Sweden NIS2 Telecom Compliance: What PTS Requires From Telia, Tele2, Telenor, and Tre for 5G Security
PTS — not MCF, not NCSC-SE — is the authority that opens a supervision file when a Swedish telecom operator misses an incident report. That distinction matters more in telecom than in almost any other NIS2 sector, because Sweden’s electronic communications providers were already living under a sector-specific security regime years before the Cybersakerhetslag existed. Telia, Tele2, Telenor, and Tre (Hi3G) are not adjusting to a brand-new rulebook — they’re migrating from one regulator’s framework to another’s, while a six-year-old vendor ban quietly previews what NIS2’s supply-chain rules will demand from everyone else.
This guide covers what PTS actually supervises, which Swedish operators fall into which entity tier, why Telia’s Nordic-Baltic footprint creates a jurisdiction problem most single-country guides never mention, and how the 2020 Huawei/ZTE exclusion maps onto Article 21(2)(d) and Article 22 supply-chain obligations.
Does This Apply to Your Organisation?
If you provide a public electronic communications network or a publicly available electronic communications service in Sweden — mobile, fixed broadband, or both — you’re in scope. PTS is explicit that this covers the transition period too: providers fell within NIS2’s reach even before the Cybersakerhetslag (2025:1506) took effect on 15 January 2026 [7].
| Criterion | Essential entity | Important entity |
|---|---|---|
| Size | Large enterprise (250+ staff, or >EUR50M turnover and >EUR43M balance sheet) | Medium enterprise (50-249 staff, or >EUR10M turnover/balance sheet) |
| Sector | Digital infrastructure — public electronic communications networks/services (Annex I) | Same sector, smaller size band |
| Sweden example | Telia Sverige, Tele2, Telenor Sverige, Net4Mobility, Hi3G/Tre | Smaller regional ISPs and MVNOs below the size threshold |
| Regulator | PTS | PTS |
Every large Swedish mobile network operator clears the essential-entity threshold on staff count alone. The size test rarely does the filtering work in this sector — the sector test does. A five-person MVNO reselling capacity on someone else’s network still counts as a provider of a publicly available electronic communications service, though it’s far more likely to land in the important-entity band.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
PTS vs MCF: Sweden’s Telecom-Specific Regulator
MCF (Myndigheten for civilt forsvar) is Sweden’s general NIS2 coordinator — it runs entity registration, is the single point of contact for EU coordination, and picks up residual supervision for sectors nobody else covers. It is not, however, who calls a telecom operator about a missed incident report. PTS holds that role directly, because it already ran sector-specific security supervision over electronic communications providers under the Elektronisk kommunikationslag (2022:482) years before NIS2 existed [6].
That’s the operational reality worth naming plainly: Swedish telecom operators answer to PTS for Cybersakerhetslag compliance the same way they’ve always answered to PTS for network security under LEK. The regulator didn’t change. What changed is the rulebook PTS now enforces — moving from the EECC’s Article 40/41 framework (formally deleted from Directive 2018/1972 on 18 October 2024, per NIS2 Article 43 [2]) to NIS2 Article 21’s ten-domain measure set.
PTS’s own supervisory remit under the Cybersakerhetslag spans five sector groups — digital infrastructure (including electronic communications networks), B2B ICT service management, postal and courier, space, and digital service providers — making it the authority with the widest sector portfolio in Sweden’s three-body structure [6]. For the broader authority map (MCF’s registration role, CERT-SE’s incident intake, NCSC-SE’s strategic layer), see Sweden’s 3-layer NIS2 authority structure.
Telia, Tele2, Telenor, and Tre: Who’s Actually in Scope
Four brands cover nearly the entire Swedish mobile market, but only two physical radio networks carry their traffic — a structural detail that matters for supply-chain risk assessment under Article 21(2)(d).
| Operator | Network | NIS2 relevance |
|---|---|---|
| Telia Sverige | Own nationwide RAN | Essential entity; also Sweden’s largest single point of failure for fixed and mobile services |
| Tele2 + Telenor Sverige | Shared via Net4Mobility JV (50/50), ~99.9% population coverage, carries roughly 60% of Swedish network traffic [8] | Two essential entities relying on one shared physical infrastructure provider for their core network security posture |
| Hi3G / Tre | Own network, expanding 5G build-out | Essential entity; separately assessed under the same PTS vendor restrictions |
The Net4Mobility structure is the detail generic NIS2-for-telecom content skips. Tele2 and Telenor are commercial competitors who jointly own the radio access network both depend on. Under Article 21(2)(d), each of them has to treat Net4Mobility as a direct supplier and assess its risk profile independently — meaning two essential entities are simultaneously the customer and, through their JV stake, part-owner of the same critical supplier. A vulnerability in Net4Mobility’s shared RAN is a shared incident for both operators’ Article 23 reporting obligations, not a contained single-company event.
The Cross-Border Trap: Article 26 Jurisdiction for Nordic-Baltic Operators
Most NIS2 country guides treat jurisdiction as a solved problem: an entity’s main establishment determines which Member State supervises it. That rule — Article 26(1)(a) — applies to DNS providers, cloud services, and CDNs. It does not apply to telecom.
Article 26 carves out a separate rule for providers of public electronic communications networks or publicly available electronic communications services: they fall under the jurisdiction of every Member State in which they provide services, not just the one where they’re headquartered [1]. For a single-country ISP that’s a non-issue. For Telia — headquartered in Solna, Sweden, and operating mobile networks in Finland and the Baltics — it means separate supervisory relationships with separate national regulators in every EU market it serves, each running its own registration process, incident-reporting clock, and audit cycle under its own national transposition of NIS2.
Telia’s footprint has also been moving. It sold its Danish unit to Norlys in April 2024, and confirmed a memorandum of understanding in July 2025 to divest its Latvian holdings (LMT, Tet), expected to close in the first half of 2026 [10]. A compliance team mapping Telia’s Article 26 exposure today has to track which markets the group is still in, not just which markets it has ever operated in — divestment doesn’t just change the balance sheet, it changes which national competent authorities still have a live supervisory file open.
Norway complicates the picture differently. Telia and Telenor both run Norwegian networks, but Norway is an EEA member, not an EU Member State — Article 26 doesn’t bind it directly. Norway is building its own parallel regime, digitalsikkerhetsloven, which entered into force on 1 October 2025 as a NIS1-based baseline ahead of fuller NIS2 alignment once the directive is incorporated into the EEA Agreement [11]. In practice: a Nordic operator’s Norwegian operations currently answer to a national law modeled on NIS2, not to NIS2’s own Article 26 jurisdiction rule — a real distinction, not a technicality, if a Norwegian incident ever needs cross-notifying into an EU Member State’s reporting chain.
5G Supply Chain Security: From PTS’s Huawei Ban to Article 21(2)(d) and Article 22
Sweden’s most consequential 5G security decision predates NIS2’s Swedish transposition by more than five years. In October 2020, PTS barred Huawei and ZTE equipment from the central functions — radio access, transmission, and core — of networks built in the 3.5GHz and 2.3GHz bands, after a security assessment from the Swedish Armed Forces and Sapo (the Security Service). Existing Huawei/ZTE equipment in those functions had to be decommissioned by 1 January 2025. Four bidders were cleared to compete for the spectrum: Hi3G (Tre), Net4Mobility (Tele2/Telenor), Telia Sverige, and Teracom [8].
Read that decision next to Article 21(2)(d) and Article 22, and it stops looking like a one-off national security measure and starts looking like a preview. Article 21(2)(d) requires entities to address cybersecurity risk in their supply chain relationships with direct suppliers, and Article 22 lets the Cooperation Group — working with the Commission and ENISA — run coordinated, EU-wide risk assessments of specific critical ICT supply chains [4]. The European Commission has explicitly positioned its ICT Supply Chain Security Toolbox, which recommends assessing critical suppliers and reducing dependency on high-risk vendors, as feeding directly into that Article 22 mechanism [9].
PTS effectively ran a single-vendor-category version of an Article 22 assessment four years before Article 22 existed. For Telia, Tele2, Telenor, and Tre, that’s not ancient history — it’s the template their own Article 21(2)(d) supplier risk register should already resemble: a documented, security-service-informed classification of which vendors are acceptable for which network function, revisited as new technology (network slicing, Open RAN) creates new supplier categories the 2020 decision never anticipated. The EECC-to-NIS2 gap analysis for the other nine Article 21 domains — cryptography, MFA, asset management, and the rest — is covered in depth in EECC Article 40 vs NIS2 Article 21: the 7 gaps telecom operators must close.
Penalties, Liability, and Your Compliance Checklist
Essential entities — which covers every large Swedish mobile operator — face fines up to EUR10,000,000 or 2% of total worldwide annual turnover, whichever is higher. Important entities face up to EUR7,000,000 or 1.4%, whichever is higher [3]. For a group the size of Telia, the percentage figure, not the flat EUR10M cap, is the number that matters — 2% of worldwide turnover comfortably exceeds EUR10M for an operator with Nordic-Baltic-scale revenue.
- Confirm your entity tier with PTS — large enterprise + Annex I sector = essential, by default, for every named operator above (Effort: Low)
- Map your Article 21(2)(d) supplier register against your existing vendor-security documentation from the LEK/EECC era — don’t rebuild from zero (Effort: Medium)
- Document the Net4Mobility (or equivalent shared-infrastructure) relationship as a direct-supplier risk, not an internal arrangement, if your network is JV-owned (Effort: Medium)
- Verify your incident-reporting chain reaches PTS specifically, not just MCF/CERT-SE’s general intake (Effort: Low)
- Brief the board on personal liability exposure under Article 20 alongside the 2%/EUR10M corporate figure (Effort: Low)
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Frequently Asked Questions
Is PTS or MCF my primary NIS2 contact as a Swedish telecom operator?
PTS. MCF handles general entity registration and EU coordination, but PTS is the sector-specific supervisory authority for electronic communications providers and the one that acts on incident reports and non-compliance in this sector [6].
Does the old EECC security regime still apply alongside NIS2?
No — Articles 40 and 41 of the EECC (Directive (EU) 2018/1972) were deleted with effect from 18 October 2024 [2]. Sweden’s Elektronisk kommunikationslag (LEK) continues to govern non-security telecom matters, but the security obligations now run through NIS2 and the Cybersakerhetslag.
If Telia operates in five EU/EEA countries, does one country’s approval cover the rest?
No. Article 26 puts providers of electronic communications services under the jurisdiction of every Member State where they provide services, not just their home state — Telia maintains separate supervisory relationships in each EU market it serves [1]. Norway sits outside this rule entirely, covered instead by its own national regime.
Does the 2020 Huawei/ZTE ban count as NIS2 compliance?
It’s a precedent, not a substitute. The ban addressed one supplier-risk decision under national security powers; Article 21(2)(d) requires an ongoing, documented supply-chain risk-management process covering all direct suppliers, not a single historical vendor exclusion [4].
Sources
- “Article 26 — Jurisdiction and Territoriality,” NIS2 Directive (EU) 2022/2555
- “Article 43 — Amendment of Directive (EU) 2018/1972,” NIS2 Directive
- “Article 34 — Penalties,” NIS2 Directive
- “Article 22 — Union-Level Coordinated Security Risk Assessments,” NIS2 Directive
- Cybersakerhetslag (2025:1506) — Sveriges riksdag
- Cybersakerhetslagen — Post- och telestyrelsen (PTS)
- “NIS2 paverkar telekomaktorer redan nu” — PTS
- “Fyra sokande far delta i 5G-auktioner” (SVT Nyheter)
- “ICT Supply Chain Security: EU Adopts a Toolbox to Mitigate Risks” — European Commission
- “Telia Company” (Wikipedia)
- “What is Digitalsikkerhetsloven? NIS2 in Norway” (Cyberday)
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
