SĂ€kerhetsskyddslagen (Protective Security Act, SFS 2018:585) is Swedenâs national security law for organizations that run security-sensitive activities or handle security-classified information.
It applies in Sweden across both public and private sectors whose operations are important to Swedenâs security. The goal is to protect against espionage, sabotage, terrorism, and other threats by requiring structured protective security work.
What does SĂ€kerhetsskyddslagen stand for?
âSĂ€kerhetsskyddâ means protective security. The Act sets the ground rules for how operators must identify what needs protection, against which threats, and with what measures, starting from a documented protective security analysis. It is complemented by the Protective Security Ordinance (SFS 2021:955) and guidance from the Swedish Security Service (SĂ€kerhetspolisen) and the Swedish Armed Forces.
What does SĂ€kerhetsskyddslagen require?
At a high level, organisations in scope must:
- Do a protective security analysis (sÀkerhetsskyddsanalys). Document what must be protected, from what, and how. Review it regularly, at least every two years.
- Implement proportional measures in three areas: information security, physical security, and personnel security, based on the analysis.
- Appoint a security protection manager (sÀkerhetsskyddschef) with a clear mandate near top management.
- Vet personnel when needed, including record checks for roles with access to security-sensitive activities or classified information.
- Control suppliers. Use security protection agreements (sÀkerhetsskyddsavtal) in procurements, collaborations, or outsourcing that involve security-sensitive activities.
- Approve information systems before putting them into use in security-sensitive activities.
- Report security-threatening incidents and consult the competent authority before exposing or transferring security-sensitive activities.
Read more:Â What does SĂ€kerhetsskyddslagen require?
How does SĂ€kerhetsskyddslagen provide security?
It forces a systematic, risk-based approach: analyze threats, classify assets and information, and apply targeted controls in tech, people, and physical domains. Mandatory supplier controls and system approvals reduce supply-chain and IT-system risk. Supervision sits with SÀkerhetspolisen and Försvarsmakten, with sector authorities involved, and there are administrative fines for breaches.
What are benefits of SĂ€kerhetsskyddslagen?
Following SĂ€kerhetsskyddslagen helps organizations lower the risk of espionage, sabotage, and insider incidents by requiring that only vetted and trusted personnel can access sensitive areas and information. By enforcing structured personnel checks and clear access control processes, it reduces the chance of malicious insiders or unauthorized individuals gaining entry to critical systems or premises.
The law also strengthens resilience against supply chain threats by making security protection agreements mandatory for suppliers involved in security-sensitive activities. These agreements set clear security obligations for vendors and subcontractors, helping organizations maintain consistent protective measures even when working with external partners. This significantly reduces vulnerabilities introduced through outsourcing or collaborative projects.
Finally, SĂ€kerhetsskyddslagen improves governance and accountability by requiring the appointment of a dedicated security protection manager. This role ensures that protective security work is not a side task but a clearly managed responsibility within the organization. With a defined leader in charge, security measures are more likely to be implemented effectively, regularly reviewed, and kept up to date with evolving threats.

FAQs
Is SĂ€kerhetsskyddslagen mandatory?
Yes, SĂ€kerhetsskyddslagen is mandatory for applicable entities involved in national security in Sweden.
Why is SĂ€kerhetsskyddslagen important?
It is crucial for protecting Swedenâs national security interests. By enforcing strict security measures, it prevents espionage, sabotage, and other threats, ensuring the safety and integrity of critical operations.
Who needs to comply with SĂ€kerhetsskyddslagen?
It applies to public and private entities involved in security-sensitive operations in Sweden.
Read more: Who does SĂ€kerhetsskydslagen apply to?
When is SĂ€kerhetsskyddslagen in effect?
The framework is currently in effect and governs all relevant security operations.
Is SĂ€kerhetsskyddslagen supported in Cyberday?
Yes. Cyberday provides full support for SĂ€kerhetsskyddslagen compliance.