Defence Contracts 2026

Last Updated September 23, 2026

Sweden

Law and Practice

Authors



Advokatfirman Cederquist is a full-service Swedish business law firm with approximately 120 lawyers in a single Stockholm office. Its five-lawyer co-ordination defence and security team combines public procurement, protective security, export controls, sanctions, FDI screening, competition law, corporate/M&A, cybersecurity, IP and technology expertise, drawing on specialists across the firm for complex cross-border mandates. The team advises defence contractors, technology companies, infrastructure investors and suppliers to public authorities throughout the life cycle of security-sensitive projects: market entry, tenders, licensing and regulatory clearances, transactions, contracting, supply-chain resilience, disputes and investigations. Recent relevant work includes advising Samsung Electronics’ networks division on Swedish procurement matters, Kåpan Fastigheter on the expansion and procurement of public properties needed for defence and security, Triton Partners in creating the Nordic technical-security group Varna, and Prima Materia on its investment in defence AI company Helsing. Cederquist co-ordinates international matters through a network of leading independent law firms.

The principal legislation and regulatory framework comprise:

  • constitutional rules;
  • legislation on total defence and heightened state of alert;
  • organisational and operational rules for the Swedish Armed Forces;
  • civil-defence and security-of-supply legislation; and
  • protective-security legislation.

The principal legislation and regulatory framework include the following regarding civil defence and emergency preparedness:

  • Act (1992:1403) on Total Defence and Heightened State of Alert;
  • Ordinance (2015:1053) on Total Defence and Heightened State of Alert;
  • Act (1982:1004) on the Obligation for Business Operators, Labour Market Organisations, etc to Participate in Total Defence Planning;
  • Ordinance (1982:1005) on the Obligation for Business Operators, Labour Market Organisations, etc to Participate in Total Defence Planning;
  • Ordinance (2022:524) on the Preparedness of Central Government Agencies;
  • Act (1976:295) on the Obligation for Business Operators to Participate in Stockpiling for Security of Supply;
  • Act (2006:544) on Municipal and Regional Measures prior to and during Extraordinary Events in Peacetime and in Times of Heightened State of Alert;
  • Ordinance (2006:637) on Municipal and Regional Measures prior to and during Extraordinary Events in Peacetime and in Times of Heightened State of Alert; and
  • the Disposal Act (1978:262).

The responsibility for overseeing and enforcing defence-related regulation in Sweden is divided among several ministries, government agencies and regulatory bodies, principally as follows.

Defence and Procurement

  • The Ministry of Defence – responsible for total defence, crisis preparedness, NATO contributions and international defence co-operation and operations.
  • The Swedish Armed Forces – its primary task is to defend Sweden and its interests, conduct operations and support civilian authorities and total-defence objectives.
  • The Swedish Defence Materiel Administration – procures and supplies defence materiel, supporting Sweden’s Armed Forces and NATO commitments.
  • The Ministry of Finance is responsible for procurement policy.
  • The National Agency for Public Procurement provides guidance, while the Swedish Competition Authority supervises procurement law. Procurement challenges are heard by the administrative courts.

Export Controls and Foreign Investment

  • The Ministry for Foreign Affairs – responsible for Sweden’s foreign development co-operation and trade policy.
  • The Inspectorate of Strategic Products (ISP) – oversees defence materiel, dual-use products and targeted sanctions, and is the Swedish screening authority for foreign direct investments.

National and Protective Security

  • The Ministry of Justice – responsible for the judicial system, migration and legislation concerning public administration, civil and criminal law, public order and security.
  • The Swedish Security Service – prevents threats to national security, combats terrorism and protects the central government. Protective security matters are also handled by various sector-specific authorities while the Swedish Security Service maintain a co-ordination role.

In Sweden, the meaning of “defence” goods, services and technology depends on the applicable regulatory context. “Military equipment” is defined in the annex to the Military Equipment Ordinance.

In relation to “dual-use” items, Sweden relies on the application and distinction provided in the EU Dual-Use Regulation (2021/821) and has national legislation that complements the EU Regulation. As such, “dual-use” items are goods, software and technology capable of both civilian and military applications, including items connected with the development of nuclear, chemical or biological weapons.

The distinction is therefore primarily based on design and technical characteristics; purely military items are specifically designed or adapted for military purposes, whereas dual-use items also have civilian applications.

The Swedish defence regulation is strongly shaped by international obligations and EU law. Sweden follows a dualist approach, whereby treaties generally require incorporation or implementation through domestic legislation before they apply internally, while EU Regulations are directly applicable (as regulated by EU law). The principal international frameworks and treaty obligations reflected in the Swedish defence regulation are, for example:

  • NATO obligations;
  • EU Defence Directives;
  • the Arms Trade Treaty;
  • the Wassenaar Arrangement; and
  • UN Security Council resolutions.

Sweden also implements non-proliferation treaties such as the Chemical Weapons Convention, for which ISP acts as the national authority. Overall, international commitments strongly shape Swedish licensing criteria, control lists, procurement legislation, sanctions and security requirements, but enforcement remains primarily the responsibility of Swedish authorities.

The Defence and Security Procurement Act (2011:1029) (LUFS), regulates procurements in the defence and security sector of military or sensitive equipment, related works and services, and works or services for military purposes or of a sensitive nature. LUFS is based on and implements Directive 2009/81/EC.

There are certain exceptions to the applicability of LUFS – eg, for procurements of arms, ammunition and war material covered by Article 296(1)(b) of the Treaty on the Functioning of the European Union (TFEU), and for contracts for which the application of LUFS would require disclosure of information contrary to Sweden’s essential security interests or contracts for the purposes of intelligence activities.

The applicability of LUFS is not limited to central government or Ministry of Defence bodies. It applies to all contracting authorities and contracting entities for their procurements in the defence and security sector.

Entities within the scope of the legislation include:

  • central government and municipal authorities;
  • municipal and regional decision-making assemblies;
  • bodies governed by public law; and
  • undertakings over which a contracting authority exercises controlling influence and undertakings operating in those sectors under a statutory special or exclusive right.

LUFS applies to procurements of contracts concerning:

  • (i) military equipment, including parts, components and subassemblies thereof;
  • (ii) sensitive equipment, including parts, components and subassemblies thereof;
  • (iii) works, supplies and services directly related to the equipment referred to in (i) and (ii) for any element of its life cycle; and
  • (iv) works and services specifically intended for military purposes, and sensitive works or services.

The EU procurement directives apply above certain thresholds. LUFS applies both above and below the applicable EU thresholds, as Sweden has adopted national rules below the threshold value, included in Chapter 15 and 15a of LUFS.

From 1 January 2026, the thresholds are SEK4,903,632 for supplies and services and SEK61,340,804 for works contracts. The direct award threshold is SEK1.2 million.

LUFS does not specifically set out any separate classified procurement procedures but contains specific provisions relating to information security for procurement involving security-classified information.

Contracting authorities and entities shall specify in the procurement documents the measures and requirements necessary to protect such information. Tenderers may be required to demonstrate that they can comply with those requirements.

The authority or entity may also require undertakings to protect security classified information disclosed during the procurement, during the performance of the contract and after the contract has been completed or terminated.

Sweden’s security protection legislation also applies to procurements in this field, and imposes additional requirements concerning security vetting, access to sensitive information activities and, where applicable, security protection agreements.

For procurements above the EU threshold, the restricted procedure, the negotiated procedure with prior publication and the competitive dialogue are the main procedures. In certain circumstances, the negotiated procedure without prior publication can be applied.

For procurements below the EU threshold, subject to requirements for publication, as regulated in Chapter 15a, LUFS, there are no regulated procurement procedures which enable the contracting authority or entity to design the procurement process more freely as long as the procedure complies with the fundamental procurement principles of, for example, transparency, equal treatment and proportionality. The procurement documents must clearly set out how the procedure will be conducted.

Direct awards are regulated in a separate chapter – Chapter 15a, LUFS.

For procurements above the EU threshold, LUFS permits direct or single-source awards in specified circumstances, through the negotiated procedure without prior publication. This includes situations where the contract can only be awarded to a specific supplier due to technical reasons or exclusive rights, in situations of extreme urgency, or where there is urgency due to crisis situations.

Note also that certain contracts can be exempted from the applicability of LUFS.

For procurements below the EU threshold, Chapter 15a, LUFS regulates direct awards. Direct awards may be used where the estimated value of the procurement is below SEK1.2 million, in certain situations where the estimated value is below the EU threshold or if there are exceptional reasons.

There are no specific requirements regulating offset obligations, industrial participation requirements or sovereign capability conditions in procurement legislation. However, the protective security regime may require protective security agreements, security vetting of personnel, controls on subcontractors, etc. Such requirements may in practice restrict where security and defence contracts are performed and by whom.

In exceptional cases, procurements relating to production of or trade in arms, ammunitions and war materials subject to Article 346(1)(b), TFEU may in a specific instance be exempted from the applicability of LUFS where this is necessary to protect Sweden’s essential security interests.

There is an example in Swedish case law of procurements in the classic sector where a requirement that the supplier could not have certain ownership relating to countries that are identified as a threat to Sweden was upheld, even though it excluded a Swedish entity. The reason was that the requirement had strong protective security justification.

LUFS requires that contracting authorities and entities specify the requirements for security of supply in the procurement documents. Tenderers may be required to demonstrate in their tenders that they meet requirements for security of supply – eg, by providing export licences, information on the organisation and location of the supply chain, undertaking to maintain certain capacity as required to meet an increased demand during a crisis, etc.

A tender that fails to satisfy the stated requirements may be rejected.

A supplier who has failed to comply with information-security or security-of-supply requirements in previous contracts may also be excluded from participation in a later procurement on these grounds.

The contracting authority or entity shall award the contract either to the tender that is the most economically advantageous to the contracting authority or entity, or to the tender containing the lowest price.

In determining the most economically advantageous tender, the contracting authority or entity shall consider various criteria linked to the subject matter of the contract, such as price, delivery or performance time, quality, security of supply, interoperability and operational characteristics.

A contracting authority or entity shall specify, in the contract notice or the procurement documents, the basis for contract award that will be applied.

LUFS contains both mandatory and discretionary grounds for excluding suppliers based on Directive 2009/81/EC.

A tenderer shall be excluded from participation in a procurement where the supplier, or its representatives, have been convicted by a final judgment of an offence involving participation in a criminal organisation, corruption, fraud, money laundering and terrorist financing, or terrorist offences. A contracting authority or entity may however, in the case of exceptional reasons, decide not to exclude a tenderer subject to a mandatory exclusion ground.

A tenderer may also be excluded from participation in a procurement for insolvency-related reasons, reasons related to professional misconduct, failure to pay taxes or social-security contributions, or where the tenderer has been found not to possess the reliability necessary to exclude risks to the security of Sweden.

Applicable EU sanctions may also prohibit the award or performance of a contract involving a sanctioned person or entity.

Under LUFS, procurement documents are generally subject to prior publication and transparency requirements, although the legislation also allows contracting authorities and entities to require that tenderers protect security classified information disclosed during the procurement, during the performance of the contract and after the contract has been completed or terminated.

The Swedish Protective Security Act may require that a protective security agreement be signed before access is granted to security-classed information.

The Swedish Public Access to Information and Secrecy Act may also provide grounds for keeping information confidential during and after a procurement procedure.

LUFS does not contain any provisions specifically allowing for modifications of public contracts. However, it follows from Court of Justice of the European Union (CJEU) case law that modifications may be made under certain circumstances.

A supplier that has suffered, or risks suffering, harm from an alleged breach of LUFS may apply for review before the general administrative court in whose jurisdiction the contracting authority or entity is established.

The court may order the procurement to be corrected or recommenced, and may grant interim relief. Following contract conclusion, it may declare the contract ineffective in specified circumstances, including an unlawful negotiated procedure without prior publication.

The principal legislation governing military equipment is the Military Equipment Act and the Military Equipment Ordinance. Dual-use items are governed by the EU Dual-Use Regulation and complementary Swedish legislation. ISP is the authority responsible for export control and military equipment matters.

The Military Equipment Ordinance has an annex listing military equipment within the scope of the regulation. The Annex is continuously updated to ensure adherence to international obligations, and it requires a decision from the government to be updated. Dual-use items are identified by reference to Annex I to the EU Dual-Use Regulation.

In relation to export and transport authorisation, there are three types of licences:

  • individual authorisation, a licence for a particular transaction;
  • global authorisation, a licence for multiple transactions valid for three years; and
  • general authorisation, a licence for certain intra-EEA transfers that does not require an individual application but prior notification.

An application for a licence is made to ISP, and it is advisable to notify the authority early to ensure a smooth process. ISP may also provide an advance ruling. The application should contain information about the contract (including basic information about parties and products) and appropriate end-user documentation.

Under the Military Equipment Act, a licence may only be approved if there are security or defence policy reasons for the export, and the export does not conflict with Sweden’s foreign policy or international obligations. In addition, there is a list of absolute obstacles to a licence such as conflicts with international obligations.

Considerations for granting or refusing licences for dual-use items include international obligations and sanctions, national foreign and security policy, the intended end use and the risk of diversion or unauthorised re-exportation.

For permanent exports or transfers of military equipment to recipients abroad, ISP requires original end-user documentation. For dual-use items, appropriate end-user documentation may be required depending on the authorisation and transaction.

ISP may conduct post-shipment verification in selected cases to confirm that exported military equipment has reached and remains with the authorised end user.

Brokering of military equipment falls within the concept of supply, which includes, among other things, sale, lease, loan, donation and brokering. Conducting such activities professionally requires authorisation from ISP.

In addition to the general rules under the EU Dual-Use Regulation, requiring a licence for Annex I items that may be intended for a weapons-of-mass-destruction end use, Sweden has extended this to also include brokering for non-Annex I dual-use items if the authority has informed the broker that the items may be intended for such use. The broker also has an obligation to notify the authority if there is reason to suspect such end use.

There are no general exemptions in relation to intra-company or intra-group transfers of controlled items or technology. The important aspect is whether there is a cross-border transfer of the items or technology.

Penalties for breach of export control legislation can be of both a criminal and civil nature. There are criminal penalties for exporting without a licence, as well as possible administrative fines for administrative breaches. ISP imposes the administrative fines, whereas criminal charges are brought by the prosecutors’ office.

Voluntary disclosure to ISP in relation to military equipment is possible if a company identifies a possible breach. Such voluntary disclosure is considered a mitigating factor when ISP determines the administrative fine.

The international sanctions applicable in Sweden are those adopted by the EU or the UN.

Breaches of applicable sanctions are primarily regulated in the Swedish Act on International Sanctions (2025:327). The Act implements Directive (EU) 2024/1226 by establishing criminal liability for breaches and circumvention of international sanctions. In the assessment of whether an offence is aggravated, whether the action related to military or dual-use items is expressly relevant.

Sanctions for legal entities are covered by the provisions of the Swedish Criminal Code and its provisions on corporate fines. Several authorities are responsible for different tasks in relation to international sanctions, depending on the applicable sanction’s regulation and provisions therein.

The Security Policy Department of the Ministry for Foreign Affairs co-ordinates Sweden’s sanctions policy.

The Swedish Sanctions Co-Ordination Council was established in 2024 to strengthen co-operation among the authorities responsible for preventing, detecting, investigating and prosecuting sanctions violations.

Sweden implements arms embargoes imposed by the UN Security Council. In addition, the EU has autonomously imposed arms embargoes and, in relation to certain countries, prohibitions concerning equipment that may be used for internal repression. ISP is the competent Swedish authority for matters relating to such embargoes.

Defence sector participants must comply with applicable sanctions and should implement appropriate, risk-based measures to avoid dealing with sanctioned parties. Where applicable sanctions require screening of counterparties and business partners, such requirements should be complied with.

There is no general due diligence requirement applicable to all situations. Generally, economic operators should continuously identify, evaluate and understand the risks of circumventions in their own operations and implement appropriate measures to reduce the risk of participating in or being used to circumvent applicable sanctions. The scope and frequency of the due diligence measures should be determined based on the risks associated with each company’s operations.

Exceptions from applicable sanctions are available only where expressly provided in the relevant sanction’s regulation. The Swedish government will appoint the competent national authority to process applications for an exception. For example, ISP generally handles matters concerning dual-use items, equipment that may be used for internal repression and arms embargoes, while the National Board of Trade reviews most other exemption applications concerning legal entities.

The international sanctions applicable in Sweden are those adopted by the EU or the UN. Sweden does not recognise or give effect to extraterritorial sanctions imposed by third countries. Such sanctions may nevertheless create legal, financial and commercial risks for Swedish entities.

A sanctions compliance programme should be risk-based and tailored to each entity’s operations and risk exposure. Factors relevant to evaluating the risk exposure could be supply chains, customers and end-user identification, type of products or services, transport routes and payment flows. Based on the risks identified, appropriate and proportionate measures should be implemented. The risk exposure and measures should be regularly reviewed.

There should be clear allocation of responsibilities with oversight of senior management. The sanctions programme should include regular training of staff, routines for monitoring, as well as reporting and escalating mechanisms.

Under the Swedish Act on International Sanctions (2025:327) an intentional or grossly negligent sanctions offence may result in imprisonment for up to three years. A minor offence may result in a fine or imprisonment for up to six months. An intentional aggravated or repeated offence may result in imprisonment for between two and six years.

When determining whether an offence is aggravated, particular consideration is given to whether the offence concerns a very significant value, involves military equipment or dual-use items, or is otherwise of a particularly dangerous nature.

A corporate fine under the Swedish Criminal Code may be imposed on legal entities where an offence has been committed in its business and the company has failed to take the measures that could have been reasonably required to prevent it, or where the offence was committed by a person in a senior position or with particular responsibility for supervision or control.

The corporate fine is based on a sanction value of between SEK5,000 and SEK10 million. For larger companies, the fine may be increased by reference to the company’s financial position and may amount to a maximum of SEK500 million. A corporate fine may be reduced where the company has taken reasonable steps to prevent, remedy or limit the harmful effects of the offence, or has voluntarily reported it.

The Swedish International Sanctions Act has only been in force since June 2025, and there is therefore yet limited case law concerning its application, although there have been several preliminary investigations for sanctions violations.

Although the Swedish Sanctions Co-Ordination Council was established in 2024, a regulation formalising its role and functions came into force in 2026. Given the increased focus on sanctions circumventions, more developments are expected in the coming year.

The principal legislation governing national security in the defence sector in Sweden comprises the following.

  • The Protective Security Act (2018:585) and the Protective Security Ordinance (2021:955) applicable to public and private entities conducting security-sensitive activities. The Swedish Security Service and the Swedish Armed Forces act as co-ordinating authorities for the designated authorities.
  • The Military Equipment Act (1992:1300) and the Military Equipment Ordinance (1992:1303) regulate manufacturing, supply, exportation and brokering of military equipment. The regulations also apply to agreements concerning manufacturing rights and technical assistance concerning military equipment. Supervision and relevant authorisation are exercised by ISP. The government may determine certain matters of principle or particular importance.
  • The Strategic Products Acts (2025:952) and the Strategic Products Ordinance (2026:6) together with the EU Dual-Use Regulation apply to exports, brokering, transit and technical assistance involving dual-use and other strategically sensitive products. ISP is the main supervisory authority. The Swedish Radiation Safety Authority may review matters concerning nuclear materials and related products, while Swedish Customs is responsible for relevant border control.
  • The Screening of Foreign Direct Investments Act (2023:560) (the “FDI Act”) and the Ordinance (2023:624) on Screening of Foreign Direct Investments establish mandatory and suspensory screening of investments in protected activities. ISP is the designated screening and supervisory body.
  • The Public Access to Information and Secrecy Act (2009:400) and Chapter 19 of the Swedish Criminal Code (1962:700) concerning protection of information relating to national defence and security, and establishing criminal liability for offences including espionage and unauthorised dealings with classified information.

Individuals participating in security-sensitive activities under the Protective Security Act must undergo security vetting before access is granted to the relevant activity. The scope of the vetting must be proportionate to the individual’s role and ordinarily includes basic investigation. Individuals holding positions classified within security classes require register checks and, for classes 1 and 2, a special personal investigation. Positions are assigned to classes based on the level of sensitive information accessible through the position in relation to the potential harm to national security if the information is disclosed.

The Swedish Security Service conducts the register checks but does not grant security clearance. The relevant employer or operator is responsible for the overall suitability assessment and the final decision on access. The vetting is a continuously ongoing process; access must be withdrawn if an individual no longer satisfies the applicable reliability, loyalty or vulnerability requirements.

Sweden does not have a general domestic facility-clearance regime. Entities conducting security-sensitive activities must undertake a security protection analysis and implement appropriate information, physical and personnel measures. Where a supplier, contractor or partner may gain access to security-sensitive activities, a written security protection agreement, sustainability assessment and consultation with the relevant supervisory authority may be required.

Supervision is exercised by the authorities designated under Chapter 8 of the Protective Security Ordinance.

Classified defence information is primarily regulated under the Protective Security Act, the Protective Security Ordinance, the Public Access to Information and Secrecy Act and an implementing regulation issued by the Swedish Security Service and the Swedish Armed Forces. Information is assigned one of four security classifications according to the potential harm to Sweden’s security if the information is disclosed. The classifications are Top Secret, Secret, Confidential and Restricted.

Access is generally granted on a need-to-know basis, where an individual must:

  • have a legitimate operational need for the information;
  • have undergone the required security vetting; and
  • possess sufficient knowledge of applicable protective security requirements.

The relevant operator must implement information, physical and personnel measures preventing unauthorised disclosure, alteration, destruction or loss of access. Detailed requirements apply to storage, IT systems, communications, copying, transportation, destruction and incident reporting, depending on the information classification.

Before granting a contractor access to information classified as Confidential or above, or to activities of corresponding importance, a special security protection assessment must be conducted, and the parties must enter into a written security protection agreement. The agreement must regulate the contractor’s security obligations, following which the contractor is responsible for relevant compliancy.

There is no general single statutory designation of critical national infrastructure for defence assets in Sweden. Such assets and capabilities are protected though overlapping classification and regulatory regimes. Defence assets may constitute security-sensitive activities under the Protective Security Act. If the relevant activity constitutes a security-sensitive activity, the operator must:

  • notify the relevant supervisory authority;
  • conduct and document a protective security analysis;
  • implement relevant information, physical and personnel security measures;
  • security-vet relevant personnel;
  • enter into protective security agreements with contractors where required; and
  • conduct prior security and suitability assessments before certain procurements, collaborations or transfers.

The supervisory authority may prohibit a transfer or agreement that is unsuitable from a security protection perspective. The authority may also impose measures on valid agreements where a protective security aspect is of current relevance, although not relevant at the time of entry into force of the agreement.

Military facilities, installations, vessels and other strategically important assets may also be designated as protected objects under the Protection Act (2010:305). Such designation permits restrictions on access, photography and other activities and authorises specially appointed security guards to enforce the restrictions.

Lastly, investments in security-sensitive activities, military equipment and strategically protected technologies fall within the FDI regime. Relevant acquisitions are subject to mandatory notifications and may not be completed before obtaining clearance from ISP. Investments in security-sensitive activities may also be subject to a notification requirement under the Protective Security Act.

There is no general mandatory cybersecurity certification or accreditation scheme for defence contractors in Sweden equivalent to the US CMMC framework. The applicable requirements depend on the nature of the information and whether the relevant activities are security-sensitive under the Protective Security Act (2018:585).

Security-Sensitive Activities

Where a contractor handles security-classified information or otherwise participates in security-sensitive activities, the operator must, as applicable:

  • conduct and document a protective security analysis;
  • implement appropriate information-security, physical-security and personnel-security measures;
  • security-vet relevant personnel and, where required, conduct register checks;
  • enter into protective security agreements with contractors and subcontractors;
  • assess and approve relevant information systems before they are put into operation; and
  • implement appropriate access controls, authentication, security logging, network separation, incident reporting, back-up arrangements and protection against intrusion and malicious code.

Security Clearances Issued by FMV

The Swedish Defence Materiel Administration (Försvarets materielverk; FMV) acts as Sweden’s Designated Security Authority for industrial security. It may issue Facility Security Clearances (FSCs) and Personnel Security Clearances (PSCs).

An FSC confirms that a contractor has entered into a Level 1 security protection agreement with FMV, and may handle and store classified information at premises approved by FMV. A PSC confirms that an individual is authorised to access classified information. These clearances may be issued following an application from a foreign state, an international organisation or a company established in Sweden.

FSCs and PSCs relate to specified classified activities. They are not general assessments of a contractor’s cybersecurity maturity and are therefore not directly equivalent to CMMC certification.

Cybersecurity Act and NIS2

Defence contractors may also fall within the Cybersecurity Act (2025:1506), which implements the NIS2 Directive in Sweden. An organisation covered by the Act must register with the competent supervisory authority, implement proportionate technical, operational and organisational cybersecurity measures, and report significant incidents.

The Act does not generally apply to a private operator that exclusively conducts security-sensitive activities or exclusively provides services to certain government authorities predominantly engaged in such activities. Such operators are instead subject to the Protective Security Act.

Procurement and Contractual Requirements

Contracting authorities may impose additional cybersecurity requirements in individual procurement procedures and contracts. These may include compliance with, or certification under, standards such as ISO/IEC 27001. Such certification is not, however, a general statutory requirement for participation in Swedish defence programmes.

Cybersecurity Act and NIS2

From 1 October 2026, entities covered by the Cybersecurity Act must assess and manage cybersecurity and continuity risks in their digital supply chains under MCFFS 2026:11. This includes obtaining relevant information about subcontractors, particularly where alternative suppliers are unavailable, and assessing cybersecurity risks arising from those subcontractors.

Defence Procurements

Within defence procurements under LUFS, contracting authorities and entities may require information relating to the supply chain, aiming to ensure that subcontractors have the capacity to protect security-sensitive information as well as commitments and documentation to ensure security of supply requirements, also in a crisis.

Under the Protective Security Act, when a business carries out security-sensitive operations, particular care must be taken to ascertain that it protects information, assets and activities against espionage, sabotage, terrorist offences and other threats deemed necessary for the particular business operations deemed as security-sensitive. A notification must be urgently sent to the Security Services in the case of certain events, such as:

  • where there is reason to believe that a security-classified piece of information has been wrongfully disclosed; and
  • where an IT incident in an information system that the business is responsible for, and that is of importance to security-sensitive activities and the security of the system, may be seriously affected.

Mitigation in relation to foreign ownership, control and influence over defence sector entities is available through the FDI Act and the Protective Security Act in relation to investments, and through the Protective Security Act in relation to clearance to handle security-sensitive information. If issues are raised in relation to an investigation, ISP may impose commitments on the investor to mitigate identified risks under the FDI Regime. The relevant supervisory authority under the Protective Security Act may also impose conditions to approve an investment. Relevant commitments may include:

  • that the board of directors and/or management should comprise Swedish nationals to a certain extent;
  • that security clearance is granted or that ISP must approve directors; and
  • that certain operations shall be conducted subject to certain rules.

Refer to the previous sections in 5. National Security Regulation.

In Sweden, foreign direct investments are governed by the FDI Act and the Ordinance (2023:624) on Screening of Foreign Direct Investments. The regime applies to both direct and indirect investments in “protected activities” conducted by entities domiciled in Sweden.

“Protected activities” are broadly defined under Section 3 of the FDI Act, and include:

  • essential services, as further defined in the Swedish Civil Defence and Resilience Agency’s Resolution on Essential Services in Connection with Foreign Direct Investment (MCFFS 2026:13);
  • security-sensitive activities as defined in the Protective Security Act (2018:585);
  • activities related to critical raw materials;
  • processing of large amounts of personal data or location data;
  • manufacturing, development, research or supply of military equipment;
  • manufacturing, development, research or supply of dual-use products; and
  • emerging technologies or other strategic protected activities, such as AI, biotechnology, and information and cybersecurity.

ISP is the designated screening and supervisory body.

There is no separate screening procedure for transactions in the defence sector. Such transactions are subject to the standard FDI screening process, provided that the target company’s business activities fall within the definition of “protected activities” under Section 3 of the FDI Act and constitute a covered type of transaction.

Notification is required where a transaction results in, among other things, the following:

  • acquisition of shares resulting in the investor holding, directly or indirectly, 10%, 20%, 30%, 50%, 65% or 90% of the voting rights;
  • establishment of a new entity, including joint ventures, where the investor will hold at least 10% of the voting rights;
  • investments through which the investor otherwise obtains direct or indirect influence over the management of the entity;
  • investments in protected activities conducted through partnerships, foundations or sole proprietorships; or
  • investments through which the investor obtains influence over the relevant protected activities by other means, such as veto rights or equivalent.

It is important to note that the notification obligation applies to Swedish and foreign investors alike, and the regime also covers intra-group reorganisations.

Notification is mandatory for all transactions within the scope of the Swedish FDI Act, with only one limited exemption in relation to issuance of shares. Failure to notify, and implementation before a clearance decision, may be subject to fines of up to SEK100 million. If the transaction is prohibited, the legal actions implementing said transaction may be declared invalid and forced to be divested.

The review period for a notification is 25 business days from submission of a complete notification in Phase 1, whereby the authority will either clear the transaction or initiate an in-depth review (Phase 2). If an in-depth review is initiated, such review must generally be completed within three months of its initiation. Where a special ground exists, the review period may be extended to a maximum of six months. Notifiable transactions are subject to a standstill obligation and may not be completed before the transaction has been cleared.

The notification must be submitted by the investor, using the forms provided by ISP and required annexes. The notification must include, among other things:

  • information concerning the investor, including its full ownership structure up to and including each ultimate owner holding 10% or more of the votes in any underlying entity;
  • information concerning the target and the protected activities conducted by the target;
  • information concerning the transaction, such as its structure and purpose, financing and value, as well as the nature of the influence exercised by the investor before and after the transaction; and
  • relevant documents concerning the transaction and ownership-structure charts.

ISP provides only limited public guidance on how individual factors are assessed, as case-specific information is generally confidential. The following parameters are central to the assessment under the FDI Act:

  • the nature and scope of the protected activities;
  • whether the investor is controlled, wholly or partly, by a non-EU state through its ownership structure, significant financing or other means;
  • whether the investor or any entity in its ownership structure has previously been involved in activities that have or could have adversely affected security, public order or public security in Sweden or another EU member state; and
  • any other investor-related circumstances indicating that the investment may have such an adverse effect.

The assessment is conducted on a case-by-case basis, and the legislation does not prescribe an exhaustive list of relevant factors or fixed criteria automatically resulting in prohibition.

There are no separate remedies available for transactions in the defence sector. ISP may grant clearance subject to conditions necessary to prevent the transaction from adversely affecting security, public order or public security in Sweden. Such conditions may relate to:

  • the conduct of the protected activities;
  • the management and control of the target; or
  • circumstances relating to the investor.

The statutory framework permits transaction-specific behavioural, governance and control-related commitments, but does not prescribe an exhaustive catalogue of remedies or a standard form of security agreement.

ISP may prohibit an investment where prohibiting is necessary to prevent the relevant adverse effects. An investment previously approved subject to conditions may also be prohibited if the relevant conditions are breached. Legal acts implementing a prohibited investment are deemed null and void. Compliance may also be enforced through injunctions, conditional penalties and administrative sanctions.

If ISP initiates a review of a transaction not subject to the notification requirement and finds the transaction to have an adverse effect on security, public order or public security in Sweden, ISP may require the transaction to be unwound.

Sweden does not have a general “golden share” regime or equivalent statutory special shareholder rights.

There are no separate regulatory FDI requirements or restrictions applicable to the formation of joint ventures in Sweden. Joint ventures are subject to the standard FDI screening process, provided that the relevant business activities are within the scope of the FDI Act.

However, separate sector-specific requirements may apply. A joint venture in the defence sector may, for example, require certain authorisation to manufacture or supply military equipment. If the joint venture will conduct security-sensitive activities, appropriate protective-security measures may be required before a foreign partner is granted access to the joint venture.

The FDI regime does not generally regulate the allocation of intellectual property (IP), although such assets may be within scope of the FDI regime depending on the circumstances. Technology transfer and IP ownership are generally addressed contractually, including ownership of background and newly developed IP, licensing and sublicensing rights, permitted fields of use, confidentiality, access restrictions and rights following termination. Any contractual access or transfer remains subject to applicable protective-security restrictions. However, conditions may be imposed relating to IP rights.

The merger control regime and the FDI regime are based on different interests to be assessed. The merger control regime has inspired the procedural aspects of the FDI Act, but there is generally no co-operation or co-ordination mechanism between the relevant authorities.

Each relevant authority will therefore base its decision on either competition law considerations or national security considerations. If one of the relevant required clearances is not granted or fulfilled, the transaction may not be closed although the practical management of such a situation may be different.

There are a number of Swedish authorities with supervisory powers in the defence and security field, for sanctions, protective security, etc. Only a few examples are mentioned below.

The Swedish Competition Authority supervises contracting authorities’ and entities’ compliance with the Act on Public Procurement in the Defence and Security Area. It has the power to decide that a procurement sanction fee shall be imposed on the contracting authority or entity.

ISP grants licences for and monitors the exportation of military equipment and dual-use products, and reviews foreign direct investments. It may request information and documents, conduct inspections, issue compliance orders, and suspend or revoke authorisations.

Swedish Customs monitors cross-border movements and investigates suspected smuggling involving military equipment, sanctioned goods and dual-use items.

The Police, the Security Service and the Swedish Prosecution Authority investigate suspected criminal offences concerning sanctions, unlawful exports and threats to national security. Subject to the ordinary statutory thresholds, they may conduct interviews, search premises, seize evidence and use other coercive measures.

There are many ways that investigations may be triggered – eg, by whistle-blower reports, incident notifications, intelligence from security services, customs inspections, discrepancies in export documentation, regulatory supervision, or inconsistencies in applications and regulatory filings.

There are a number of authorities with investigative powers in this field; not all defence-related matters are governed by a single legislative framework. Generally, authorities may require the disclosure of information and documents for their investigations and may require access to premises.

ISP has specific powers in connection with the screening of foreign direct investments and licence-holders under the Military Equipment Act and the dual-use items regulations. The power includes requesting information and documents in order to assess notifications and conduct supervisory tasks. ISP may also access premises where relevant business is conducted; such access rights are associated with its supervisory activities and not with criminal investigative powers.

Defence sector entities are not exempt from dawn raids under Swedish competition law. The entity is obliged to co-operate, provide access to offices or transports, provide relevant records and refrain from obstructing the inspection. The Swedish Competition Authority may therefore conduct inspections following authorisation by the Patent and Market Court, where a defence undertaking is suspected of an infringement, such as bid rigging. Any inspection involving security classified information or sensitive premises must, however, be conducted in accordance with security protection requirements.

ISP may also carry out unannounced inspections in exercising its supervisory powers under the Military Equipment Act and the dual-use items regime.

Swedish law provides strong protection for confidential communications with members of the Swedish Bar Association, but its scope depends on the procedural rules applicable to the relevant investigation.

For example, documents whose contents are protected by the statutory restriction on examining an advocate as a witness are protected from measures taken by the Swedish Competition Authority. Any dispute concerning whether a document is protected is determined by the Patent and Market Court.

In relation to supervisory activities from ISP and other authorities, the general rule on legal professional privilege in the Code of Judicial Procedure applies, and a distinction should be made between documents that may be included and documents which there is a legal obligation to provide in response to such a request.

A regulatory breach or a criminal conviction may lead to exclusion from future procurements in the defence and security field. If the criminal conviction relates to certain specified offences, exclusion of the tenderer is mandatory unless there are exceptional reasons. Other regulatory breaches or offences could result in exclusion of the tenderer. Please refer to 2.10 Exclusion Grounds for further details.

Disputes concerning defence and security contracts are generally resolved by:

  • the administrative courts where the dispute relates to the procurement process or awarding decision, before the contract is signed;
  • arbitration, where agreed in the contract; and
  • the general courts, for contract disputes where arbitration has not been agreed upon.

Sweden has no defence-specific whistle-blower regime. The Swedish Whistle-Blower Act (2021:890) does not apply to reporting of:

  • security-sensitive or classified information under the Protective Security Act; and
  • information concerning national security in the activities of defence and security authorities – eg, the Armed Forces and ISP.

Please refer to 3.9 Enforcement, Penalties and Voluntary Disclosure, 4.1 Sanctions Legislation and Regulatory Framework and 4.7 Enforcement, Penalties and Voluntary Disclosure.

Advokatfirman Cederquist

PO Box 1670
SE-111 96 Stockholm
Sweden

+46 522 065 00

+46 8 522 067 00

advokat@cederquist.se www.cederquist.se
Author Business Card

Trends and Developments


Authors



Kahn Pedersen has established a distinctive position in the Swedish legal market by combining highly specialised public-sector expertise with digital and security-related capabilities. Its defence practice sits at the intersection of public procurement, protective security, cybersecurity, essential infrastructure and total-defence preparedness. This combination enables the firm to advise clients not only on legal compliance but also on the strategic and operational challenges created by a changing security environment. The firm works with authorities and businesses facing complex procurement, security and resilience issues, allowing it to understand both regulatory requirements and commercial realities. Its unique market position combines deep expertise, digital competence, public-sector knowledge and a commercially oriented approach to security and defence challenges. Kahn Pedersen serves a diverse client base spanning Swedish public authorities, municipalities and publicly owned companies, as well as major Swedish and international businesses. Its private-sector clients include banks, insurers, industrial, energy and real-estate companies. Notable clients in the defence field includes the Swedish Civil Defence and Resilience Agency, the National Board of Health and Welfare and the Swedish Police Authority.

Sweden: Where Total Defence Is a Matter for the Entire Population

Introduction to the Swedish concept of “total defence”

The opening provision of the Total Defence Service Act – the statute under which individual citizens may be required to serve in the armed forces – states:

“Total defence is a matter for the entire population.”

This concise statutory statement captures how Sweden approaches both national defence and defence law. The same spirit runs through many of the nearly 50 legal instruments that together form the legal framework for Sweden’s total defence.

One of the principal statutes in this field, the Total Defence and Heightened Readiness Act, defines total defence as all activities necessary to prepare Sweden for war, whether undertaken by public or private actors and whether military or civilian in nature. In short, Sweden’s total defence is, in both practical and legal terms, a matter of public concern in which all actors sustaining essential societal functions – public and private alike – are expected to participate and assume responsibility.

The military component of Sweden’s total defence follows a traditional hierarchical structure. Commander-in-Chief Michael Claesson is the highest-ranking officer and reports only to the government.

The civil component of total defence has a considerably more complex organisational structure. Civil defence is divided into 12 sectors which, collectively, are intended to cover the societal functions Sweden requires for an effective defence. These sectors are:

  • economic security;
  • electronic communications and postal services;
  • energy supply;
  • financial services;
  • the provision of basic data;
  • health, healthcare and social services;
  • industry, construction and trade;
  • food supply and drinking water;
  • public order and security;
  • emergency services and civil protection;
  • transport; and
  • foreign trade.

Each sector has a designated sector-responsible authority, together with a number of so-called emergency preparedness authorities. These authorities are responsible for leading efforts to strengthen total defence capabilities within their respective sectors, both within the authorities themselves and among other public and private actors.

The form this work takes varies depending on the authority responsible for the sector. Matters governed by legislation or regulation in one sector may be addressed through soft law or voluntary agreements in another. A significant amount of preparedness work is also cross-sectoral.

Taken together, these features can make it difficult to obtain a clear overview of both the legal framework and the administrative structure of Sweden’s total defence. The Swedish Civil Defence and Resilience Agency therefore has an overarching role in co-ordinating the civil defence system, and regularly issues guidance and other support to assist public authorities and private entities with their total defence work.

“Just in Time” Is Too Late

The peacetime mission of total defence is as easy to state as it is difficult to carry out. Actors operating within any of the 12 preparedness sectors must, individually and collectively, take the measures and undertake the planning necessary to make the functions critical to total defence in each sector more robust and resilient in the event of an invasion of Swedish territory or acts of war in neighbouring countries.

In addition to the basic requirements for each entity to establish a wartime organisation, conduct a risk and vulnerability analysis, and regularly undertake scenario-based exercises, this also entails preparing a so-called supply analysis. In such an analysis, entities identify the dependencies on which their ability to continue operating would rely under conditions of severe trade disruption. In practice, this means ensuring that they can maintain their operations – at least at a basic level – even without relying on resources located outside Sweden.

For the vast majority of companies, establishing the domestic capacity required for security of supply presents a major challenge. Companies whose operating models rely on “just-in-time” deliveries and “follow-the-sun” support are being forced to reconsider their strategies and establish a stronger local presence and capability. The rebuilding of Sweden’s total defence now under way is, in this respect, a disruptive force across society.

For companies seeking to retain a more traditional, global operating model, the concept of total defence presents a genuine challenge. For companies able to adapt their organisation and establish a stronger local presence, however, Sweden’s total defence structure offers the kinds of commercial opportunities associated with major economic paradigm shifts.

Cold War-Era Legislation, Revamped

The concept of total defence has deep roots, and Sweden has organised its defence on this basis since at least the Second World War. The concept assumes that Russia is the principal adversary, and is designed to prepare Sweden for the kind of protracted invasion war now being fought in Ukraine.

Between the fall of the Berlin Wall and Russia’s annexation of Crimea, however, the concept of total defence lay dormant. The legislation governing total defence remained on the books but was not applied in practice for nearly 25 years.

Now that this legislation is being reactivated, much of it appears outdated and poorly suited to the activities that constitute modern total defence. Much has changed since 1989.

Firstly, tasks relevant to total defence are now carried out to a far greater extent by private companies. Secondly, those companies are far more likely to be international or global businesses. Thirdly, the services they provide are significantly more complex and increasingly dependent on highly specialised international expertise.

Cold War-era total defence legislation is plainly insufficient to address the complexities of modern business, and intensive legislative work is under way across all sectors to modernise the existing rules. At the same time, there is a reluctance to begin again from a blank sheet of paper.

Russia’s full-scale invasion of Ukraine has underscored the urgency of rebuilding Sweden’s total defence capabilities, and there is simply no time to reconstruct the entire system from the ground up. The approach has therefore been to preserve as much as possible of the legal structures inherited from the Cold War, while updating them where necessary to reflect the present-day defence policy and economic environment.

One of the principal challenges in this modernisation effort is to develop a contemporary equivalent of what was known as the “K-company”.

Agreements Come First

Although a legislative framework exists, Sweden’s concept of total defence has always relied heavily on voluntary participation. At its height, the Swedish total defence system included – in addition to public-sector actors – an estimated 11,000 private companies that had voluntarily committed themselves to total defence planning. These companies, known as “K-companies”, had entered into agreements under which they undertook to make their resources available to the defence effort in various ways in the event of heightened readiness or war.

The voluntary nature of these arrangements is, of course, open to debate. As is often the case in the Swedish legal tradition, the State will generally first seek to reach an agreement. If no agreement can be reached, however, it will not hesitate to legislate.

The same approach is being followed today. Each sector-responsible authority first considers whether the desired total defence capability can be secured through a so-called preparedness agreement, or “F-agreement”. Only if this route proves insufficient may legislation be used to impose obligations on the companies concerned.

There are several reasons for preferring this approach. A negotiated agreement defining how a particular company is to contribute to total defence can take account of that company’s specific circumstances in a way that general legislation cannot. Contractually agreed preparedness may therefore be significantly more cost-effective than preparedness imposed solely through legislation.

An agreement also creates better conditions for the company to develop a genuine commitment to defence preparedness and to focus its resources on building the greatest possible defence capability. Legislation, by contrast, tends to direct a company’s resources towards compliance rather than capability enhancement. This can create a false sense of preparedness where the underlying capability is, in fact, absent.

There is also a clear commercial opportunity. Companies that are early in offering their capabilities under F-agreements may help shape the standards governing how such agreements should be structured. Those companies may therefore not only influence the terms applicable to their own operations but also contribute to the development of standards for their wider industry – standards that may ultimately inform future legislation or regulatory practice.

The Digital Dimension

The largest gap between the assumptions underpinning the older preparedness system and modern commercial reality may be found in IT services. Sweden is a highly digitalised economy, and critical functions increasingly depend on Software as a Service (SaaS) applications, cloud infrastructure, identity platforms, data centres, managed services, telecommunications and globally distributed support organisations.

This reveals a fundamental paradox at the heart of modern total defence. The technologies that have made Swedish society more efficient have, in some respects, also made resilience more difficult to engineer. Cloud services are not inherently at odds with resilience. Large providers may offer levels of technical security, redundancy and operational expertise that individual customers could not reproduce. The problem is not merely that a service is external; it is that the customer’s ability to understand, influence and replace that service may be limited at precisely the moment when control matters most.

Traditional preparedness planning typically began with tangible assets and dependencies: a factory, a warehouse, a vehicle fleet, a local workforce or a defined stock of goods. A modern digital service may instead depend on an international chain of data centres, software components, identity services, telecommunications networks, subcontractors and remote support teams. These digital dependencies are both less visible and more difficult to control.

For total defence purposes, the relevant question is therefore no longer merely where the servers are located or where the data is stored. The more difficult questions concern who actually controls the service, which dependencies exist further down the supply chain, where the personnel required to operate and restore the service are located, and whether the customer can continue operating if connectivity or access to external resources is severely disrupted. A service may, for example, store all its data in Sweden while essential administration, updates or incident response are carried out elsewhere. Data localisation can reduce one category of risk without delivering genuine operational sovereignty.

This is also where total defence increasingly intersects with NIS2 and the Critical Entities Resilience Directive, or CER. The three frameworks address related problems, but they do so from different perspectives.

Sweden’s Cybersecurity Act, which implements NIS2, focuses primarily on cybersecurity and the security of network and information systems. It requires covered entities to address, among other matters, business continuity, crisis management and supply-chain security. CER takes a broader, all-hazards approach to the resilience of critical entities and their ability to maintain essential services. Total defence poses a further and ultimately more demanding question: what must continue to function under conditions of heightened readiness and, ultimately, war?

The frameworks are deliberately connected, but overlap does not amount to equivalence. An organisation may comply with its cybersecurity obligations and still lack the operational resilience required for total defence purposes. Conversely, measures taken as part of total defence planning may also contribute to compliance with NIS2 or CER. The Protective Security Act may add a further layer where Sweden’s national security is directly engaged.

For companies and public authorities, the result is an increasingly complex contractual landscape. A single IT service, outsourcing arrangement or cloud relationship may fall within several legal frameworks at once. More importantly, the organisation bearing the regulatory or preparedness obligation may not itself control the technical capability on which its compliance depends. That capability may instead reside with a cloud provider, a SaaS supplier or a subcontractor several steps down the supply chain.

This makes contractual design particularly important. A generic requirement that the supplier comply with applicable law is plainly insufficient. Customers increasingly need visibility into relevant dependencies, timely access to information, clear escalation routes, incident co-operation, continuity commitments and appropriate control over critical subcontracting arrangements. In this sense, the agreement becomes the means by which the customer seeks to extend its resilience requirements into the supplier’s organisation and supply chain.

SaaS services illustrate the difficulty particularly clearly. The commercial logic of SaaS is based on standardisation and scale. The supplier operates a common service for a large number of customers and retains extensive control over the underlying software, infrastructure, subcontractors and product roadmap. The customer benefits from an efficient and continuously updated service, but has comparatively little operational control.

That model can sit uneasily with some of the assumptions underpinning total defence. A supplier may deliver excellent availability under normal conditions while being unable to guarantee that a Swedish customer will receive priority access to scarce capacity or specialist personnel during a major international crisis. A function may also fail because a separate identity provider, network connection or integration is unavailable, even though the SaaS platform itself remains operational.

A multi-cloud strategy does not necessarily solve the problem either. Two cloud environments do not provide genuine redundancy if both depend on the same telecommunications provider, identity layer, management tools or limited pool of specialist personnel. Resilience requires an understanding of common dependencies, not merely a larger number of suppliers.

None of this suggests that Sweden should seek to reverse decades of digitalisation or eliminate international dependencies. Such an approach would be neither realistic nor necessarily conducive to greater resilience. Sweden’s defence is now embedded in NATO, the Nordic region and the EU, and resilience can be built through trusted interdependence as well as through domestic capacity. For many systems and workloads (but not all), large cloud and SaaS providers may also offer levels of cybersecurity, redundancy and specialist expertise that individual Swedish organisations could not reasonably reproduce. There are therefore compelling reasons for cautious optimism.

Firstly, NIS2, CER and renewed total defence planning are forcing organisations to identify dependencies that have historically remained hidden within technical architectures and supply chains. It is difficult to build resilience around a dependency that no one has identified. Greater visibility is therefore an essential first step.

Secondly, contractual practice is developing. Matters that were previously treated as technical details – subcontracting, data location, continuity, recovery, portability and access to key personnel – are increasingly becoming substantive negotiation issues. Customers are beginning to procure continuity, portability and tested recovery as characteristics of the service itself, rather than relying on general assurances about resilience.

Thirdly, digitalisation can itself form part of the solution. Properly designed cloud architectures can provide geographic redundancy, rapid restoration and distributed capacity that would have been impossible under older infrastructure models. The problem is not digitalisation as such but unmanaged concentration and dependency.

Not every system requires sovereign infrastructure or an offline alternative; the most critical systems may. The essential point is that this distinction is made consciously, that hidden dependencies are understood and that the required capability is actually tested.

The task is not to recreate the analogue resilience of the past. Sweden cannot, and should not, reverse decades of digitalisation. The task is instead to build a form of digital resilience capable of supporting modern total defence.

The EU Dimension

There is a natural tension between EU law and Swedish total defence law. Total defence is, and will remain, a national responsibility. Article 4 of the Treaty on European Union recognises national responsibility for security matters. At the same time, there are clear geopolitical advantages to the Europeanisation of defence. Although the EU is not yet a fully fledged defence union, it is increasingly becoming a preparedness union.

This creates a challenge for Sweden’s total defence efforts. Every agreement entered into and every decision taken within the framework of total defence must be assessed for compatibility with EU law, particularly procurement law and state aid law. Peacetime total defence activities must be conducted in a manner consistent with EU law.

At the same time, it is clear that the EU is seeking to address this tension. One example is the European Commission’s updated decision on services of general economic interest, or SGEI, which expressly supports the development of national preparedness in relation to critical medical products. Another important development is the increasing scope within public procurement to exclude non-European alternatives.

For Swedish authorities, the challenge is therefore not simply to maximise national autonomy but to build a total defence capability that is both operationally credible and legally compatible with Sweden’s obligations as an EU member state.

What Comes Next for Sweden?

We are living through a period of rapid and far-reaching change. In this environment, the role of defence law is to provide the structure and predictability required for the investments on which total defence depends. The next three years will be marked by intense legislative activity and a significant increase in the expectations placed on private companies carrying out activities critical to Swedish society.

At the same time, this shift – and the willingness to invest that accompanies it – presents significant commercial opportunities for companies capable of responding quickly to the expectations of total defence. As ever, whether this change is perceived as a challenge or an opportunity depends on one’s perspective.

Advokatfirman Kahn Pedersen

Katarinavägen 9 C
PO Box 4047
102 61 Stockholm
Sweden

+46 8 121 502 20

info@kahnpedersen.se kahnpedersen.se/
Author Business Card

Law and Practice

Authors



Advokatfirman Cederquist is a full-service Swedish business law firm with approximately 120 lawyers in a single Stockholm office. Its five-lawyer co-ordination defence and security team combines public procurement, protective security, export controls, sanctions, FDI screening, competition law, corporate/M&A, cybersecurity, IP and technology expertise, drawing on specialists across the firm for complex cross-border mandates. The team advises defence contractors, technology companies, infrastructure investors and suppliers to public authorities throughout the life cycle of security-sensitive projects: market entry, tenders, licensing and regulatory clearances, transactions, contracting, supply-chain resilience, disputes and investigations. Recent relevant work includes advising Samsung Electronics’ networks division on Swedish procurement matters, Kåpan Fastigheter on the expansion and procurement of public properties needed for defence and security, Triton Partners in creating the Nordic technical-security group Varna, and Prima Materia on its investment in defence AI company Helsing. Cederquist co-ordinates international matters through a network of leading independent law firms.

Trends and Developments

Authors



Kahn Pedersen has established a distinctive position in the Swedish legal market by combining highly specialised public-sector expertise with digital and security-related capabilities. Its defence practice sits at the intersection of public procurement, protective security, cybersecurity, essential infrastructure and total-defence preparedness. This combination enables the firm to advise clients not only on legal compliance but also on the strategic and operational challenges created by a changing security environment. The firm works with authorities and businesses facing complex procurement, security and resilience issues, allowing it to understand both regulatory requirements and commercial realities. Its unique market position combines deep expertise, digital competence, public-sector knowledge and a commercially oriented approach to security and defence challenges. Kahn Pedersen serves a diverse client base spanning Swedish public authorities, municipalities and publicly owned companies, as well as major Swedish and international businesses. Its private-sector clients include banks, insurers, industrial, energy and real-estate companies. Notable clients in the defence field includes the Swedish Civil Defence and Resilience Agency, the National Board of Health and Welfare and the Swedish Police Authority.

Compare law and practice by selecting locations and topic(s)

{{searchBoxHeader}}

Select Topic(s)

loading ...
{{topic.title}}

Please select at least one chapter and one topic to use the compare functionality.