Resilience becomes law. What Sweden's new CER law means for you

On 1 January 2027 Sweden's CER law takes effect, adding physical-protection requirements for essential services. Here is how to prepare in time.

Total Defence · · 5 min read

On 1 January 2027 a new law takes effect that makes resilience a legal concept in Sweden. Government bill 2025/26:303 implements the EU’s CER Directive and complements the Cybersecurity Act with requirements on the physical protection of essential services. Here we walk through what the law means, who it captures, and what you should do already now.

From directive to Swedish law

The CER Directive (EU) 2022/2557 was adopted at the same time as the NIS2 Directive, and the two are deliberately built as a pair. NIS2, implemented in Sweden through the Cybersecurity Act that entered into force in January 2026, governs the protection of networks and information systems. The CER Directive governs what the cybersecurity discussion often forgets: the physical resilience of the operations society cannot do without.

On 14 July 2026 the government submitted the bill A new law for increased resilience of critical entities. The law is proposed to take effect on 1 January 2027 and is being considered by the Riksdag during the autumn.

The logic behind the split is easy to explain to a management team. The Cybersecurity Act protects your systems against digital attacks. The CER law protects your ability to deliver the service even when something physical happens: sabotage against a substation, a flood at a water treatment plant, the loss of key personnel. Society’s function depends on both.

Who is covered and how you get designated

An important difference from the Cybersecurity Act is how entities come under the regime. The Cybersecurity Act relies on operators registering themselves. The CER law instead relies on identification by government decision. It is the state that designates which entities are critical, and the one designated is informed through a formal decision.

The sectors broadly correspond to the essential sectors in the NIS family: energy, transport, drinking water, wastewater, healthcare, food and public administration, among others. Three areas are, however, excluded: banking, financial market infrastructure and digital infrastructure, because they are already covered by other regulation.

For the one identified, the clock starts ticking. The obligations apply nine and ten months respectively after the identification decision. That sounds like plenty of time, but anyone who waits to build the capability until the decision arrives faces a very steep climb.

The requirements in brief

The law’s requirements are fewer and more focused than the Cybersecurity Act’s, but they are concrete and auditable.

  • A risk assessment at least every four years, covering both antagonistic threats and other events that could disrupt delivery of the essential service.
  • Measures focused on physical protection, documented in a written resilience plan. The plan is the law’s central governing document and will likely be specified further in regulations.
  • Background checks for sensitive roles, renewed at least every two years. That requires a role analysis, a review of which roles are actually sensitive.
  • Incident reporting within 24 hours where an incident significantly disrupts or could disrupt the service, with a full report no later than one month after notification.

Here is perhaps the law’s most important mechanism for anyone already working on NIS2 matters. Whoever is identified as a critical entity automatically becomes an essential entity under the Cybersecurity Act. This applies regardless of how the organisation was previously classified.

For an operation classified as important today, an identification decision therefore brings not only new physical-protection requirements but also stricter supervision and higher sanction levels on the cyber side. The two frameworks therefore need to be handled in a single, unified management system, not in two parallel tracks.

Sanctions and a tightened Protective Security Act

The administrative fines follow the same pattern as other modern EU regulation. For private operators the cap is the higher of 2 per cent of global turnover and 10 million euro. For public operators the cap is 10 million kronor.

The same bill also tightens the Protective Security Act. The cap on fines against private actors is raised to the higher of 2 per cent of global turnover and 120 million kronor. That is a marked increase that deserves its own attention in the boardroom of anyone conducting security-sensitive operations.

What you should do now

The law is not yet decided, and the authority structure will be set out in a regulation later. But the direction is fixed, and for energy companies, municipalities with water supply, healthcare providers and other likely candidates there is no reason to wait.

  1. Assess the likelihood that you are identified as a critical entity. Start from your role in the supply chain, not from your size.
  2. Inventory your physical dependencies: facilities, supply of electricity and water, key personnel and suppliers the operation cannot function without.
  3. Carry out a role analysis and review your routines for background checks.
  4. Integrate the physical perspective into existing risk analysis and continuity planning rather than building a separate process.
  5. Review the incident process so it can handle yet another reporting path with a 24-hour deadline.

The through-line is familiar from the rest of our information security work. Compliance can be met on paper while the real capability is weak. From 2027 the legislator defines resilience as something that must be demonstrated in practice. That’s a good yardstick to start measuring yourself against today.

Do you think you could be designated a critical entity? At VER&IT we help you connect the physical protection with your NIS2 work in a single management system, so that resilience holds both on paper and in practice. Get in touch, and we’ll talk through where you stand.

Sources

Author

KB
Kim Borg

Founder & CEO

25+ years of experience in IT leadership, from software developer and Scrum Master to IT Director and Group CIO. Deep expertise in ISO 27001, NIS2, risk management, and information security governance. Educated in ISMS at the University of Skovde.

Ready to strengthen your cybersecurity?

Book a free meeting and we will discuss how we can help your organisation meet the new requirements.

Book a meeting