New cybersecurity regulations have now come into effect – this is what you need to do now

New cybersecurity regulations have now come into effect – this is what you need to do now

On October 1, the regulations related to the Cybersecurity Act came into effect. In total, the regulations comprise 27 pages of legal text. But don't worry. I've read them so you don't have to.
The Cybersecurity Act came into force on 15 January 2026. On 1 October, MCFFS 2026:11 also came into force – the regulations that specify the requirements for security measures and management training. The act covers many medium-sized and large operators in the 18 sectors listed in the NIS2 regulations, as well as certain public activities and in some cases smaller activities of particular importance. Each organization needs to assess whether, and to what extent, it is covered.
The law itself is a significant tightening of previous legislation. In the event of non-compliance, the supervisory authority can intervene with a warning, an injunction – possibly combined with a fine – or a sanction fee. For significant private operators, the fee can amount to the higher of 2 percent of global annual turnover or the equivalent of 10 million euros.
The fact that the law places such a large responsibility on management is in line with the fact that cybersecurity is something that needs to be built from the top down. It simply has to permeate the entire business, and then it is not enough to outsource the job to the organization's security manager or IT department.
In particularly serious cases, a board member, CEO or other covered executive in a significant private business may be prohibited from holding a management function in the business. The threshold is high: the business must first have failed to comply with an injunction, the violation must be serious and the person must have acted intentionally or with gross negligence.
The new regulations have been developed by the Swedish Civil Defence Agency (MCF) and you can find all the documents here. here. In broad terms, it is now required, among other things, to:
- The management of the business undergoes safety training.
- The business applies systematic and risk-based work with cybersecurity.
- The law also requires reporting significant incidents to the National Cyber Security Center (NCSC).
- The supervisory authorities can carry out random inspections of operations to verify compliance with the law and its regulations.
So what do you need to do now (if you haven't already)? Here's a quick checklist:
- Make an assessment of whether and how the activity is covered.
- Ensure management training and mandate for cybersecurity work.
- Conduct a gap analysis or internal audit against the requirements of the law and relevant regulations.
- Prioritize actions, appoint owners, decide on resources and continuously monitor remaining risks.
- Security requirements should be managed during purchasing and outsourcing, so that suppliers do not become a blind spot in the resilience of the business.
These steps are a good start. However, they are not enough in themselves to demonstrate that the business meets all the requirements or has the resilience that the law aims for. It is important to remember that the Cybersecurity Act requires ongoing monitoring, updates and reporting.
So this is not a project with an end date. It is a continuous work, maybe not something you need to do every day, but it is a skill that must be maintained.
In short, you can say that you have done your job when the organization has a real ability to handle serious incidents, not when it just passes an inspection by a regulatory authority.
Latest articles






Insights
Latest articles

Where do humans fit into a development process where AI agents write the code?

In the Shadow of the Hugging Face Attack: How to Safely Sandbox AI Models
