Published: 06-05-2026 16:08 | Updated: 06-05-2026 16:09

The requirements on KI of the new cybersecurity act

The cybersecurity act places greater emphasis on preventive IT and information security measures, systematic work on information security, and formalised requirements for the handling and reporting of IT incidents.

The cybersecurity act(cybersäkerhetslagen), which came into force on 15 January this year, strengthens the requirements for information and IT security in operations that are critical to society. The act introduces stricter requirements for risk management, incident reporting and management’s responsibility for cybersecurity.

To meet the requirements of the cybersecurity act, current compliance will be analysed in 2026 at a selection of departments that are currently being contacted. A notification regarding the applicability of the cybersecurity act to KI has been submitted to the Swedish civil defence and resilience agency (MCF). The act also requires members of management to undergo training in the field of IT and information security.

Read more about cyber security at KI here