Swedish cyber incident check

Initial Notice And Incident Notification Within 24 Hours — The ordinary scope route requires both a covered… · Establish the covered activity and Swedish nexus…

The calculated result is “Preliminary Medium Or Larger Threshold Met · Initial Notice And Incident Notification Within 24 Hours”. Establish the covered activity and Swedish nexus before using the ordinary scope route.

Decision path28DE45BC59Schema 2026.01.15
Entered facts12
Staff headcount used in the size assessment9,999,999
Annual turnover used in the size assessment (€)€9,999,999
Annual balance-sheet total used in the size assessment (€)€60
The entity's applicability under the Swedish Cybersecurity Act is confirmedYes
DORA or equivalent sector rules displace these incident-reporting dutiesNo
Significant incident? (severe operational disruption, financial loss, or harm to others)Yes
Incident-notification deadline categoryTrust Service Provider
Size-independent or special scope basisNone
A covered activity and the required Swedish nexus have been establishedNo
Initial incident notice submittedNo
Fuller incident notification submittedNo
Final report submittedYes
Action required
Calculated result

Preliminary Medium Or Larger Threshold Met · Initial Notice And Incident Notification Within 24 Hours

Apply the published Swedish Cybersecurity Act interpretation to scope, size, covered activity, sector-specific displacement, significance, entity category, deadlines, and reporting status. This scenario is distinct because it produces this exact combination of calculated result, active obligations, deadlines, and required evidence.

Published by ProseIDVersion 2026.01.15
Rules activated6
Required

Establish the covered activity and Swedish nexus before using the ordinary scope…

Establish the covered activity and Swedish nexus before using the ordinary scope route.

Cybersäkerhetslag (2025:1506) 1 kap. 4 § 1–2
Required

Make the confirmed scope basis and incident-notification deadline category…

Make the confirmed scope basis and incident-notification deadline category consistent.

Cybersäkerhetslag (2025:1506) 1 kap. 5 § 4 and 2 kap. 6 §
Required

Submit the initial incident notice to the CSIRT unit within 24 hours of awareness

Submit the initial incident notice to the CSIRT unit within 24 hours of awareness.

Cybersäkerhetslag (2025:1506) 2 kap. 5 §
Required

Submit the trust-service incident notification within 24 hours of awareness

Submit the trust-service incident notification within 24 hours of awareness.

Cybersäkerhetslag (2025:1506) 2 kap. 6 §
Required

Submit the incident notification within 72 hours of awareness

Submit the incident notification within 72 hours of awareness.

Cybersäkerhetslag (2025:1506) 2 kap. 6 §
Required

Complete “Detailed final incident description, severity, and impact”

Complete “Detailed final incident description, severity, and impact”.

Cybersäkerhetslag (2025:1506) 2 kap. 8 §; NIS2 Art. 23(4)(d)

Change the facts

A nearby path produces a different result.

Annual balance-sheet total used in the size assessment (€)€60 → €1

Significant incident? (severe operational disruption, financial loss, or harm to others)Yes → No

Size-independent or special scope basisNone → Other Formally Confirmed Basis

Result becomesPreliminary Medium Or Larger Threshold Met · No Significant Incident Report On Entered Facts

Inspect the changed path →

Published legal basis

Sources carried by this schema release.

The calculated path is bound to the cited version and sources. It is general information, not a substitute for advice on facts or law outside the schema.

Use your facts

Run the actual workflow.

This page shows one calculated path. Open the maintained workflow to answer with your own facts and, when needed, create a version-bound audit record.