The principal legislation and regulatory framework comprise:
The principal legislation and regulatory framework include the following regarding civil defence and emergency preparedness:
The responsibility for overseeing and enforcing defence-related regulation in Sweden is divided among several ministries, government agencies and regulatory bodies, principally as follows.
Defence and Procurement
Export Controls and Foreign Investment
National and Protective Security
In Sweden, the meaning of “defence” goods, services and technology depends on the applicable regulatory context. “Military equipment” is defined in the annex to the Military Equipment Ordinance.
In relation to “dual-use” items, Sweden relies on the application and distinction provided in the EU Dual-Use Regulation (2021/821) and has national legislation that complements the EU Regulation. As such, “dual-use” items are goods, software and technology capable of both civilian and military applications, including items connected with the development of nuclear, chemical or biological weapons.
The distinction is therefore primarily based on design and technical characteristics; purely military items are specifically designed or adapted for military purposes, whereas dual-use items also have civilian applications.
The Swedish defence regulation is strongly shaped by international obligations and EU law. Sweden follows a dualist approach, whereby treaties generally require incorporation or implementation through domestic legislation before they apply internally, while EU Regulations are directly applicable (as regulated by EU law). The principal international frameworks and treaty obligations reflected in the Swedish defence regulation are, for example:
Sweden also implements non-proliferation treaties such as the Chemical Weapons Convention, for which ISP acts as the national authority. Overall, international commitments strongly shape Swedish licensing criteria, control lists, procurement legislation, sanctions and security requirements, but enforcement remains primarily the responsibility of Swedish authorities.
The Defence and Security Procurement Act (2011:1029) (LUFS), regulates procurements in the defence and security sector of military or sensitive equipment, related works and services, and works or services for military purposes or of a sensitive nature. LUFS is based on and implements Directive 2009/81/EC.
There are certain exceptions to the applicability of LUFS – eg, for procurements of arms, ammunition and war material covered by Article 296(1)(b) of the Treaty on the Functioning of the European Union (TFEU), and for contracts for which the application of LUFS would require disclosure of information contrary to Sweden’s essential security interests or contracts for the purposes of intelligence activities.
The applicability of LUFS is not limited to central government or Ministry of Defence bodies. It applies to all contracting authorities and contracting entities for their procurements in the defence and security sector.
Entities within the scope of the legislation include:
LUFS applies to procurements of contracts concerning:
The EU procurement directives apply above certain thresholds. LUFS applies both above and below the applicable EU thresholds, as Sweden has adopted national rules below the threshold value, included in Chapter 15 and 15a of LUFS.
From 1 January 2026, the thresholds are SEK4,903,632 for supplies and services and SEK61,340,804 for works contracts. The direct award threshold is SEK1.2 million.
LUFS does not specifically set out any separate classified procurement procedures but contains specific provisions relating to information security for procurement involving security-classified information.
Contracting authorities and entities shall specify in the procurement documents the measures and requirements necessary to protect such information. Tenderers may be required to demonstrate that they can comply with those requirements.
The authority or entity may also require undertakings to protect security classified information disclosed during the procurement, during the performance of the contract and after the contract has been completed or terminated.
Sweden’s security protection legislation also applies to procurements in this field, and imposes additional requirements concerning security vetting, access to sensitive information activities and, where applicable, security protection agreements.
For procurements above the EU threshold, the restricted procedure, the negotiated procedure with prior publication and the competitive dialogue are the main procedures. In certain circumstances, the negotiated procedure without prior publication can be applied.
For procurements below the EU threshold, subject to requirements for publication, as regulated in Chapter 15a, LUFS, there are no regulated procurement procedures which enable the contracting authority or entity to design the procurement process more freely as long as the procedure complies with the fundamental procurement principles of, for example, transparency, equal treatment and proportionality. The procurement documents must clearly set out how the procedure will be conducted.
Direct awards are regulated in a separate chapter – Chapter 15a, LUFS.
For procurements above the EU threshold, LUFS permits direct or single-source awards in specified circumstances, through the negotiated procedure without prior publication. This includes situations where the contract can only be awarded to a specific supplier due to technical reasons or exclusive rights, in situations of extreme urgency, or where there is urgency due to crisis situations.
Note also that certain contracts can be exempted from the applicability of LUFS.
For procurements below the EU threshold, Chapter 15a, LUFS regulates direct awards. Direct awards may be used where the estimated value of the procurement is below SEK1.2 million, in certain situations where the estimated value is below the EU threshold or if there are exceptional reasons.
There are no specific requirements regulating offset obligations, industrial participation requirements or sovereign capability conditions in procurement legislation. However, the protective security regime may require protective security agreements, security vetting of personnel, controls on subcontractors, etc. Such requirements may in practice restrict where security and defence contracts are performed and by whom.
In exceptional cases, procurements relating to production of or trade in arms, ammunitions and war materials subject to Article 346(1)(b), TFEU may in a specific instance be exempted from the applicability of LUFS where this is necessary to protect Sweden’s essential security interests.
There is an example in Swedish case law of procurements in the classic sector where a requirement that the supplier could not have certain ownership relating to countries that are identified as a threat to Sweden was upheld, even though it excluded a Swedish entity. The reason was that the requirement had strong protective security justification.
LUFS requires that contracting authorities and entities specify the requirements for security of supply in the procurement documents. Tenderers may be required to demonstrate in their tenders that they meet requirements for security of supply – eg, by providing export licences, information on the organisation and location of the supply chain, undertaking to maintain certain capacity as required to meet an increased demand during a crisis, etc.
A tender that fails to satisfy the stated requirements may be rejected.
A supplier who has failed to comply with information-security or security-of-supply requirements in previous contracts may also be excluded from participation in a later procurement on these grounds.
The contracting authority or entity shall award the contract either to the tender that is the most economically advantageous to the contracting authority or entity, or to the tender containing the lowest price.
In determining the most economically advantageous tender, the contracting authority or entity shall consider various criteria linked to the subject matter of the contract, such as price, delivery or performance time, quality, security of supply, interoperability and operational characteristics.
A contracting authority or entity shall specify, in the contract notice or the procurement documents, the basis for contract award that will be applied.
LUFS contains both mandatory and discretionary grounds for excluding suppliers based on Directive 2009/81/EC.
A tenderer shall be excluded from participation in a procurement where the supplier, or its representatives, have been convicted by a final judgment of an offence involving participation in a criminal organisation, corruption, fraud, money laundering and terrorist financing, or terrorist offences. A contracting authority or entity may however, in the case of exceptional reasons, decide not to exclude a tenderer subject to a mandatory exclusion ground.
A tenderer may also be excluded from participation in a procurement for insolvency-related reasons, reasons related to professional misconduct, failure to pay taxes or social-security contributions, or where the tenderer has been found not to possess the reliability necessary to exclude risks to the security of Sweden.
Applicable EU sanctions may also prohibit the award or performance of a contract involving a sanctioned person or entity.
Under LUFS, procurement documents are generally subject to prior publication and transparency requirements, although the legislation also allows contracting authorities and entities to require that tenderers protect security classified information disclosed during the procurement, during the performance of the contract and after the contract has been completed or terminated.
The Swedish Protective Security Act may require that a protective security agreement be signed before access is granted to security-classed information.
The Swedish Public Access to Information and Secrecy Act may also provide grounds for keeping information confidential during and after a procurement procedure.
LUFS does not contain any provisions specifically allowing for modifications of public contracts. However, it follows from Court of Justice of the European Union (CJEU) case law that modifications may be made under certain circumstances.
A supplier that has suffered, or risks suffering, harm from an alleged breach of LUFS may apply for review before the general administrative court in whose jurisdiction the contracting authority or entity is established.
The court may order the procurement to be corrected or recommenced, and may grant interim relief. Following contract conclusion, it may declare the contract ineffective in specified circumstances, including an unlawful negotiated procedure without prior publication.
The principal legislation governing military equipment is the Military Equipment Act and the Military Equipment Ordinance. Dual-use items are governed by the EU Dual-Use Regulation and complementary Swedish legislation. ISP is the authority responsible for export control and military equipment matters.
The Military Equipment Ordinance has an annex listing military equipment within the scope of the regulation. The Annex is continuously updated to ensure adherence to international obligations, and it requires a decision from the government to be updated. Dual-use items are identified by reference to Annex I to the EU Dual-Use Regulation.
In relation to export and transport authorisation, there are three types of licences:
An application for a licence is made to ISP, and it is advisable to notify the authority early to ensure a smooth process. ISP may also provide an advance ruling. The application should contain information about the contract (including basic information about parties and products) and appropriate end-user documentation.
Under the Military Equipment Act, a licence may only be approved if there are security or defence policy reasons for the export, and the export does not conflict with Sweden’s foreign policy or international obligations. In addition, there is a list of absolute obstacles to a licence such as conflicts with international obligations.
Considerations for granting or refusing licences for dual-use items include international obligations and sanctions, national foreign and security policy, the intended end use and the risk of diversion or unauthorised re-exportation.
For permanent exports or transfers of military equipment to recipients abroad, ISP requires original end-user documentation. For dual-use items, appropriate end-user documentation may be required depending on the authorisation and transaction.
ISP may conduct post-shipment verification in selected cases to confirm that exported military equipment has reached and remains with the authorised end user.
Brokering of military equipment falls within the concept of supply, which includes, among other things, sale, lease, loan, donation and brokering. Conducting such activities professionally requires authorisation from ISP.
In addition to the general rules under the EU Dual-Use Regulation, requiring a licence for Annex I items that may be intended for a weapons-of-mass-destruction end use, Sweden has extended this to also include brokering for non-Annex I dual-use items if the authority has informed the broker that the items may be intended for such use. The broker also has an obligation to notify the authority if there is reason to suspect such end use.
There are no general exemptions in relation to intra-company or intra-group transfers of controlled items or technology. The important aspect is whether there is a cross-border transfer of the items or technology.
Penalties for breach of export control legislation can be of both a criminal and civil nature. There are criminal penalties for exporting without a licence, as well as possible administrative fines for administrative breaches. ISP imposes the administrative fines, whereas criminal charges are brought by the prosecutors’ office.
Voluntary disclosure to ISP in relation to military equipment is possible if a company identifies a possible breach. Such voluntary disclosure is considered a mitigating factor when ISP determines the administrative fine.
The international sanctions applicable in Sweden are those adopted by the EU or the UN.
Breaches of applicable sanctions are primarily regulated in the Swedish Act on International Sanctions (2025:327). The Act implements Directive (EU) 2024/1226 by establishing criminal liability for breaches and circumvention of international sanctions. In the assessment of whether an offence is aggravated, whether the action related to military or dual-use items is expressly relevant.
Sanctions for legal entities are covered by the provisions of the Swedish Criminal Code and its provisions on corporate fines. Several authorities are responsible for different tasks in relation to international sanctions, depending on the applicable sanction’s regulation and provisions therein.
The Security Policy Department of the Ministry for Foreign Affairs co-ordinates Sweden’s sanctions policy.
The Swedish Sanctions Co-Ordination Council was established in 2024 to strengthen co-operation among the authorities responsible for preventing, detecting, investigating and prosecuting sanctions violations.
Sweden implements arms embargoes imposed by the UN Security Council. In addition, the EU has autonomously imposed arms embargoes and, in relation to certain countries, prohibitions concerning equipment that may be used for internal repression. ISP is the competent Swedish authority for matters relating to such embargoes.
Defence sector participants must comply with applicable sanctions and should implement appropriate, risk-based measures to avoid dealing with sanctioned parties. Where applicable sanctions require screening of counterparties and business partners, such requirements should be complied with.
There is no general due diligence requirement applicable to all situations. Generally, economic operators should continuously identify, evaluate and understand the risks of circumventions in their own operations and implement appropriate measures to reduce the risk of participating in or being used to circumvent applicable sanctions. The scope and frequency of the due diligence measures should be determined based on the risks associated with each company’s operations.
Exceptions from applicable sanctions are available only where expressly provided in the relevant sanction’s regulation. The Swedish government will appoint the competent national authority to process applications for an exception. For example, ISP generally handles matters concerning dual-use items, equipment that may be used for internal repression and arms embargoes, while the National Board of Trade reviews most other exemption applications concerning legal entities.
The international sanctions applicable in Sweden are those adopted by the EU or the UN. Sweden does not recognise or give effect to extraterritorial sanctions imposed by third countries. Such sanctions may nevertheless create legal, financial and commercial risks for Swedish entities.
A sanctions compliance programme should be risk-based and tailored to each entity’s operations and risk exposure. Factors relevant to evaluating the risk exposure could be supply chains, customers and end-user identification, type of products or services, transport routes and payment flows. Based on the risks identified, appropriate and proportionate measures should be implemented. The risk exposure and measures should be regularly reviewed.
There should be clear allocation of responsibilities with oversight of senior management. The sanctions programme should include regular training of staff, routines for monitoring, as well as reporting and escalating mechanisms.
Under the Swedish Act on International Sanctions (2025:327) an intentional or grossly negligent sanctions offence may result in imprisonment for up to three years. A minor offence may result in a fine or imprisonment for up to six months. An intentional aggravated or repeated offence may result in imprisonment for between two and six years.
When determining whether an offence is aggravated, particular consideration is given to whether the offence concerns a very significant value, involves military equipment or dual-use items, or is otherwise of a particularly dangerous nature.
A corporate fine under the Swedish Criminal Code may be imposed on legal entities where an offence has been committed in its business and the company has failed to take the measures that could have been reasonably required to prevent it, or where the offence was committed by a person in a senior position or with particular responsibility for supervision or control.
The corporate fine is based on a sanction value of between SEK5,000 and SEK10 million. For larger companies, the fine may be increased by reference to the company’s financial position and may amount to a maximum of SEK500 million. A corporate fine may be reduced where the company has taken reasonable steps to prevent, remedy or limit the harmful effects of the offence, or has voluntarily reported it.
The Swedish International Sanctions Act has only been in force since June 2025, and there is therefore yet limited case law concerning its application, although there have been several preliminary investigations for sanctions violations.
Although the Swedish Sanctions Co-Ordination Council was established in 2024, a regulation formalising its role and functions came into force in 2026. Given the increased focus on sanctions circumventions, more developments are expected in the coming year.
The principal legislation governing national security in the defence sector in Sweden comprises the following.
Individuals participating in security-sensitive activities under the Protective Security Act must undergo security vetting before access is granted to the relevant activity. The scope of the vetting must be proportionate to the individual’s role and ordinarily includes basic investigation. Individuals holding positions classified within security classes require register checks and, for classes 1 and 2, a special personal investigation. Positions are assigned to classes based on the level of sensitive information accessible through the position in relation to the potential harm to national security if the information is disclosed.
The Swedish Security Service conducts the register checks but does not grant security clearance. The relevant employer or operator is responsible for the overall suitability assessment and the final decision on access. The vetting is a continuously ongoing process; access must be withdrawn if an individual no longer satisfies the applicable reliability, loyalty or vulnerability requirements.
Sweden does not have a general domestic facility-clearance regime. Entities conducting security-sensitive activities must undertake a security protection analysis and implement appropriate information, physical and personnel measures. Where a supplier, contractor or partner may gain access to security-sensitive activities, a written security protection agreement, sustainability assessment and consultation with the relevant supervisory authority may be required.
Supervision is exercised by the authorities designated under Chapter 8 of the Protective Security Ordinance.
Classified defence information is primarily regulated under the Protective Security Act, the Protective Security Ordinance, the Public Access to Information and Secrecy Act and an implementing regulation issued by the Swedish Security Service and the Swedish Armed Forces. Information is assigned one of four security classifications according to the potential harm to Sweden’s security if the information is disclosed. The classifications are Top Secret, Secret, Confidential and Restricted.
Access is generally granted on a need-to-know basis, where an individual must:
The relevant operator must implement information, physical and personnel measures preventing unauthorised disclosure, alteration, destruction or loss of access. Detailed requirements apply to storage, IT systems, communications, copying, transportation, destruction and incident reporting, depending on the information classification.
Before granting a contractor access to information classified as Confidential or above, or to activities of corresponding importance, a special security protection assessment must be conducted, and the parties must enter into a written security protection agreement. The agreement must regulate the contractor’s security obligations, following which the contractor is responsible for relevant compliancy.
There is no general single statutory designation of critical national infrastructure for defence assets in Sweden. Such assets and capabilities are protected though overlapping classification and regulatory regimes. Defence assets may constitute security-sensitive activities under the Protective Security Act. If the relevant activity constitutes a security-sensitive activity, the operator must:
The supervisory authority may prohibit a transfer or agreement that is unsuitable from a security protection perspective. The authority may also impose measures on valid agreements where a protective security aspect is of current relevance, although not relevant at the time of entry into force of the agreement.
Military facilities, installations, vessels and other strategically important assets may also be designated as protected objects under the Protection Act (2010:305). Such designation permits restrictions on access, photography and other activities and authorises specially appointed security guards to enforce the restrictions.
Lastly, investments in security-sensitive activities, military equipment and strategically protected technologies fall within the FDI regime. Relevant acquisitions are subject to mandatory notifications and may not be completed before obtaining clearance from ISP. Investments in security-sensitive activities may also be subject to a notification requirement under the Protective Security Act.
There is no general mandatory cybersecurity certification or accreditation scheme for defence contractors in Sweden equivalent to the US CMMC framework. The applicable requirements depend on the nature of the information and whether the relevant activities are security-sensitive under the Protective Security Act (2018:585).
Security-Sensitive Activities
Where a contractor handles security-classified information or otherwise participates in security-sensitive activities, the operator must, as applicable:
Security Clearances Issued by FMV
The Swedish Defence Materiel Administration (Försvarets materielverk; FMV) acts as Sweden’s Designated Security Authority for industrial security. It may issue Facility Security Clearances (FSCs) and Personnel Security Clearances (PSCs).
An FSC confirms that a contractor has entered into a Level 1 security protection agreement with FMV, and may handle and store classified information at premises approved by FMV. A PSC confirms that an individual is authorised to access classified information. These clearances may be issued following an application from a foreign state, an international organisation or a company established in Sweden.
FSCs and PSCs relate to specified classified activities. They are not general assessments of a contractor’s cybersecurity maturity and are therefore not directly equivalent to CMMC certification.
Cybersecurity Act and NIS2
Defence contractors may also fall within the Cybersecurity Act (2025:1506), which implements the NIS2 Directive in Sweden. An organisation covered by the Act must register with the competent supervisory authority, implement proportionate technical, operational and organisational cybersecurity measures, and report significant incidents.
The Act does not generally apply to a private operator that exclusively conducts security-sensitive activities or exclusively provides services to certain government authorities predominantly engaged in such activities. Such operators are instead subject to the Protective Security Act.
Procurement and Contractual Requirements
Contracting authorities may impose additional cybersecurity requirements in individual procurement procedures and contracts. These may include compliance with, or certification under, standards such as ISO/IEC 27001. Such certification is not, however, a general statutory requirement for participation in Swedish defence programmes.
Cybersecurity Act and NIS2
From 1 October 2026, entities covered by the Cybersecurity Act must assess and manage cybersecurity and continuity risks in their digital supply chains under MCFFS 2026:11. This includes obtaining relevant information about subcontractors, particularly where alternative suppliers are unavailable, and assessing cybersecurity risks arising from those subcontractors.
Defence Procurements
Within defence procurements under LUFS, contracting authorities and entities may require information relating to the supply chain, aiming to ensure that subcontractors have the capacity to protect security-sensitive information as well as commitments and documentation to ensure security of supply requirements, also in a crisis.
Under the Protective Security Act, when a business carries out security-sensitive operations, particular care must be taken to ascertain that it protects information, assets and activities against espionage, sabotage, terrorist offences and other threats deemed necessary for the particular business operations deemed as security-sensitive. A notification must be urgently sent to the Security Services in the case of certain events, such as:
Mitigation in relation to foreign ownership, control and influence over defence sector entities is available through the FDI Act and the Protective Security Act in relation to investments, and through the Protective Security Act in relation to clearance to handle security-sensitive information. If issues are raised in relation to an investigation, ISP may impose commitments on the investor to mitigate identified risks under the FDI Regime. The relevant supervisory authority under the Protective Security Act may also impose conditions to approve an investment. Relevant commitments may include:
Refer to the previous sections in 5. National Security Regulation.
In Sweden, foreign direct investments are governed by the FDI Act and the Ordinance (2023:624) on Screening of Foreign Direct Investments. The regime applies to both direct and indirect investments in “protected activities” conducted by entities domiciled in Sweden.
“Protected activities” are broadly defined under Section 3 of the FDI Act, and include:
ISP is the designated screening and supervisory body.
There is no separate screening procedure for transactions in the defence sector. Such transactions are subject to the standard FDI screening process, provided that the target company’s business activities fall within the definition of “protected activities” under Section 3 of the FDI Act and constitute a covered type of transaction.
Notification is required where a transaction results in, among other things, the following:
It is important to note that the notification obligation applies to Swedish and foreign investors alike, and the regime also covers intra-group reorganisations.
Notification is mandatory for all transactions within the scope of the Swedish FDI Act, with only one limited exemption in relation to issuance of shares. Failure to notify, and implementation before a clearance decision, may be subject to fines of up to SEK100 million. If the transaction is prohibited, the legal actions implementing said transaction may be declared invalid and forced to be divested.
The review period for a notification is 25 business days from submission of a complete notification in Phase 1, whereby the authority will either clear the transaction or initiate an in-depth review (Phase 2). If an in-depth review is initiated, such review must generally be completed within three months of its initiation. Where a special ground exists, the review period may be extended to a maximum of six months. Notifiable transactions are subject to a standstill obligation and may not be completed before the transaction has been cleared.
The notification must be submitted by the investor, using the forms provided by ISP and required annexes. The notification must include, among other things:
ISP provides only limited public guidance on how individual factors are assessed, as case-specific information is generally confidential. The following parameters are central to the assessment under the FDI Act:
The assessment is conducted on a case-by-case basis, and the legislation does not prescribe an exhaustive list of relevant factors or fixed criteria automatically resulting in prohibition.
There are no separate remedies available for transactions in the defence sector. ISP may grant clearance subject to conditions necessary to prevent the transaction from adversely affecting security, public order or public security in Sweden. Such conditions may relate to:
The statutory framework permits transaction-specific behavioural, governance and control-related commitments, but does not prescribe an exhaustive catalogue of remedies or a standard form of security agreement.
ISP may prohibit an investment where prohibiting is necessary to prevent the relevant adverse effects. An investment previously approved subject to conditions may also be prohibited if the relevant conditions are breached. Legal acts implementing a prohibited investment are deemed null and void. Compliance may also be enforced through injunctions, conditional penalties and administrative sanctions.
If ISP initiates a review of a transaction not subject to the notification requirement and finds the transaction to have an adverse effect on security, public order or public security in Sweden, ISP may require the transaction to be unwound.
Sweden does not have a general “golden share” regime or equivalent statutory special shareholder rights.
There are no separate regulatory FDI requirements or restrictions applicable to the formation of joint ventures in Sweden. Joint ventures are subject to the standard FDI screening process, provided that the relevant business activities are within the scope of the FDI Act.
However, separate sector-specific requirements may apply. A joint venture in the defence sector may, for example, require certain authorisation to manufacture or supply military equipment. If the joint venture will conduct security-sensitive activities, appropriate protective-security measures may be required before a foreign partner is granted access to the joint venture.
The FDI regime does not generally regulate the allocation of intellectual property (IP), although such assets may be within scope of the FDI regime depending on the circumstances. Technology transfer and IP ownership are generally addressed contractually, including ownership of background and newly developed IP, licensing and sublicensing rights, permitted fields of use, confidentiality, access restrictions and rights following termination. Any contractual access or transfer remains subject to applicable protective-security restrictions. However, conditions may be imposed relating to IP rights.
The merger control regime and the FDI regime are based on different interests to be assessed. The merger control regime has inspired the procedural aspects of the FDI Act, but there is generally no co-operation or co-ordination mechanism between the relevant authorities.
Each relevant authority will therefore base its decision on either competition law considerations or national security considerations. If one of the relevant required clearances is not granted or fulfilled, the transaction may not be closed although the practical management of such a situation may be different.
There are a number of Swedish authorities with supervisory powers in the defence and security field, for sanctions, protective security, etc. Only a few examples are mentioned below.
The Swedish Competition Authority supervises contracting authorities’ and entities’ compliance with the Act on Public Procurement in the Defence and Security Area. It has the power to decide that a procurement sanction fee shall be imposed on the contracting authority or entity.
ISP grants licences for and monitors the exportation of military equipment and dual-use products, and reviews foreign direct investments. It may request information and documents, conduct inspections, issue compliance orders, and suspend or revoke authorisations.
Swedish Customs monitors cross-border movements and investigates suspected smuggling involving military equipment, sanctioned goods and dual-use items.
The Police, the Security Service and the Swedish Prosecution Authority investigate suspected criminal offences concerning sanctions, unlawful exports and threats to national security. Subject to the ordinary statutory thresholds, they may conduct interviews, search premises, seize evidence and use other coercive measures.
There are many ways that investigations may be triggered – eg, by whistle-blower reports, incident notifications, intelligence from security services, customs inspections, discrepancies in export documentation, regulatory supervision, or inconsistencies in applications and regulatory filings.
There are a number of authorities with investigative powers in this field; not all defence-related matters are governed by a single legislative framework. Generally, authorities may require the disclosure of information and documents for their investigations and may require access to premises.
ISP has specific powers in connection with the screening of foreign direct investments and licence-holders under the Military Equipment Act and the dual-use items regulations. The power includes requesting information and documents in order to assess notifications and conduct supervisory tasks. ISP may also access premises where relevant business is conducted; such access rights are associated with its supervisory activities and not with criminal investigative powers.
Defence sector entities are not exempt from dawn raids under Swedish competition law. The entity is obliged to co-operate, provide access to offices or transports, provide relevant records and refrain from obstructing the inspection. The Swedish Competition Authority may therefore conduct inspections following authorisation by the Patent and Market Court, where a defence undertaking is suspected of an infringement, such as bid rigging. Any inspection involving security classified information or sensitive premises must, however, be conducted in accordance with security protection requirements.
ISP may also carry out unannounced inspections in exercising its supervisory powers under the Military Equipment Act and the dual-use items regime.
Swedish law provides strong protection for confidential communications with members of the Swedish Bar Association, but its scope depends on the procedural rules applicable to the relevant investigation.
For example, documents whose contents are protected by the statutory restriction on examining an advocate as a witness are protected from measures taken by the Swedish Competition Authority. Any dispute concerning whether a document is protected is determined by the Patent and Market Court.
In relation to supervisory activities from ISP and other authorities, the general rule on legal professional privilege in the Code of Judicial Procedure applies, and a distinction should be made between documents that may be included and documents which there is a legal obligation to provide in response to such a request.
A regulatory breach or a criminal conviction may lead to exclusion from future procurements in the defence and security field. If the criminal conviction relates to certain specified offences, exclusion of the tenderer is mandatory unless there are exceptional reasons. Other regulatory breaches or offences could result in exclusion of the tenderer. Please refer to 2.10 Exclusion Grounds for further details.
Disputes concerning defence and security contracts are generally resolved by:
Sweden has no defence-specific whistle-blower regime. The Swedish Whistle-Blower Act (2021:890) does not apply to reporting of:
Please refer to 3.9 Enforcement, Penalties and Voluntary Disclosure, 4.1 Sanctions Legislation and Regulatory Framework and 4.7 Enforcement, Penalties and Voluntary Disclosure.
PO Box 1670
SE-111 96 Stockholm
Sweden
+46 522 065 00
+46 8 522 067 00
advokat@cederquist.se www.cederquist.se
Sweden: Where Total Defence Is a Matter for the Entire Population
Introduction to the Swedish concept of “total defence”
The opening provision of the Total Defence Service Act – the statute under which individual citizens may be required to serve in the armed forces – states:
“Total defence is a matter for the entire population.”
This concise statutory statement captures how Sweden approaches both national defence and defence law. The same spirit runs through many of the nearly 50 legal instruments that together form the legal framework for Sweden’s total defence.
One of the principal statutes in this field, the Total Defence and Heightened Readiness Act, defines total defence as all activities necessary to prepare Sweden for war, whether undertaken by public or private actors and whether military or civilian in nature. In short, Sweden’s total defence is, in both practical and legal terms, a matter of public concern in which all actors sustaining essential societal functions – public and private alike – are expected to participate and assume responsibility.
The military component of Sweden’s total defence follows a traditional hierarchical structure. Commander-in-Chief Michael Claesson is the highest-ranking officer and reports only to the government.
The civil component of total defence has a considerably more complex organisational structure. Civil defence is divided into 12 sectors which, collectively, are intended to cover the societal functions Sweden requires for an effective defence. These sectors are:
Each sector has a designated sector-responsible authority, together with a number of so-called emergency preparedness authorities. These authorities are responsible for leading efforts to strengthen total defence capabilities within their respective sectors, both within the authorities themselves and among other public and private actors.
The form this work takes varies depending on the authority responsible for the sector. Matters governed by legislation or regulation in one sector may be addressed through soft law or voluntary agreements in another. A significant amount of preparedness work is also cross-sectoral.
Taken together, these features can make it difficult to obtain a clear overview of both the legal framework and the administrative structure of Sweden’s total defence. The Swedish Civil Defence and Resilience Agency therefore has an overarching role in co-ordinating the civil defence system, and regularly issues guidance and other support to assist public authorities and private entities with their total defence work.
“Just in Time” Is Too Late
The peacetime mission of total defence is as easy to state as it is difficult to carry out. Actors operating within any of the 12 preparedness sectors must, individually and collectively, take the measures and undertake the planning necessary to make the functions critical to total defence in each sector more robust and resilient in the event of an invasion of Swedish territory or acts of war in neighbouring countries.
In addition to the basic requirements for each entity to establish a wartime organisation, conduct a risk and vulnerability analysis, and regularly undertake scenario-based exercises, this also entails preparing a so-called supply analysis. In such an analysis, entities identify the dependencies on which their ability to continue operating would rely under conditions of severe trade disruption. In practice, this means ensuring that they can maintain their operations – at least at a basic level – even without relying on resources located outside Sweden.
For the vast majority of companies, establishing the domestic capacity required for security of supply presents a major challenge. Companies whose operating models rely on “just-in-time” deliveries and “follow-the-sun” support are being forced to reconsider their strategies and establish a stronger local presence and capability. The rebuilding of Sweden’s total defence now under way is, in this respect, a disruptive force across society.
For companies seeking to retain a more traditional, global operating model, the concept of total defence presents a genuine challenge. For companies able to adapt their organisation and establish a stronger local presence, however, Sweden’s total defence structure offers the kinds of commercial opportunities associated with major economic paradigm shifts.
Cold War-Era Legislation, Revamped
The concept of total defence has deep roots, and Sweden has organised its defence on this basis since at least the Second World War. The concept assumes that Russia is the principal adversary, and is designed to prepare Sweden for the kind of protracted invasion war now being fought in Ukraine.
Between the fall of the Berlin Wall and Russia’s annexation of Crimea, however, the concept of total defence lay dormant. The legislation governing total defence remained on the books but was not applied in practice for nearly 25 years.
Now that this legislation is being reactivated, much of it appears outdated and poorly suited to the activities that constitute modern total defence. Much has changed since 1989.
Firstly, tasks relevant to total defence are now carried out to a far greater extent by private companies. Secondly, those companies are far more likely to be international or global businesses. Thirdly, the services they provide are significantly more complex and increasingly dependent on highly specialised international expertise.
Cold War-era total defence legislation is plainly insufficient to address the complexities of modern business, and intensive legislative work is under way across all sectors to modernise the existing rules. At the same time, there is a reluctance to begin again from a blank sheet of paper.
Russia’s full-scale invasion of Ukraine has underscored the urgency of rebuilding Sweden’s total defence capabilities, and there is simply no time to reconstruct the entire system from the ground up. The approach has therefore been to preserve as much as possible of the legal structures inherited from the Cold War, while updating them where necessary to reflect the present-day defence policy and economic environment.
One of the principal challenges in this modernisation effort is to develop a contemporary equivalent of what was known as the “K-company”.
Agreements Come First
Although a legislative framework exists, Sweden’s concept of total defence has always relied heavily on voluntary participation. At its height, the Swedish total defence system included – in addition to public-sector actors – an estimated 11,000 private companies that had voluntarily committed themselves to total defence planning. These companies, known as “K-companies”, had entered into agreements under which they undertook to make their resources available to the defence effort in various ways in the event of heightened readiness or war.
The voluntary nature of these arrangements is, of course, open to debate. As is often the case in the Swedish legal tradition, the State will generally first seek to reach an agreement. If no agreement can be reached, however, it will not hesitate to legislate.
The same approach is being followed today. Each sector-responsible authority first considers whether the desired total defence capability can be secured through a so-called preparedness agreement, or “F-agreement”. Only if this route proves insufficient may legislation be used to impose obligations on the companies concerned.
There are several reasons for preferring this approach. A negotiated agreement defining how a particular company is to contribute to total defence can take account of that company’s specific circumstances in a way that general legislation cannot. Contractually agreed preparedness may therefore be significantly more cost-effective than preparedness imposed solely through legislation.
An agreement also creates better conditions for the company to develop a genuine commitment to defence preparedness and to focus its resources on building the greatest possible defence capability. Legislation, by contrast, tends to direct a company’s resources towards compliance rather than capability enhancement. This can create a false sense of preparedness where the underlying capability is, in fact, absent.
There is also a clear commercial opportunity. Companies that are early in offering their capabilities under F-agreements may help shape the standards governing how such agreements should be structured. Those companies may therefore not only influence the terms applicable to their own operations but also contribute to the development of standards for their wider industry – standards that may ultimately inform future legislation or regulatory practice.
The Digital Dimension
The largest gap between the assumptions underpinning the older preparedness system and modern commercial reality may be found in IT services. Sweden is a highly digitalised economy, and critical functions increasingly depend on Software as a Service (SaaS) applications, cloud infrastructure, identity platforms, data centres, managed services, telecommunications and globally distributed support organisations.
This reveals a fundamental paradox at the heart of modern total defence. The technologies that have made Swedish society more efficient have, in some respects, also made resilience more difficult to engineer. Cloud services are not inherently at odds with resilience. Large providers may offer levels of technical security, redundancy and operational expertise that individual customers could not reproduce. The problem is not merely that a service is external; it is that the customer’s ability to understand, influence and replace that service may be limited at precisely the moment when control matters most.
Traditional preparedness planning typically began with tangible assets and dependencies: a factory, a warehouse, a vehicle fleet, a local workforce or a defined stock of goods. A modern digital service may instead depend on an international chain of data centres, software components, identity services, telecommunications networks, subcontractors and remote support teams. These digital dependencies are both less visible and more difficult to control.
For total defence purposes, the relevant question is therefore no longer merely where the servers are located or where the data is stored. The more difficult questions concern who actually controls the service, which dependencies exist further down the supply chain, where the personnel required to operate and restore the service are located, and whether the customer can continue operating if connectivity or access to external resources is severely disrupted. A service may, for example, store all its data in Sweden while essential administration, updates or incident response are carried out elsewhere. Data localisation can reduce one category of risk without delivering genuine operational sovereignty.
This is also where total defence increasingly intersects with NIS2 and the Critical Entities Resilience Directive, or CER. The three frameworks address related problems, but they do so from different perspectives.
Sweden’s Cybersecurity Act, which implements NIS2, focuses primarily on cybersecurity and the security of network and information systems. It requires covered entities to address, among other matters, business continuity, crisis management and supply-chain security. CER takes a broader, all-hazards approach to the resilience of critical entities and their ability to maintain essential services. Total defence poses a further and ultimately more demanding question: what must continue to function under conditions of heightened readiness and, ultimately, war?
The frameworks are deliberately connected, but overlap does not amount to equivalence. An organisation may comply with its cybersecurity obligations and still lack the operational resilience required for total defence purposes. Conversely, measures taken as part of total defence planning may also contribute to compliance with NIS2 or CER. The Protective Security Act may add a further layer where Sweden’s national security is directly engaged.
For companies and public authorities, the result is an increasingly complex contractual landscape. A single IT service, outsourcing arrangement or cloud relationship may fall within several legal frameworks at once. More importantly, the organisation bearing the regulatory or preparedness obligation may not itself control the technical capability on which its compliance depends. That capability may instead reside with a cloud provider, a SaaS supplier or a subcontractor several steps down the supply chain.
This makes contractual design particularly important. A generic requirement that the supplier comply with applicable law is plainly insufficient. Customers increasingly need visibility into relevant dependencies, timely access to information, clear escalation routes, incident co-operation, continuity commitments and appropriate control over critical subcontracting arrangements. In this sense, the agreement becomes the means by which the customer seeks to extend its resilience requirements into the supplier’s organisation and supply chain.
SaaS services illustrate the difficulty particularly clearly. The commercial logic of SaaS is based on standardisation and scale. The supplier operates a common service for a large number of customers and retains extensive control over the underlying software, infrastructure, subcontractors and product roadmap. The customer benefits from an efficient and continuously updated service, but has comparatively little operational control.
That model can sit uneasily with some of the assumptions underpinning total defence. A supplier may deliver excellent availability under normal conditions while being unable to guarantee that a Swedish customer will receive priority access to scarce capacity or specialist personnel during a major international crisis. A function may also fail because a separate identity provider, network connection or integration is unavailable, even though the SaaS platform itself remains operational.
A multi-cloud strategy does not necessarily solve the problem either. Two cloud environments do not provide genuine redundancy if both depend on the same telecommunications provider, identity layer, management tools or limited pool of specialist personnel. Resilience requires an understanding of common dependencies, not merely a larger number of suppliers.
None of this suggests that Sweden should seek to reverse decades of digitalisation or eliminate international dependencies. Such an approach would be neither realistic nor necessarily conducive to greater resilience. Sweden’s defence is now embedded in NATO, the Nordic region and the EU, and resilience can be built through trusted interdependence as well as through domestic capacity. For many systems and workloads (but not all), large cloud and SaaS providers may also offer levels of cybersecurity, redundancy and specialist expertise that individual Swedish organisations could not reasonably reproduce. There are therefore compelling reasons for cautious optimism.
Firstly, NIS2, CER and renewed total defence planning are forcing organisations to identify dependencies that have historically remained hidden within technical architectures and supply chains. It is difficult to build resilience around a dependency that no one has identified. Greater visibility is therefore an essential first step.
Secondly, contractual practice is developing. Matters that were previously treated as technical details – subcontracting, data location, continuity, recovery, portability and access to key personnel – are increasingly becoming substantive negotiation issues. Customers are beginning to procure continuity, portability and tested recovery as characteristics of the service itself, rather than relying on general assurances about resilience.
Thirdly, digitalisation can itself form part of the solution. Properly designed cloud architectures can provide geographic redundancy, rapid restoration and distributed capacity that would have been impossible under older infrastructure models. The problem is not digitalisation as such but unmanaged concentration and dependency.
Not every system requires sovereign infrastructure or an offline alternative; the most critical systems may. The essential point is that this distinction is made consciously, that hidden dependencies are understood and that the required capability is actually tested.
The task is not to recreate the analogue resilience of the past. Sweden cannot, and should not, reverse decades of digitalisation. The task is instead to build a form of digital resilience capable of supporting modern total defence.
The EU Dimension
There is a natural tension between EU law and Swedish total defence law. Total defence is, and will remain, a national responsibility. Article 4 of the Treaty on European Union recognises national responsibility for security matters. At the same time, there are clear geopolitical advantages to the Europeanisation of defence. Although the EU is not yet a fully fledged defence union, it is increasingly becoming a preparedness union.
This creates a challenge for Sweden’s total defence efforts. Every agreement entered into and every decision taken within the framework of total defence must be assessed for compatibility with EU law, particularly procurement law and state aid law. Peacetime total defence activities must be conducted in a manner consistent with EU law.
At the same time, it is clear that the EU is seeking to address this tension. One example is the European Commission’s updated decision on services of general economic interest, or SGEI, which expressly supports the development of national preparedness in relation to critical medical products. Another important development is the increasing scope within public procurement to exclude non-European alternatives.
For Swedish authorities, the challenge is therefore not simply to maximise national autonomy but to build a total defence capability that is both operationally credible and legally compatible with Sweden’s obligations as an EU member state.
What Comes Next for Sweden?
We are living through a period of rapid and far-reaching change. In this environment, the role of defence law is to provide the structure and predictability required for the investments on which total defence depends. The next three years will be marked by intense legislative activity and a significant increase in the expectations placed on private companies carrying out activities critical to Swedish society.
At the same time, this shift – and the willingness to invest that accompanies it – presents significant commercial opportunities for companies capable of responding quickly to the expectations of total defence. As ever, whether this change is perceived as a challenge or an opportunity depends on one’s perspective.
Katarinavägen 9 C
PO Box 4047
102 61 Stockholm
Sweden
+46 8 121 502 20
info@kahnpedersen.se kahnpedersen.se/