When the NIS2 directive is discussed, the focus often lands on technology: security systems, IT infrastructure, incident response. That is not wrong, but it is rarely where the real challenge lies.
In Sweden, the directive is implemented through national cybersecurity legislation. For many organisations, that points to something more fundamental: having control over how work is actually performed every day.
This guide covers what NIS2 is, who is covered, what the requirements and penalties look like, and, most importantly, what the rules demand of daily operations. At the end you will find a practical checklist and answers to the most common questions.
What is NIS2?
NIS2 is the EU's updated directive on cybersecurity (Directive (EU) 2022/2555). It replaces the original NIS directive from 2016 and raises the bar in three ways: far more sectors are covered, the minimum requirements are clearer and stricter, and responsibility is placed explicitly on company management rather than on the IT department.
The directive entered into force at EU level in January 2023, and member states were required to transpose it into national law by October 2024. In Sweden, that happens through the Cybersecurity Act (cybersäkerhetslagen).
Who is covered by NIS2?
NIS2 divides organisations into essential entities and important entities across 18 sectors. The high-criticality sectors include energy, transport, banking and financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, and space. Other covered sectors include postal services, waste management, chemicals, food production and distribution, manufacturing (including medical devices, electronics, machinery, and vehicles), digital providers, and research.
As a general rule, the directive applies to organisations in these sectors with at least 50 employees or an annual turnover of at least 10 million euros. Smaller organisations can still be covered when their services are critical, for example sole providers of an essential service.
Two things surprise many businesses:
- The supply chain is in scope. Even if your company is not directly covered, your customers may be, and NIS2 requires them to put security requirements on their suppliers. The requirements travel down the chain.
- Management is personally accountable. Management bodies must approve the risk measures, oversee their implementation, and undergo training. Liability cannot be delegated to IT.
NIS2 and the Swedish Cybersecurity Act
NIS2 is the EU directive; the Cybersecurity Act is how Sweden implements it in national law. The requirements originate in the directive, while supervision, registration, and the practical details are governed by Swedish law and authorities, with MSB (the Swedish Civil Contingencies Agency) in a central role alongside sector-specific supervisory authorities.
The Swedish legislative timeline has shifted during the process, so verify the current status, application dates, and registration requirements with MSB. The practical guidance does not change with the dates: the requirements are extensive enough that preparation takes months, not weeks, so the right time to start is before the obligations apply.
What NIS2 really changes
At its core, NIS2 is an attempt to raise the floor. More sectors are in scope, requirements are clearer, and responsibility sits closer to the business.
What is often missed is that the requirements are not only about having the right things in place, but they must work in practice.
It is no longer enough to:
- have a policy
- have documented procedures
- have training material
What is expected is something else: being able to show that it is used.
The key requirements in brief
The directive requires covered organisations to take risk management measures across ten areas, including:
- risk analysis and information security policies
- incident handling
- business continuity, backups, and crisis management
- supply chain security
- security in acquisition, development, and maintenance of systems
- policies and procedures to assess whether the measures actually work
- basic cyber hygiene practices and cybersecurity training
- policies on cryptography and encryption
- personnel security, access control, and asset management
- multi-factor authentication where appropriate
On top of that come incident reporting obligations with tight deadlines: an early warning to the authority within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month.
Notice how few of these are purely technical. Training, procedures, follow-up, supplier management, and the ability to assess whether measures work are operational questions, and they are precisely the areas where evidence of daily execution is required.
What are the penalties?
The sanctions are designed to reach management attention. Essential entities can be fined up to at least 10 million euros or 2 percent of global annual turnover, whichever is higher. Important entities face up to at least 7 million euros or 1.4 percent. In addition, management bodies can be held personally accountable for failures to comply, and supervisory authorities can impose binding instructions and, in severe cases for essential entities, temporarily suspend managers from their duties.
Where it starts to get difficult
Most organisations already have some form of structure. There are documents, instructions, checklists. The problem is that they can easily live a life of their own:
- Procedures exist, but are followed differently depending on the person
- Tasks are done, but without clear follow-up
- Knowledge exists, but does not reach the whole organisation
A gap appears between how work is supposed to run and what it looks like day to day. That is the gap NIS2 makes visible.
It is less about IT than you might think
It is easy to read NIS2 as a technical initiative. Yet in many organisations the risk is not in the systems but in execution, in how procedures are interpreted, how tasks are prioritised, and how responsibility is shared. That is where variation appears, and where consequences show up.
From documents to reality
Meeting the requirements is not solved by improving documentation alone. What must change is the link between instruction and action.
In practice that means:
- it must be clear what should be done
- it must be clear who does it
- it must be possible to verify that it was actually done
It sounds simple. Yet this is often where things break down.
Where many organisations get stuck
It is common to assume the answer is more information: more documents, more guidelines, more training. Without structure in execution, that only adds more to manage.
What is missing is not content; it is coherence.
A practical NIS2 checklist for daily operations
A workable starting point, in the order most organisations should take it:
- Confirm your scope. Check your sector and size against the Cybersecurity Act, and ask your key customers whether their NIS2 obligations put requirements on you as a supplier.
- Assign ownership. Name a responsible person and put NIS2 on the management agenda; the accountability sits there anyway.
- Map critical processes, systems, and suppliers. You cannot protect or report on what you have not identified.
- Run risk assessments on a fixed cadence, and document them, not as a one-off project but as a recurring routine.
- Turn policies into daily routines. Break the security measures down into scheduled checklists and recurring tasks that named people complete.
- Set up the incident chain. Everyone should know what counts as an incident, who to alert, and how the 24-hour and 72-hour reporting deadlines are met in practice.
- Train everyone, and track completion. Cyber hygiene training is an explicit requirement, and untracked training cannot be demonstrated.
- Put requirements on suppliers and follow up on them, since supply chain security is part of your own compliance.
- Log execution. Who did what, and when. This evidence trail is the difference between claiming compliance and showing it.
- Review and improve on a schedule, and report status to management regularly.
If your organisation already runs a systematic internal control program, the working method will feel familiar: NIS2 compliance is largely the same discipline of routines, evidence, and follow-up applied to cybersecurity.
How Todolo fits in
Todolo is not built to replace security systems. It is built to create structure in how work is performed. That helps ensure:
- procedures do not only exist, they are used
- tasks are not only planned, they are followed up
- work does not only happen, it can be shown afterwards
When instructions, tasks, and follow-up are connected, dependence on individuals decreases. It becomes clearer what should happen, and easier to see what actually did.
The table below is a simplified illustration of how common requirement areas can map to everyday traceability in Todolo, not legal advice, but a practical picture.
| NIS2 requirement area | How Todolo can support your compliance work |
|---|---|
| Risk management measures | Digital checklists and recurring tasks for regular security controls. |
| Staff training | Education module with micro-learning, quizzes, and traceable completion of assessments. |
| Incident management | Fast paths for reporting, clear instructions in critical situations, and follow-up in one flow. |
| Documentation expectations | Logging of completed activities (who did what, and when) linked to routines and documents. |
What changes in practice
When work becomes more structured, something quite concrete happens:
- variation decreases
- onboarding gets easier
- follow-up needs less manual effort
And perhaps most importantly, it becomes possible to answer questions that are otherwise hard:
- Did we do what we were supposed to?
- When was it done?
- By whom?
NIS2 in practice
It is easy to treat NIS2 as a compliance project. In practice, it is just as much about making the business work better. The requirements push for clarity, consistency, and follow-up. For organisations that take it seriously, it is not only about meeting rules, but about working in a more controlled way every day.
Frequently Asked Questions
What is NIS2?
NIS2 is the EU's updated directive on cybersecurity (Directive 2022/2555). It replaces the original NIS directive from 2016, covers many more sectors, sets clearer minimum requirements for risk management and incident reporting, and makes company management explicitly accountable for compliance.
Who does NIS2 apply to?
Essential and important entities in 18 sectors, including energy, transport, health, food, manufacturing, digital infrastructure, and public administration. As a general rule it covers organisations with at least 50 employees or 10 million euros in annual turnover, and some smaller organisations whose services are critical. Suppliers to covered organisations are also affected indirectly through supply chain requirements.
What is the difference between NIS2 and the Swedish Cybersecurity Act?
NIS2 is the EU directive; the Cybersecurity Act (cybersäkerhetslagen) is how Sweden implements it in national law. The requirements come from the directive, while supervision, registration, and practical details follow from Swedish law and authorities such as MSB.
What are the penalties for not complying with NIS2?
Fines of up to at least 10 million euros or 2 percent of global annual turnover for essential entities, and up to at least 7 million euros or 1.4 percent for important entities. Management can also be held personally accountable.
When do businesses need to comply?
The EU deadline for national implementation was October 2024, and the Swedish obligations follow the Cybersecurity Act. Timelines have shifted during the legislative process, so verify current dates with MSB. In practice, preparation takes months, so the safe answer is: start now.
How should a business start preparing for NIS2?
Confirm whether you are in scope, assign ownership at management level, map your critical processes and suppliers, set up incident reporting paths that meet the 24-hour and 72-hour deadlines, train staff with tracked completion, and make daily execution traceable so compliance can be demonstrated, not just claimed.
A final reflection
Many organisations will focus on the right things: systems, security, technology. Yet what often decides the outcome is simpler: how work is actually performed, day after day. That is where the difference shows, and where the greatest risk, and opportunity, lies.
Would you like a clearer picture of how work is actually performed in your organisation, and where variation exists today? That is often the most valuable place to start.
Contact us if you want to talk about building clearer structure in day-to-day work.


