The CER and NIS2 directives were adopted by the EU in December 2022 and both target essential services – but they regulate different things. NIS2 is about cybersecurity. CER is about physical and organizational resilience – including requirements for background checks of personnel.
In Sweden, NIS2 is implemented through the Cybersecurity Act, in force since 15 January 2026. CER is implemented through the Act on Resilience of Critical Operators (LOM), proposed to enter into force on 1 January 2027 (govt. bill 2025/26:303).
Many organizations – not least municipalities, energy companies, waterworks and healthcare providers – are covered by both frameworks and need to plan for them together.
CER and NIS2 side by side
| CER / LOM | NIS2 / Cybersecurity Act | |
|---|---|---|
| Focus | Physical and organizational resilience against disruptions, sabotage and infiltration | Cybersecurity: risk management, incident handling and reporting |
| Swedish law | The Act on Resilience of Critical Operators (LOM) | The Cybersecurity Act |
| Entry into force | Proposed to enter into force on 1 January 2027 | In force since 15 January 2026, registration duty since 2 February 2026 |
| Sectors | 11 sectors: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, food and space | 18 sectors – broader, including waste, postal services, manufacturing and digital providers |
| How you are designated | The supervisory authorities identify which organizations are critical operators | Organizations assess themselves whether they are covered and register with the supervisory authority |
| Personnel checks | Explicit requirements for background checks of positions assessed, through a documented position analysis, as potentially causing more than minor disruption – may include employees, consultants and suppliers – renewed at least every two years | Personnel security is part of the risk management measures, but without explicit background check requirements |
| Sanctions | Sanction fees up to the higher of 2 percent of global annual turnover or the equivalent of EUR 10 million (private operators), or SEK 10 million (public operators) | Sanction fees up to EUR 10 million or 2 percent of global annual turnover for essential entities |
What would LOM require of critical operators?
- Risk assessment of the operation and measures to prevent, withstand and manage disruptions.
- Position analysis: mapping which positions require a background check.
- Background checks: verified identity, a criminal record extract (no more than six months old) and a complementary assessment – renewed at least every two years.
- Incident reporting of disruptions to the supervisory authority.
- Ten months after designation the routines are to be in place under the proposal. The Swedish civil defence agency MCF (Myndigheten för civilt försvar, formerly MSB) coordinates the work in Sweden and sector supervisory authorities exercise supervision.
If you are covered by both
- An organization designated as a critical operator under CER also counts as an essential entity under the NIS2 framework.
- Risk analysis, governance and incident processes can be coordinated in one program – but CER's background checks and NIS2's cybersecurity measures are separate requirements that must both be met.
- Start with what takes the longest: the position analysis and the routines for recurring background checks of staff and suppliers.
Frequently asked questions about CER and NIS2
NIS2 regulates cybersecurity – protection of networks and information systems, incident reporting and risk management. CER regulates the physical and organizational resilience of critical operators, with explicit requirements for background checks of staff and suppliers.
The Act on Resilience of Critical Operators – the Swedish law implementing the CER Directive. The government submitted the bill (2025/26:303) to the Riksdag in July 2026 and the act is proposed to enter into force on 1 January 2027.
If you deliver essential services in any of the eleven sectors – for example energy, drinking water, transport, healthcare or public administration – your supervisory authority can designate you as a critical operator. Municipalities and municipal companies can also be covered.
Not explicitly. Personnel security is part of NIS2's risk management measures, but it is the CER Directive and LOM that impose explicit background check requirements with identity verification and criminal record extracts.
Yes. Under CER, everyone with physical or digital access to the critical operation must be checked – including consultants and supplier staff. NIS2 in turn requires supply chain security.
The Cybersecurity Act already applies, with a registration duty since 2 February 2026. LOM is proposed to enter into force on 1 January 2027, and ten months after an organization is designated as critical, the routines – including background checks – must be in place. Position analysis and check routines take time to establish, so start now.
Get started with the CER checks
The service is designed to support the checking steps described in the Swedish legislative proposal. Final scope must be assessed against enacted law, regulations and the entity’s classification.