Framework

NIS2, built from the Swedish legal text

Supervision and sanctions are being enforced now. OptiTech builds NIS2 from the Cybersecurity Act and MSBFS, not a generic mapping, with scoping, controls, and the full MSB incident flow included.

  • 10 M€ / 2%

    Maximum sanction under NIS2

  • 24h

    Early warning to CERT-SE / MSB

  • 10,000+

    Swedish companies now in scope

NIS2 reaches further than most think

  • 10,000+ companies in scope

    Eighteen sectors plus their suppliers. Many are pulled in as subcontractors without realizing it.

  • Personal liability

    Management and the board carry personal responsibility, with sanctions up to 10 M€ or 2% of turnover.

  • Generic tools fall short

    Foreign platforms map NIS2 loosely. They do not follow the Swedish legal text or the MSB reporting process.

How OptiTech gets you compliant

  1. 01

    Scope and categorize

    A gap analysis determines whether you are in scope and whether you are an essential or important entity.

  2. 02

    Implement and collect evidence

    Controls from the legal text, with continuous evidence from your systems and Swedish policy templates.

  3. 03

    Report incidents to MSB

    A guided flow for the 24-hour early warning, 72-hour notification, and one-month final report.

What OptiTech gives you for NIS2

  • Built from MSBFS

    Controls derived from the Swedish legal text and MSB regulations.

  • Scoping wizard

    Essential or important, decided from your real profile.

  • MSB incident flow

    The 24h, 72h, and one-month reporting windows, guided.

  • Board training

    The management training NIS2 specifically requires.

NIS2 support that is a mapping of a foreign standard is not NIS2 support. It has to start from the Swedish legal text.
OptiTech, Product principle

Questions

  • Run the free gap analysis. It determines whether you are in scope and, if so, whether you are essential or important.
  • Yes. The flow follows the 24-hour, 72-hour, and one-month windows and prefills the authority forms from your incident data.
  • Often, yes. Many companies are pulled into scope through the supply chain as subcontractors to regulated sectors.
  • Management and the board carry personal responsibility, which is why board training is part of the framework.
Framework

Find out if NIS2 applies to you

A free gap analysis tells you your scope and category.

Book a free gap analysis