Law assists in the sale of Mysec Sweden AB

21 Jun 2018

Mysec develops, installs, operates and maintains advanced security systems for companies and the public sector. With a strong position in the Stockholm region, the company has built long-term customer relationships with documented high delivery quality. Mysec, which was named DI Gasell in 2017, has delivered 25% growth on an annual basis over the past three years and turnover from May 2017 to February 2018 amounted to approximately SEK 29 million.

Important major customers include Arla, ICA, Botkyrka Municipality, the City of Stockholm, SATS, and a major Swedish clothing chain.

Next Law expands with three new partners

9 Jan 2018

Next Law welcomes three new partners - Claes Lood, Kristoffer Sparring and Joacim Öhlund - from the beginning of the year. The addition strengthens the firm's offering of M&A, stock market law, real estate law and commercial contract and dispute resolution, which provides an increased breadth to offer our clients. Claes Lood and Kristoffer Sparring have extensive experience in commercial dispute resolution. Claes Lood also brings extensive expertise in brokerage-related law and economic associations. Kristoffer Sparring has extensive experience in commercial contract law and sports law. Joacim Öhlund brings with him a broad range of expertise and extensive experience in M&A, stock market law and corporate law.