Swedish cyber incident check

Initial Notice And Incident Notification Within 24 Hours — Annual Balance Sheet Total Eur: €501 · Final report submitted becomes required

The calculated result is “Preliminary Threshold Not Met On Entered Figures · Initial Notice And Incident Notification Within 24 Hours”. Submit the initial incident notice to the CSIRT unit within 24 hours of awareness.

Decision path94EBE35C0BSchema 2026.01.15
Entered facts12
Staff headcount used in the size assessment7
Annual turnover used in the size assessment (€)€1
Annual balance-sheet total used in the size assessment (€)€501
The entity's applicability under the Swedish Cybersecurity Act is confirmedYes
DORA or equivalent sector rules displace these incident-reporting dutiesNo
Significant incident? (severe operational disruption, financial loss, or harm to others)Yes
Incident-notification deadline categoryTrust Service Provider
Initial incident notice submittedNo
Fuller incident notification submittedYes
Incident notification submitted within its 24- or 72-hour deadlineNo
The authority requested an interim reportYes
One month has passed since the incident notificationYes
Action required
Calculated result

Preliminary Threshold Not Met On Entered Figures · Initial Notice And Incident Notification Within 24 Hours

Apply the published Swedish Cybersecurity Act interpretation to scope, size, covered activity, sector-specific displacement, significance, entity category, deadlines, and reporting status. This scenario is distinct because it produces this exact combination of calculated result, active obligations, deadlines, and required evidence.

Published by ProseIDVersion 2026.01.15
Rules activated8
Required

Submit the initial incident notice to the CSIRT unit within 24 hours of awareness

Submit the initial incident notice to the CSIRT unit within 24 hours of awareness.

Cybersäkerhetslag (2025:1506) 2 kap. 5 §
Required

Complete “Incident-notification submission date, time, and zone”

Complete “Incident-notification submission date, time, and zone”.

Cybersäkerhetslag (2025:1506) 2 kap. 6 §; NIS2 Art. 23(4)(b)
Review

The fuller incident notification may be late

The fuller incident notification may be late.

Cybersäkerhetslag (2025:1506) 2 kap. 6 §
Required

Complete “Interim status update”

Complete “Interim status update”.

Cybersäkerhetslag (2025:1506) 2 kap. 7 §
Required

Submit the final report no later than one month after the incident notification

Submit the final report no later than one month after the incident notification.

Cybersäkerhetslag (2025:1506) 2 kap. 8 §
Required

Submit a status report at the one-month point for the ongoing incident

Submit a status report at the one-month point for the ongoing incident.

Cybersäkerhetslag (2025:1506) 2 kap. 8 §
Required

Submit the final report within one month after the incident was handled

Submit the final report within one month after the incident was handled.

Cybersäkerhetslag (2025:1506) 2 kap. 8 §
Required

Complete “One-month status update”

Complete “One-month status update”.

Cybersäkerhetslag (2025:1506) 2 kap. 8 §

Change the facts

A nearby path produces a different result.

Annual turnover used in the size assessment (€)€1 → €60

Annual balance-sheet total used in the size assessment (€)€501 → €100

Significant incident? (severe operational disruption, financial loss, or harm to others)Yes → No

Result becomesPreliminary Threshold Not Met On Entered Figures · No Significant Incident Report On Entered Facts

Inspect the changed path →

Published legal basis

Sources carried by this schema release.

The calculated path is bound to the cited version and sources. It is general information, not a substitute for advice on facts or law outside the schema.

Use your facts

Run the actual workflow.

This page shows one calculated path. Open the maintained workflow to answer with your own facts and, when needed, create a version-bound audit record.