GLOSSARY

Plain-language definitions

The terms that come up most when people are trying to work out if any of this applies to them. No legal drafting, just what each word actually means in practice.

NIS2

The EU's Network and Information Security Directive, second version. Implemented in Sweden as the Cybersecurity Act (Cybersäkerhetslagen), in force since 15 January 2026. Sets minimum cybersecurity requirements for medium and large organisations across 18 sectors.

DORA

The Digital Operational Resilience Act. An EU regulation specific to financial entities — banks, insurers, investment firms, payment providers, and others — covering ICT risk management and resilience. Applicable EU-wide since 17 January 2025.

Essential entity / important entity

NIS2's two tiers of coverage. "Essential" entities (larger, higher-impact sectors like energy and finance-adjacent infrastructure) face stricter supervision than "important" entities, but both carry real obligations.

Cybersäkerhetslagen

The Swedish Cybersecurity Act (SFS 2025:1506), which is how NIS2 became binding law in Sweden. In force since 15 January 2026, with no transition period. It replaced the older NIS Act (2018:1174), and registrations made under that older law did not carry over.

Size-cap exception

The rule that certain entity types are in scope for NIS2 regardless of headcount or turnover, including public administration bodies, providers of public electronic communications, DNS and trust service providers, and sole providers of an essential service. The most common reason a small organisation wrongly concludes it is out of scope.

Supply-chain security

The NIS2 requirement that in-scope organisations assess and manage the security of their direct suppliers. In practice it travels downhill: suppliers who carry no obligations themselves get asked to evidence their security through contract terms and questionnaires.

NCSC (Nationellt cybersäkerhetscenter)

The Swedish authority that has received NIS2 registrations since 1 July 2026, when cyber functions transferred to it at FRA. Before that the duty sat with MCF, and before that with MSB. Guidance published earlier than mid-2026 usually names the wrong body.

OT / ICS

Operational Technology and Industrial Control Systems — the hardware and software that runs physical processes: factory equipment, power grids, water treatment, building management. Different risk profile to standard IT, because failures affect the physical world, not just data.

IT-OT convergence

The trend of previously isolated OT systems being connected to standard IT networks (and often the internet) for monitoring or efficiency reasons — which exposes systems that were never designed to be network-secured.

AI governance

The practice of deciding which AI uses in an organisation need what level of oversight, based on risk — not a single policy document, but an ongoing way of sorting and managing how AI actually gets used.

EU AI Act

The EU regulation governing AI systems, binding across the union. It phases in: prohibited practices and the Article 4 AI literacy duty since February 2025, Article 50 transparency since August 2026, and high-risk obligations from December 2027 after Regulation (EU) 2026/1744 deferred them. Unlike the NIST framework, this one is law.

High-risk AI system

An AI system in one of the AI Act’s named categories, such as recruitment, creditworthiness assessment, access to essential services or critical infrastructure management. Carries the heaviest obligations: risk management, documentation, logging, human oversight and conformity assessment. Applies from 2 December 2027 for standalone systems.

Article 50 transparency

The AI Act duty to tell people when they are interacting with an AI system, and to mark generated or manipulated content. In force since 2 August 2026, and extending to already-deployed systems from 2 December 2026. It was not affected by the deferral of the high-risk rules.

ISO/IEC 42001

A certifiable management system standard for AI, roughly what ISO 27001 is to information security. Voluntary, but increasingly asked about in procurement as a way of evidencing that AI governance exists rather than being asserted.

NIST AI RMF

The US National Institute of Standards and Technology's AI Risk Management Framework — a voluntary, widely-referenced structure for thinking about AI risk. Not a legal requirement in the EU, but a common anchor point for governance work.

Incident reporting (24h / 72h)

Under NIS2, organisations in scope must send an early warning within 24 hours of becoming aware of a significant incident, followed by a fuller notification within 72 hours, and a final report within a month.

Cyber Resilience Act (CRA)

The EU regulation setting cybersecurity requirements for products with digital elements. Its reporting duties apply from 11 September 2026: manufacturers must report actively exploited vulnerabilities and severe incidents within 24 hours, then 72 hours, including for products already on the market. The wider product requirements follow on 11 December 2027, which is a distinction that is widely conflated.

Scope

Whether a given law or regulation actually applies to your organisation. Usually determined by a mix of sector, size (employees, turnover, or balance sheet), and sometimes activity type. Getting this wrong in either direction — assuming you're covered when you're not, or the reverse — is the single most common mistake.
Missing a term you keep running into? Ask and I'll add it.