EU directives · Knowledge hub

CER or NIS2 – which applies to your organization?

Two EU directives impose new requirements on essential services in Sweden. Here are the differences – and what they mean for your checks of staff and suppliers.

The CER and NIS2 directives were adopted by the EU in December 2022 and both target essential services – but they regulate different things. NIS2 is about cybersecurity. CER is about physical and organizational resilience – including requirements for background checks of personnel.

In Sweden, NIS2 is implemented through the Cybersecurity Act, in force since 15 January 2026. CER is implemented through the Act on Resilience of Critical Operators (LOM), proposed to enter into force on 1 January 2027 (govt. bill 2025/26:303).

Many organizations – not least municipalities, energy companies, waterworks and healthcare providers – are covered by both frameworks and need to plan for them together.

Comparison

CER and NIS2 side by side

CER / LOMNIS2 / Cybersecurity Act
FocusPhysical and organizational resilience against disruptions, sabotage and infiltrationCybersecurity: risk management, incident handling and reporting
Swedish lawThe Act on Resilience of Critical Operators (LOM)The Cybersecurity Act
Entry into forceProposed to enter into force on 1 January 2027In force since 15 January 2026, registration duty since 2 February 2026
Sectors11 sectors: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, food and space18 sectors – broader, including waste, postal services, manufacturing and digital providers
How you are designatedThe supervisory authorities identify which organizations are critical operatorsOrganizations assess themselves whether they are covered and register with the supervisory authority
Personnel checksExplicit requirements for background checks of positions assessed, through a documented position analysis, as potentially causing more than minor disruption – may include employees, consultants and suppliers – renewed at least every two yearsPersonnel security is part of the risk management measures, but without explicit background check requirements
SanctionsSanction fees up to the higher of 2 percent of global annual turnover or the equivalent of EUR 10 million (private operators), or SEK 10 million (public operators)Sanction fees up to EUR 10 million or 2 percent of global annual turnover for essential entities
LOM

What would LOM require of critical operators?

  • Risk assessment of the operation and measures to prevent, withstand and manage disruptions.
  • Position analysis: mapping which positions require a background check.
  • Background checks: verified identity, a criminal record extract (no more than six months old) and a complementary assessment – renewed at least every two years.
  • Incident reporting of disruptions to the supervisory authority.
  • Ten months after designation the routines are to be in place under the proposal. The Swedish civil defence agency MCF (Myndigheten för civilt försvar, formerly MSB) coordinates the work in Sweden and sector supervisory authorities exercise supervision.
Overlap

If you are covered by both

  • An organization designated as a critical operator under CER also counts as an essential entity under the NIS2 framework.
  • Risk analysis, governance and incident processes can be coordinated in one program – but CER's background checks and NIS2's cybersecurity measures are separate requirements that must both be met.
  • Start with what takes the longest: the position analysis and the routines for recurring background checks of staff and suppliers.
FAQ

Frequently asked questions about CER and NIS2

NIS2 regulates cybersecurity – protection of networks and information systems, incident reporting and risk management. CER regulates the physical and organizational resilience of critical operators, with explicit requirements for background checks of staff and suppliers.

Get started with the CER checks

The service is designed to support the checking steps described in the Swedish legislative proposal. Final scope must be assessed against enacted law, regulations and the entity’s classification.

Sources