The NIS2 Directive (DIRECTORY (EU) 2022/2555 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 December 2022 concerning measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972 and repealing Directive (EU) 2016/1148) was to have been transposed into Swedish law on 18 October 2024, but has been delayed for various reasons. The NIS2 Directive thus replaces the so-called NIS Directive. A special investigation (the “Inquiry”) has, on behalf of the government, prepared a proposal for a cybersecurity law (the “Cybersecurity Act”) regarding the actual implementation of the NIS2 Directive (see SOU 2024:18 New rules on cybersecurity and in some parts also 2024:64 Resilience in essential services).
The inquiry has in many ways made a professional contribution and proposed legislation that is in many parts easy to understand in the short time they were given. Despite this, there are certain regulations that may need to be analyzed. I have chosen to only analyze the incorporation of Article 21 of the NIS2 Directive into the Cybersecurity Act. To some extent, this has already been done in some of the more than 160 consultation responses the inquiry received. For those interested, reference is made to the Consultation for SOU 2024:18 New regulations on cyber security - Regeringen.se.
Article 21 can be considered one of the more important regulations to incorporate into Swedish law as it contains the basic requirements for risk management measures for cybersecurity. These requirements are intended to comprehensively ensure or at least improve the protection of public and private operators against both cyber security incidents, antagonistic and otherwise, which often result in a number of undesirable consequences, such as lost trust, lost customers, costs for forensic investigation and restoration of systems and data, and in the worst case even the cessation of the entire operation. In addition to the consequences for the affected operator, these incidents can also lead to consequences for the nation's economy.
For reasons of space, I have not copied the entire article 21 in this article nor certain other text to which I partially refer. For those interested, these texts can be read in their entirety in the NIS2 Directive and in SOU 2024:18. It should of course be added that there will be regulations from both the MSB and the designated supervisory authorities, which can hopefully clarify some of the regulations I am analyzing, but the fact remains that the interpretations made by the Inquiry of the NIS2 Directive (and whether they become the actual legislation) will still be decisive for the upcoming regulations.
Directive-like or not
The Inquiry has not incorporated Article 21 of the NIS2 Directive in the proposal for the Cybersecurity Act in a directive-like manner. This is justified by the fact that, according to the government directive, the NIS2 Directive should not be “introduced in a directive-like manner, but that the proposals should be designed based on the systematics and terminology used in Swedish law. A normal use of language should be sought. It also explicitly follows from the government directive that the terminology used in the directives should be adapted to accepted concepts in national regulation”.
Contrary to the Inquiry, PTS considered in its response to the consultation “that it is important that the Cybersecurity Act uses formulations as close to the NIS2 Directive as possible”. To some extent, it is difficult to disagree with PTS’s opinion that the Cybersecurity Act should be more directive-like, especially when it comes to the writings regarding risk management measures. This is because these rules should be regulated as coherently as possible within the EU, among other things to avoid the differences created by the previous NIS Directive. It should be mentioned here that the NIS2 Directive, which replaces the NIS Directive, was introduced, among other things, to counteract significant differences for economically significant activities and in principle created at least some barriers to trade within the EU. It is also unlikely to create any major contradiction with the systematics and terminology used in Swedish law to incorporate Article 21 and it can probably be considered that even accepted concepts could have been used. The question therefore becomes how well such a “non-directive-like transposition” corresponds to Article 21 of the NIS2 Directive, which, it should be added, contains minimum requirements for measures for risk management and cybersecurity, i.e. at least the requirements stated in Article 21 must be incorporated and this should be done in as clear a manner as possible.
Article 21 of the NIS2 Directive has been incorporated into Chapter 3, Section 1 of the Cybersecurity Act. A comparison between these two regulations creates some doubt about how well the transposition has actually been successful.
Article 21(1) of the NIS2 Directive compared to Chapter 3, Section 1 of the Cybersecurity Act
The first question is whether the Investigation into the Cybersecurity Act encompasses all the requirements set out in Article 21(1) of the NIS2 Directive.
NIS2 Article 21(1) states:
Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to address risks to the security of network and information systems that they use for their activities or to provide their services and to prevent or minimise the impact of incidents on the recipients of their services and on other services.
Taking into account the latest and, where applicable, relevant European and international standards and the costs of implementation, the measures referred to in the first subparagraph shall ensure a level of security of network and information systems appropriate to the risk presented. In assessing the proportionality of those measures, due account shall be taken of the degree of risk exposure of the entity, its size and the likelihood of incidents occurring and their severity, including their societal and economic consequences.
The introductory text of Chapter 3, Section 1 of the Cybersecurity Act states:
The operator shall take technical, operational and organisational risk management measures to protect network and information systems and the physical environment of the systems against incidents. The measures shall be based on an all-risk perspective and a risk analysis and be proportionate to the risk. They shall be evaluated and in particular include the following:
When read in a comparative manner, it is clear that Article 21(1) of the NIS2 Directive is more detailed than the Cybersecurity Act. Of course, a more detailed text is not a better way to describe the measures to be taken, but in Chapter 3, Section 1 of the Cybersecurity Act, certain phrases have been omitted. The measures to be taken are not qualified as appropriate. Furthermore, the phrases “relevant European and international standards”, “size of the entity” and “taking into account the implementation costs” are missing, which is hardly covered by the last sentence of Chapter 3, Section 1 of the Cybersecurity Act, i.e. that “The measures shall be based on an all-risk perspective and a risk analysis and be proportionate in relation to the risk”. This may therefore give the impression that the meaning of Chapter 3, Section 1 of the Cybersecurity Act is more limited.
The concept of all-risk perspective incorporated in Chapter 3, Section 1 of the Cybersecurity Act may be considered a somewhat odd bird in Swedish law. The concept is certainly used in Article 21.2 of the NIS2 Directive, but as far as I know it is not used in Swedish legislation and probably not in normal language either. One therefore wonders why it was chosen to use that particular concept when, according to the government directive, the directive is not to be transposed in a directive-like manner. This is especially true in the portal regulation regarding risk management measures for cybersecurity. The concept of all-risk perspective is certainly used in the Government Bill (prop. 2024/25:34) Total Defence 2025-2030 and in the National Cyber Security Centre's (NCSC) paper A New Era of Cyber Security 2025-2029 and can therefore possibly be considered to have become, or at least will become, a concept that is becoming more common in both legislation and normal language.
The understanding of the concept of all-risk perspective is likely to be somewhat uncertain. In recital 79 of the NIS Directive, however, using the term all-risk approach, one can read:
Recital 79:
Since threats to the security of network and information systems can have different origins, cybersecurity risk management measures should be based on an all-risk approach aimed at protecting network and information systems and their physical environment against events such as theft, fire, flood, telecommunications or power outages or unauthorised physical access to, damage to or disruption of an essential or critical entity's information and information processing resources, which could undermine the availability, authenticity, accuracy or confidentiality of data stored, transmitted or processed or of the services offered by or accessible through network and information systems. Cybersecurity risk management measures should therefore also cover the physical security and environmental security of network and information systems by including measures to protect such systems against system failures, human errors, intentional malicious acts or natural phenomena in accordance with European and international standards, such as those included in the ISO/IEC 27000 series. In this regard, essential and important entities should also address personnel security as part of their cybersecurity risk management measures and establish appropriate access control strategies.
To understand the concept of an all-risk approach, according to the NIS Directive, one should therefore base one's risk analysis on, in simple terms, that network and information systems should be protected against physical attacks as well as against other attacks, which must be considered the very foundation of cybersecurity work. Anything else or more than that is difficult to interpret and one gets the impression that it is already stated in the Cybersecurity Act, Chapter 3, Section 1, first sentence.
The National Cybersecurity Centre's (NCSC) paper A New Era of Cybersecurity 2025-2029 states that "the national cybersecurity strategy is based on national needs and on the NIS 2 Directive and its all-risk perspective to address a range of challenges such as skills shortages, complex regulation, vulnerable supply chains and lack of systematic cybersecurity work". It may not be easier to understand what is meant by an all-risk perspective when reading this and interpretations will likely be very different until some form of standard is set for what is meant by an all-risk perspective. Note, however, that NSCS uses the lack of systematic cybersecurity work as one of the challenges, see more about this below.
In conclusion, it is noted that a directive-like regulation using normal language in the introductory text would probably have been experienced as more appropriate. In particular, the clarifications contained in the second paragraph of Article 21.1 of the NIS2 Directive disappear. It can also be mentioned in this context that Article 21.1 of the NIS2 Directive is reminiscent of the way security is regulated in connection with processing in Article 32 of the GDPR, which is certainly an EU regulation but, in accordance with our membership in the EU, is still Swedish law. In addition to this, the introductory text of the Cybersecurity Act, according to the Inquiry, should be understood as meaning that Strategies for risk analysis and information systems security should be established, see more about this below.
Strategies for risk analysis and information systems security
Article 21(2) of the NIS2 Directive lists ten points of measures to be taken to protect network and information systems. The corresponding list in Chapter 3, Section 1 of the Cybersecurity Act is nine, and yet the paragraph has chosen to split one of the points from the NIS2 Directive into two points, thus leaving only 8 points remaining from the NIS Directive in Chapter 3, Section 1 of the Cybersecurity Act.
One point that is completely excluded from the Cybersecurity Act is “strategies for risk analysis and information systems security”. The reason why the Commission chose not to introduce the measure as a separate point is justified by the fact that “With regard to this point, the Commission believes that it does not need to be stated separately, since it follows from the Commission’s proposal for comprehensive regulation.” After the comparative texts of the NIS2 Directive, Article 21.1, and the introduction to the Cybersecurity Act, Chapter 3, Section 1 (see above), it can be discussed whether it is really possible to understand that “strategies for risk analysis and information system security” really follow from the Commission’s overall regulation. A clearer regulation of this kind would have been desirable and it would not have contradicted systematics, terminology and normal language use – not least it would have made understanding easier.
As mentioned in the government directive, it was stated that normal language use should be strived for. According to the Swedish Academy’s Dictionary (SAOL), the word “strategies” means “orderly, planned”, i.e., in this case, an orderly and planned cybersecurity and information security policy. If for no other reason, it would have been an advantage for the operator to state more clearly that strategies should exist, as otherwise it would have had to be interpreted (possibly somewhat unnecessarily) into the overall regulation. One lesson that could have been learned is how several companies established a “starter package” with certain rules and documentation on personal data processing when the GDPR came into force but did not implement a strategy (orderly and planned policy for the processing of personal data) for the same.
The absence of an explicit requirement for a strategy for risk analysis and the security of information systems does not lead to particularly clear regulation. Given that what is stated in Chapter 3, Section 1 of the Cybersecurity Act are the requirements against which a supervisory authority can take action (see below), it would have made it easier for both operators and supervisory authorities to clearly state the requirement.
Security in the acquisition, development and maintenance of network and information systems, including vulnerabilities and vulnerability information
The fifth measure in Article 21(2) of the NIS2 Directive states “security in the acquisition, development and maintenance of network and information systems, including vulnerabilities and vulnerability information”.
The inquiry has here assessed the concept of acquisition as only referring to taking over something with ownership rights. This interpretation is of course the most likely, but in common usage it should be taken into account that one can acquire knowledge, acquire a license, acquire a lease and use similar expressions where none of the aforementioned implies any actual ownership rights. The English version of the NIS2 Directive states “security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure”. In the same way as in Swedish, one can acquire knowledge, acquire a license, acquire a lease where nothing implies any actual ownership rights.
In its response to the consultation, MSB suggested that acquisition could be replaced with procurement to signal that the requirements apply even when something has not been purchased, for example in the case of outsourcing. In response to this, the Inquiry states that when it comes to outsourcing, this is taken care of to some extent in the section on security in the supply chain (see Cybersecurity Act Chapter 3 Section 1 p. 3). Such uncertainty does not seem entirely desirable. Since it is a minimum directive, the Inquiry could have filled in the possible uncertainty by “extending” the requirement to include acquisitions in order to thereby more concretely ensure that it is also covered. Since the Inquiry nevertheless perceives that it is already covered by security in the supply chain to some extent, procurement instead of acquisition would probably not even have extended the requirements of the NIS2 Directive and thus would not have required any special justification (which an extension of a minimum directive usually requires). In addition to this, it would seem that if this point were to apply only to acquisitions that only concern ownership, it would probably not affect many people, as complete network and information systems are not often possible to "buy with ownership" and for many this is probably not a realistic way to go. The question can therefore be asked whether the NIS2 Directive only intended a complete transfer of rights or actually also includes outsourcing.
In accordance with the above, I am inclined to agree with MSB's proposal and include the word acquisition to refer to procurement.
Obliged to take into account the results of the coordinated security risk assessments of critical supply chains carried out in accordance with Article 22(1)
Article 21(3) of the NIS2 Directive states that Member States shall ensure that entities, when considering appropriate measures under point 2(d) of Article 21 (i.e. supply chain security), are obliged to take into account the results of the coordinated security risk assessments of critical supply chains carried out in accordance with Article 22(1) of the NIS2 Directive. This article states that the Cooperation Group may, in cooperation with the Commission and ENISA, carry out coordinated security risk assessments of specific critical supply chains for ICT services, ICT systems or ICT products.
The investigation believes that NIS2 Directive 21(1) – 21(3) have been implemented through Chapter 3, Section 1 of the Cybersecurity Act. As far as I have been able to read, there is no obligation to take into account the results of the coordinated security risk assessments stated, either in Chapter 3, Section 1 of the Cybersecurity Act or in any other section of the legislation, i.e. a requirement to take into account the results of these assessments. The absence of minimum regulation usually means that if you choose not to take this requirement into account, you must justify why you do not do so. Is the absence of this requirement an oversight or is it intended to be fulfilled in some other way? In any case, it does not become clearer when you choose to omit this wording entirely in the Cybersecurity Act.
Conduct systematic and risk-based information security work
The NIS2 Directive does not contain any explicit provision stating that information security work should be conducted systematically. Such a regulation is found in the previous Act (2018:1174) on information security for socially important and digital services (the “NIS Act”), the Swedish implementation of the predecessor to the NIS2 Directive, i.e. the NIS Directive. MSB stated in its response to the consultation that it is important to also stipulate in the Cybersecurity Act that information security work should be carried out systematically and risk-based in the same way as in the NIS Act. The investigation noted that this requirement does not follow from the NIS2 Directive but nevertheless chose to introduce it in the Cybersecurity Act, although not in Chapter 3, Section 1, but in a separate paragraph, namely Chapter 3, Section 2. This latter paragraph is not included among the paragraphs over which supervisory authorities shall intervene with supervision and possible sanctions (cf. Cybersecurity Act Chapter 5 Section 1 with Chapter 3 Section 2 and that the intervention of supervisory authorities is limited to disregarding the regulations issued with the support of, among others, Chapter 3 Section 1 of the Cybersecurity Act, but not Chapter 3 Section 2).
The above must therefore be understood as meaning that the supervisory authorities cannot intervene, which makes the obligation highly limited. An analogy, perhaps not entirely comparable but still, is that it has approximately the same effect as the ban on walking towards a red man, i.e. it is prohibited but it does not lead to any sanctions (other than if your walking towards a red man, for example, leads to a traffic accident). The truth is that this particular requirement is not explicitly and verbatim stated in the NIS2 Directive as one of the points in Article 21 of the NIS Directive, but the question is whether it can still be considered to be covered by Article 21.
As I have previously written (see above), the Inquiry believes that strategies for risk analysis and information security work are covered by the introductory text of Chapter 3, Section 1 of the Cybersecurity Act, while I believe that it should have been explicitly written in as one of the points. Regardless of which path one chooses, the section covers strategic work. If, as I have previously done, one uses SAOL to understand the normal language usage and its stated meaning of the words Strategy and Systematic, one gets the explanations that strategy means the art of waging a war; plan in general, while systematic means orderly, planned. This alone should lead to the idea that strategic work should be systematic work, otherwise how can it be strategic. Furthermore, the NIS2 Directive in Article 21.2 stipulates requirements for strategies and procedures for assessing the effectiveness of risk management measures for cybersecurity and in the same article specifies basic practices for cyber hygiene (practices has been somewhat dubiously translated from the English word practices in the Swedish version of the NIS2 Directive and should probably be translated with words such as methods or routines). The Inquiry chose not to include the latter point in the Cybersecurity Act on the grounds that “practices for cyber hygiene are, in the Inquiry’s assessment, unnecessary, since cyber hygiene is a collective term for what follows from the article as a whole”, i.e. a (rather advanced) interpretation is required by operators to understand Chapter 3, Section 1 of the Cybersecurity Act as a whole and to understand what is incumbent on them. An interpretation that I must admit, I might not have succeeded in coming up with if I had not read the NIS2 Directive. It should be recalled once again that Chapter 3, Section 1 of the Cybersecurity Act contains the measures against which supervisory authorities can intervene.
The above in any case leads me to understand the strategic work to also include systematic work. In the Government Bill 2024/25:34, page 129, the term is used in the sense of “The lessons from Ukraine show the importance of systematic cybersecurity work, access to redundant and diversified communication channels, high robustness in the central systems of electronic communications networks and well-functioning cooperation between private and public actors” and in the NCSC’s document A New Era of Cybersecurity 2025-2029, Systematic and effective cybersecurity work is used as one of the three most important measures required for a national cybersecurity strategy (see, among other things, page 26 ff. in the aforementioned document).
As is well known, a directive cannot be interpreted solely on its articles and an analysis of the reasons often provides a clearer picture of an article and its intended content. It is therefore appropriate to check what is written in two of the recitals of the NIS2 Directive, namely recital 49 and recital 122. Recital 49 states the following with regard to cyber hygiene.
Cyber hygiene policies provide the basis for protecting the infrastructure of network and information systems, hardware, software and security of online applications, as well as business or end-user data on which entities rely. Cyber hygiene policies, which include a common basic set of procedures, including software and hardware captioning, password changes, handling of new installations, restriction of user accounts at administrator level and data backup, enable a proactive framework for preparedness and overall safety and security in the event of incidents or cyber threats. ENISA should monitor and analyse the cyber hygiene policies of the Member States.
The second sentence in particular leads me to the idea that cyber hygiene requires systematic, or as SAOL puts it, orderly and planned work.
Recital 122, which is itself about supervision, states the following (I am only copying parts of recital 122, i.e. the parts I consider relevant).
[……..]. Significant entities should therefore be subject to a comprehensive supervisory system with ex ante and ex post supervision, while important entities should be subject to simpler supervision, ex post only. Important entities should therefore not be required to systematically document compliance with cybersecurity risk management measures, while competent authorities should apply a reactive ex post supervision and thus have no general obligation to supervise these entities. […..]
In recital 122, the NIS2 Directive distinguishes between essential and important entities. The essential entities should not be obliged to systematically document compliance with the risk management measures. Although the opposite conclusion is not always preferable, I am committed to precisely such a conclusion, i.e. my opinion is that the essential entities are obliged to systematically document compliance with the risk management measures. This is consistent with the fact that supervision of essential entities may only take place if the supervisory authority has reasonable grounds to assume that the Cybersecurity Act or regulations are not being complied with (see Cybersecurity Act Chapter 4 Section 3) while supervision of essential entities can take place regardless of whether there is reasonable grounds for it. Does systematically documenting compliance with the risk management measures mean the same as conducting systematic information security work? I am inclined to believe so, although possibly only for essential operators.
Conducting systematic and risk-based information security work is a requirement in the Cybersecurity Act that is not covered by the NIS2 Directive according to the Inquiry and has therefore not been subject to supervision or sanctions (see above). In my opinion, a lack of or non-existent systematic and risk-based information security work should be something that can actually be considered to follow from the NIS2 Directive and could lead to supervision and/or sanctions, if nothing else, at least for significant operators. It should be said that there are opportunities for supervisory authorities to exercise supervision and intervene against operators because the operator has failed in risk management measures (see Cybersecurity Act Chapter 5 Section 1), but such a deficiency does not in itself include a lack of or non-existent systematic and risk-based information security work but must be based on something else in Cybersecurity Act Chapter 5 Section 1.
Finally, I would like to mention that Commission Implementing Regulation (EU) 2024/2690 (the “Implementing Regulation”), a so-called delegated regulation/act which the Commission is empowered to adopt under the NIS2 Directive, which entered into force on 7 November 2024, in the Annex on Technical and Methodological Specifications in point 1.1.2 (under the heading Strategy for security of network and information systems) stipulates that the security strategy shall be reviewed and, where applicable, up-labelled by the management bodies at least once a year and when significant incidents or significant changes to operations or risks occur. The results of these reviews shall be documented. The Implementing Regulation does not apply to all operators but only to those that operate services of a cross-border nature (e.g. cloud service providers) and which are therefore considered particularly important for the security of Europe. Is what is stipulated in the Implementing Regulation an expression of systematic and risk-based information security work? I'll leave the question hanging in the air, but systematic doesn't necessarily mean daily, monthly or any other period of time, but it should involve orderly and planned work.
Some final words
Once the legislation has entered into force, it will probably not be a whole bunch of lawyers interpreting it, but CISOs, IT managers, etc. who will have to incorporate the regulation into practical work. With the, in my opinion, ambiguities contained in the Inquiry's proposal, these people will have at least the same problems with the interpretation as I have. The predictability of what measures a business operator should actually take will therefore be unclear. In addition, the supervisory authorities must take measures if a business operator violates Chapter 3, Section 1 of the Cybersecurity Act. In summary, it is therefore my opinion that the transposition of Article 21 of the NIS Directive could have been done in a clearer way. With the uncertainty I want to show above, I await the legislative council's referral and the bill to see whether the final legislation will change from the Inquiry's proposal.