Swedish cyber incident check

Use The Applicable Sector Specific Reporting Regime — Final report submitted becomes required · The final report is due no later than one month…

The calculated result is “Preliminary Medium Or Larger Threshold Met · Use The Applicable Sector Specific Reporting Regime”. These Cybersecurity Act incident duties are displaced for the entered entity; route the incident under the applicable sector-specific regime.

Decision path841F8BF858Schema 2026.01.15
Entered facts12
Staff headcount used in the size assessment9,999,999
Annual turnover used in the size assessment (€)€1,000
Annual balance-sheet total used in the size assessment (€)€2
The entity's applicability under the Swedish Cybersecurity Act is confirmedYes
DORA or equivalent sector rules displace these incident-reporting dutiesYes
Significant incident? (severe operational disruption, financial loss, or harm to others)Yes
Incident-notification deadline categoryStandard Operator
Fuller incident notification submittedYes
One month has passed since the incident notificationYes
Incident still ongoing one month after the incident notificationNo
One-month status report submitted for an ongoing incidentNo
Final report submittedNo
Action required
Calculated result

Preliminary Medium Or Larger Threshold Met · Use The Applicable Sector Specific Reporting Regime

Apply the published Swedish Cybersecurity Act interpretation to scope, size, covered activity, sector-specific displacement, significance, entity category, deadlines, and reporting status. This scenario is distinct because it produces this exact combination of calculated result, active obligations, deadlines, and required evidence.

Published by ProseIDVersion 2026.01.15
Rules activated3
Required

These Cybersecurity Act incident duties are displaced for the entered entity;…

These Cybersecurity Act incident duties are displaced for the entered entity; route the incident under the applicable sector-specific regime.

Cybersäkerhetslag (2025:1506) 1 kap. 10–11 §§
Required

Submit the final report no later than one month after the incident notification

Submit the final report no later than one month after the incident notification.

Cybersäkerhetslag (2025:1506) 2 kap. 8 §
Required

Submit the final report within one month after the incident was handled

Submit the final report within one month after the incident was handled.

Cybersäkerhetslag (2025:1506) 2 kap. 8 §

Change the facts

A nearby path produces a different result.

Staff headcount used in the size assessment9,999,999 → 7

Annual turnover used in the size assessment (€)€1,000 → €30

Annual balance-sheet total used in the size assessment (€)€2 → €50

Result becomesPreliminary Threshold Not Met On Entered Figures · Use The Applicable Sector Specific Reporting Regime

Inspect the changed path →

Published legal basis

Sources carried by this schema release.

The calculated path is bound to the cited version and sources. It is general information, not a substitute for advice on facts or law outside the schema.

Use your facts

Run the actual workflow.

This page shows one calculated path. Open the maintained workflow to answer with your own facts and, when needed, create a version-bound audit record.