NIS2 · DORA · AI Governance
Not sure if NIS2 or DORA applies to you?
You're not alone. NIS2 became Swedish law on 15 January 2026 as Cybersäkerhetslagen, with no transition period, and plenty of organisations still haven't confirmed whether they're in scope. Start with what the rules actually require, in plain language.
The confusion is real, and it's not just you
Scope is broader than it looks
NIS2 pulled thousands more Swedish organisations into scope than the old rules did. Many don't yet know they're one of them.
AI use is outrunning any policy
Most orgs have people using AI tools daily with no framework for what's safe to feed them or rely on.
Your customer's obligations become yours
NIS2 makes organisations responsible for their supply chain. For suppliers who aren't regulated themselves, that arrives as contract terms and security questionnaires.
check
Are you likely in scope?
Is your organisation a bank, insurer, investment firm, or payment provider?
Do you operate in energy, transport, health, digital infrastructure, public administration, or manufacturing of critical products?
Are you a public body, a provider of public electronic communications, DNS or trust services, or the only provider in Sweden of a service others depend on?
Do you have 50+ employees, or turnover / balance sheet over €10M?
This is a starting point, not a legal determination. If you want it mapped properly to your organisation, that's the kind of work I do.
Already dealing with an incident? Work out your reporting deadlines →
services
Where compliance and AI intersect
insights
Start with what's actually changing
Reporting starts 11 September 2026, and most published advice conflates it with the 2027 requirements.
The CRA's first deadline asks for less than you've been told
Article 14 brings in a reporting duty, not a vulnerability handling programme. What actually triggers a report, the 24 and 72-hour clock, who counts as a manufacturer when you rebrand or reconfigure someone else's hardware, and the two things still unsettled in Sweden.
Read the guide →
"Does this even apply to us?" is the question most SMEs get stuck on first.
NIS2 vs DORA: which one applies to you?
NIS2 covers a broad set of "essential" and "important" sectors under Swedish cybersecurity law; DORA is narrower and specific to financial entities. Most organisations only need to check one. This piece walks through the Part A / Part B split in plain language, so you can place yourself before anything else.
Read the guide →
Not every AI use in your org needs the same level of scrutiny.
A simple way to gate AI use by risk
A four-gate way to sort AI uses in your organisation by how much scrutiny they actually need, from "just try it" to "needs sign-off first." Built to be usable by a stretched IT person in an afternoon, not a formal governance programme.
Read the guide →
about
LW
Leighton Wilson. Security+ and Network+ certified, AI Systems Security Specialist. Day-to-day work is compliance, risk and AI governance for organisations trying to work out what Cybersäkerhetslagen and the EU AI Act actually require of them. Builds and maintains open-source security tooling in public, including an OT protocol anomaly detector and a NIS2 vendor-risk and cascading-failure model, both on GitHub, where the working is visible rather than asserted. Earlier career was six years as a time-served electrician before moving into IT and security, which is where the interest in industrial systems started.
security+
network+
ai systems security