Svenska Dokumentmallar
NIS2 Template Package – Cybersecurity Act 2026 Word/PDF
NIS2 Template Package – Cybersecurity Act 2026 Word/PDF
Downloading the template is available immediately after purchase. Our document templates are always delivered in customizable formats.
If you are unsure which template is appropriate or how you should complete it, please see the relevant information under the 'Legal Information' tab in our main menu.
Our templates are designed in accordance with current legislation and practice in each area to ensure that the documents you create are legally correct.
Couldn't load pickup availability
NIS2 template package for Swedish organizations – Word and PDF
This comprehensive NIS2 template package is designed for companies, organizations, and other operators that need to structure and document their cybersecurity work in accordance with the Swedish Cybersecurity Act (2025:1506) and the Swedish implementation of NIS2.
The package contains 15 integrated document templates, checklists, and decision support documents in a professionally designed and editable Word file, as well as a ready-to-use PDF version. The material is updated for the rules applicable in 2026 and is also structured with consideration for MCFFS 2026:11, which enters into force on October 1, 2026, and specifies requirements and general advice regarding security measures and management training.
You receive both Word (DOCX) and PDF. The Word version is fully editable so that the organization's name, roles, risk levels, systems, suppliers, responsible parties, and decisions can be customized. The PDF version can be used as a reference, for printing, or as documentation for internal reviews.
Included in the NIS2 template package
- Applicability assessment and organizational classification – support for documenting whether the organization is covered by the Cybersecurity Act, sector/subsector, classification, and relevant supervision.
- Cybersecurity and information security policy – goals, principles, responsibilities, management direction, and follow-up.
- Risk management methodology – model for identification, analysis, evaluation, treatment, and acceptance of cybersecurity risks.
- Risk register and action plan – practical table for assets, threats, vulnerabilities, consequences, probability, measures, responsibility, and deadlines.
- Incident management plan – roles, classification, escalation, containment, recovery, root cause analysis, and lessons learned.
- Incident reporting 24/72 hours and final report – ready-made forms for notification, incident report, and final report.
- Continuity and crisis management plan – support for prioritization, RTO, RPO, backup, reserve solutions, crisis activation, and drills.
- Supplier and supply chain security – due diligence, criticality, subcontractors, continuity, and follow-up.
- Security appendix to supplier agreements – contractual clauses regarding incidents, access, logging, vulnerabilities, continuity, audit, subcontractors, and exit.
- Secure development, acquisition, and change management – requirements for procurement, development, configuration, patching, and changes.
- Follow-up, metrics, and internal evaluation – KPI/KRI, target values, trends, responsibilities, and improvement measures.
- Cyber hygiene and training plan – customized for employees, IT administrators, incident teams, and management.
- Encryption, authentication, and secure communication – rules for MFA, encryption, key management, and emergency communication.
- Personnel, access, and asset security – system and information ownership, permissions, and Joiner-Mover-Leaver process.
- Management’s annual cybersecurity review – ready-made documentation for structured management review and decision-making.
Adapted to the 2026 Cybersecurity Act
The Cybersecurity Act entered into force on January 15, 2026. For organizations covered by the act, security work must be based on an all-risk perspective and include appropriate and proportionate technical, operational, and organizational security measures.
The template package is built around the central areas that the act requires affected operators to manage, including risk analysis, incident management, continuity, supply chains, secure system acquisition, follow-up of security measures, cyber hygiene, training, cryptography, access control, and authentication.
Built-in support for incident reporting
In the event of a significant incident, the regulatory framework imposes time-critical obligations. The package therefore contains separate forms and control points for the initial notification, incident report, and final reporting. As a general rule, a significant incident must be reported as soon as possible and no later than within 24 hours, followed by an incident report within the deadline applicable to the organization and subsequently a final report.
The forms are designed to help the organization collect information regarding the sequence of events, discovery, affected systems, impact on sector operations, supplier dependencies, consequences, probable root cause, and taken measures.
Prepared for MCFFS 2026:11 from October 1, 2026
As of October 1, 2026, MCFFS 2026:11 enters into force. The regulation contains more detailed requirements and general advice on security measures and management training for essential and important entities.
The template package therefore includes, among other things, support for:
- systematic and risk-based cybersecurity work,
- goals and direction from management,
- risk acceptance criteria,
- information and system ownership,
- risk registers and documented action plans,
- incident and crisis management,
- continuity and recovery prioritization,
- supplier agreements and digital supply chains,
- access management and multi-factor authentication,
- encryption and secure communication,
- follow-up and evaluation of security measures,
- management training and annual follow-up.
Who is this template for?
The package is suitable for Swedish companies, organizations, and other operators who need to create or improve their documentation regarding NIS2 and the Cybersecurity Act. It can be used by, for example, the CEO, board, management team, CISO, IT manager, information security manager, compliance function, legal counsel, data protection officer, system owners, and operations managers.
The templates are general and can be adapted to different sectors, organizational sizes, and technical environments. The organization fills in responsible roles, systems, classifications, risk levels, deadlines, suppliers, decision paths, and control levels themselves.
Professional and practical design
The document is not merely an information guide. It is built as a practical working material with fillable fields, tables, checklists, decision boxes, and ready-made formulations. The purpose is to reduce the time from regulatory requirements to usable internal documentation.
- 22 professionally designed pages
- 15 integrated templates
- Editable DOCX file
- PDF version
- Risk register and action plan
- Incident forms
- Supplier clauses
- Management review
- Implementation checklist ahead of October 1, 2026
- Legal sources and version information
Important note on legal and technical adaptation
The Cybersecurity Act is risk-based and business-specific. No general document template can alone guarantee that an organization meets all requirements. The documents must be adapted according to the organization's sector, size, system environment, risks, supervisory authority, and any sector-specific or directly applicable EU rules.
For organizations exclusively conducting activities within certain digital sectors, other detailed rules may be directly applicable, including the European Commission's Implementing Regulation (EU) 2024/2690. Therefore, always check the current act, ordinance, regulations, and sector-specific rules before the material is finalized internally.
Format and delivery
Digital product – immediate download. The delivery contains a ZIP file with:
- NIS2_CybersecurityAct_TemplatePackage_2026.docx
- NIS2_CybersecurityAct_TemplatePackage_2026.pdf
No physical product is sent.
Frequently asked questions
Is this a NIS2 policy?
Yes, the package contains a complete policy for cybersecurity and information security, but also risk management, incident reporting, continuity, supplier security, MFA, encryption, training, and management follow-up.
Can I edit the template?
Yes. The Word file is fully editable. The PDF version is included as a ready-made reference and print version.
Is the template updated for 2026?
Yes. Version 1.0 is legally reviewed as of September 27, 2026, based on the Cybersecurity Act (2025:1506), the Cybersecurity Ordinance (2025:1507), MCFFS 2026:1, MCFFS 2026:8, and MCFFS 2026:11, which enters into force on October 1, 2026.
Does the package suit all organizations?
It is constructed as a broad base package but must always be adapted. Sector-specific rules and EU law may impose additional or deviating requirements.
Share



