Swedish cyber incident check

Initial Notice Within 24 Hours And Incident Notification Within 72 Hours — Affected service recipients informed without undue… · When appropriate, recipients must be…

The calculated result is “Preliminary Medium Or Larger Threshold Met · Initial Notice Within 24 Hours And Incident Notification Within 72 Hours”. Complete “Initial-notice submission date, time, and zone”.

Decision path088F5F9B97Schema 2026.01.15
Entered facts12
Staff headcount used in the size assessment90
Annual turnover used in the size assessment (€)€7
Annual balance-sheet total used in the size assessment (€)€15
The entity's applicability under the Swedish Cybersecurity Act is confirmedYes
DORA or equivalent sector rules displace these incident-reporting dutiesNo
Significant incident? (severe operational disruption, financial loss, or harm to others)Yes
Incident-notification deadline categoryStandard Operator
Initial incident notice submittedYes
Initial notice submitted within 24 hours of awarenessNo
Fuller incident notification submittedYes
It is appropriate to inform affected service recipientsYes
Affected service recipients informed without undue delayNo
Action required
Calculated result

Preliminary Medium Or Larger Threshold Met · Initial Notice Within 24 Hours And Incident Notification Within 72 Hours

Apply the published Swedish Cybersecurity Act interpretation to scope, size, covered activity, sector-specific displacement, significance, entity category, deadlines, and reporting status. This scenario is distinct because it produces this exact combination of calculated result, active obligations, deadlines, and required evidence.

Published by ProseIDVersion 2026.01.15
Rules activated4
Required

Complete “Initial-notice submission date, time, and zone”

Complete “Initial-notice submission date, time, and zone”.

Cybersäkerhetslag (2025:1506) 2 kap. 5 §; NIS2 Art. 23(4)(a)
Review

The initial notice may be late

The initial notice may be late.

Cybersäkerhetslag (2025:1506) 2 kap. 5 §
Required

Complete “Incident-notification submission date, time, and zone”

Complete “Incident-notification submission date, time, and zone”.

Cybersäkerhetslag (2025:1506) 2 kap. 6 §; NIS2 Art. 23(4)(b)
Required

Inform affected service recipients without undue delay

Inform affected service recipients without undue delay.

Cybersäkerhetslag (2025:1506) 2 kap. 9 §

Change the facts

A nearby path produces a different result.

Annual turnover used in the size assessment (€)€7 → €10,000,001

Annual balance-sheet total used in the size assessment (€)€15 → €501

The entity's applicability under the Swedish Cybersecurity Act is confirmedYes → No

Result becomesPreliminary Medium Or Larger Threshold Met · Complete And Confirm Applicability First

Inspect the changed path →

Published legal basis

Sources carried by this schema release.

The calculated path is bound to the cited version and sources. It is general information, not a substitute for advice on facts or law outside the schema.

Use your facts

Run the actual workflow.

This page shows one calculated path. Open the maintained workflow to answer with your own facts and, when needed, create a version-bound audit record.