24 hours. 72 hours. One month. One system.
NIS2 requires an early warning to CERT-SE/MSB within 24 hours and a full notification within 72. Personal data breaches must be reported to IMY within 72 hours. We keep track of the clock for you.
Every framework you're covered by
OptiTech maps NIS2, DORA, GDPR, ISO 27001, and the EU AI Act in depth, built from Swedish legal texts and MSB regulations. Cross-mapping means one control satisfies requirements in several frameworks at once, so you do the work once and prove it everywhere.
10,000+
Swedish companies are covered by NIS2
5 frameworks
in depth, built from Swedish legal texts
From yearly project to real time
OptiTech takes you from point-in-time consultant reports to automated, continuous control monitoring. Evidence is collected around the clock from your systems, and your live status is always ready to show: to the board, to auditors, and to customers on your Trust Center.
Book a demoAlerts you can act on
Controls are verified hourly through integrations with Microsoft 365, Entra ID, AWS, Fortnox, and BankID. When something drifts, you get a concrete action: fix it directly via API, or send a ready-made ticket to the right person, with instructions written by AI.
Hourly
your controls are verified automatically
1 click
from alert to remediation via API
Everything in one platform
From the first gap analysis to a completed audit: a built-in roadmap guides every step. Policies, risk register, training, vendor assessments, and MSB and IMY reporting flows are included, with partners for penetration tests and audits when you need them.
Book a demoThree authorities, three mandates
MSB / CERT-SE
NIS2 / the Swedish Cybersecurity Act
National contact point and CSIRT function for NIS2.
PTS, Ei, and others
NIS2, sector supervision
Sector supervision for NIS2, assigned by industry.
IMY
GDPR, Article 33
Supervisory authority for personal data breaches under the GDPR.
How the statutory steps work
- 0–24hDraft
Early warning to CERT-SE/MSB
The system proposes classification and recipient automatically.
- 24–72hSubmitted
Full incident notification
Assessed severity and pre-filled fields, built from the incident record.
- Within 1 monthAcknowledged
Final report
Root-cause analysis and an action plan, compiled from the case log.
- 72hIn parallel
Personal data? Notify IMY
When the incident involves personal data with risk to individuals, a parallel IMY track starts: notification within 72 hours of discovery.
The facts, in numbers
10 M€ / 2%
Maximum sanction for essential entities under NIS2, Article 34.
7 M€ / 1.4%
Maximum sanction for important entities.
24 / 72 / 30
Hours, hours, days: the three statutory NIS2 windows.
Article 20
Management's duty to approve and oversee risk-management measures.
When the clock is already running
An incident is detected outside office hours. Who starts the clock, and when?
The clock starts at awareness, not at the next working day. The system alerts the on-call contact, opens a timestamped case, and counts down toward the 24-hour window.
Escalation path
“We cut the time from discovery to first notification from 14 hours to 25 minutes.”
One obligation, three frameworks
NIS2
24h / 72h / 1 mo
CERT-SE/MSB and your sector authority
GDPR / IMY
72h
IMY, when individuals' rights are at risk
DORA
4h / 72h / 30 days
National competent authority, financial sector
Your questions, answered
- The duty follows from entity type, essential or important under the Swedish Cybersecurity Act, not from company size in general. The scoping in the platform shows which category you belong to and which windows apply to you.
- No. Only breaches that pose a risk to data subjects' rights and freedoms must be reported, within 72 hours of discovery. The decision not to report must be documented too, and the system does that automatically.
- A first message to CERT-SE/MSB that a significant incident is under way, not a complete investigation. Among other things, it states whether the incident is suspected to be caused by unlawful acts and whether it may have cross-border effects.
- MSB, with CERT-SE as the CSIRT function. Supervision is distributed by sector to authorities such as PTS and the Swedish Energy Markets Inspectorate, depending on your industry.