2025-12-102025/26:FöU2 · p.6FöUDefence
Development of cyberpolicy
Development of cyber policy and build-out of cyber defence
What's at stake: Cyberattacks on functions critical to society, such as electricity supply, payment systems and healthcare, can have serious consequences for people's daily lives and for national security. The decision affects how much further Parliament chooses to push for continued build-out of the state's cyber-defence capability beyond the legislation now being introduced.
Case texts and AI reasoning are AI-translated from the Swedish originals; the Swedish text is authoritative.
What the vote decides
The question is whether Parliament should make an additional statement calling for further strengthening of Sweden's cyber defence and cybersecurity work, beyond what the new cybersecurity law (implementing the EU's NIS2 directive) already provides, or whether the legislative proposal is considered to already meet that need.
Yes Yes — the committee proposal
The committee considers that motion 2025/26:3556, item 97, on the development of cyber policy, is met by the government's proposed new cybersecurity law, which implements the NIS2 directive and raises the ambition level for cybersecurity work, and therefore rejects the motion.
No No — the reservations
Reservation 5 (S)
The reservation (S) calls on Parliament to declare to the government that Sweden's cyber defence and shared preparedness against cyberattacks must be strengthened further. The reasoning is that cyberattacks by both criminal actors and foreign states are growing in scale and can hit functions critical to society, such as food supply, payment systems, electricity and healthcare, as hard as a conventional armed attack; it points to measures already taken, such as a national cybersecurity centre, a cyber-defence centre at KTH, and military training of cyber soldiers, that should be built on further, along with stronger redundancy in payment and cash-handling systems.
Summarised from the committee report. Party labels in the summary come from the report, not from the vote.
What do the votes mean here?
Yes The committee proposal: rejecting the motions (keeping things as they are).
No Backing the counter-proposal: reservation 5 by S.
Abstain The party marks a position of its own that is not one of the two final alternatives.
The decision would have gone the other way
Explicit commitments that contradicted the vote: KDKristdemokraterna, MModeraterna
Ja 199–92Nej 125–166
Counterfactual: the parties above are moved to the position their own documents explicitly point at, carrying their whole contingent present. Every other party keeps its real figures, including dissenters and absentees.
How the AI parties would have voted
For each party: what its own plan – election manifesto and party programme – argues for in this case, next to how the party actually voted. The AI can only answer Yes or No; a party can also abstain.
| AI | Vote | Confidence | Evidence | ||
|---|---|---|---|---|---|
| V | No | Yes 18/0/0/4 | differs | confidence: medium | not addressed |
| S | No | No 0/92/0/14 | match | confidence: high | explicit |
| MP | No | Yes 14/0/0/4 | differs | confidence: medium | not addressed |
| C | No | Yes 19/0/0/5 | differs | confidence: medium | not addressed |
| L | No | Yes 13/0/0/3 | differs | confidence: medium | not addressed |
| KD | No | Yes 15/0/0/4 | differsagainst own programme | confidence: medium | explicit |
| M | No | Yes 59/0/0/9 | differsagainst own programme | confidence: high | explicit |
| SD | No | Yes 61/0/0/11 | differs | confidence: medium | derived |
Committee proposal
The Riksdag rejects the motion 2025/26:3556 by Peter Hultqvist et al. (S) item 97.
Original (Swedish)
Riksdagen avslår motion 2025/26:3556 av Peter Hultqvist m.fl. (S) yrkande 97.
Riksdag decision: To achieve a high cybersecurity level in society, the government proposes a new cybersecurity law aimed at implementing the so-called NIS 2 directive. The Riksdag approved the government's proposal. The proposal means that public and private operators in certain designated sectors are to take measures to protect their networks and information systems and report significant incidents. The proposal also means that a supervisory authority is to intervene if an operator breaches provisions in the law. The NIS 2 directive was decided by the EU in 2022 and aims to achieve a high common cybersecurity level throughout the union. The Riksdag also approved the government's proposal to amend other laws concerning electronic communications, top-level domains, and confidentiality. The new rules enter into force on 15 January 2026.
Counter-proposals
- The counter-proposal wants to strengthen Swedish cyber defense and society's capacity to meet cyber threats through continued investments in IT and cybersecurity, military cyber capacity, and redundancy in payment and cash systems. (S) — Reservation 5
Plan vs actual vote
Every party, in chamber order: what its own plan pointed to, how it voted, and the reasoning behind both. Highlighted rows are where the two differ — but a vote that follows the plan is a result too, so the reasoning is there for every party.
The plan wants to see a robust total defence with broad capacity to meet various forms of crises and requires strengthened preparedness for crises, disasters and war.
Plan documents: party programme
Reasoning and quotes
The plan wants to see a robust total defence with broad capacity to meet various forms of crises and requires strengthened preparedness for crises, disasters and war. Protection of socially vital functions such as electricity supply, payment systems and healthcare against cyberattacks is civil crisis preparedness rather than military rearmament, and thus lies within the plan's ambition. The documents do not explicitly mention cyber defence, so the position is derived from the preparedness commitment.
Original (Swedish)
Planen vill se ett robust totalförsvar med bred förmåga att möta olika former av kriser och kräver stärkt beredskap inför kriser, katastrofer och krig. Skydd av samhällsviktiga funktioner som elförsörjning, betalningssystem och sjukvård mot cyberangrepp är civil krisberedskap snarare än militär upprustning, och ligger därmed inom planens ambition. Dokumenten nämner inte cyberförsvar uttryckligen, så ställningstagandet härleds ur beredskapsåtagandet.
- broad crisis preparednessdecisive»bred förmåga att möta olika former av kriser Sverige kan ställas inför.« (party programme ↗)“broad capacity to meet various forms of crises Sweden could face.”
- strengthened preparedness»och stärka beredskapen inför kriser, katastrofer och krig.« (party programme ↗)“and strengthen preparedness for crises, disasters and war.”
- strategic technology policy»Sverige behöver ett medvetet och strategiskt förhållningssätt till« (party programme ↗)“Sweden needs a conscious and strategic approach to”
The plan takes no explicit position on what the committee actually decided — often because the committee's reason was procedural. The stance is derived and fully cited, but it does not show the party broke a commitment.
The plan explicitly establishes that cyber defense and intelligence capability shall be developed and that the capacity to withstand cyberattacks shall be strengthened.
Plan documents: 2022 manifesto · party programme
Reasoning and quotes
The plan explicitly establishes that cyber defense and intelligence capability shall be developed and that the capacity to withstand cyberattacks shall be strengthened. It also requires preparedness against hybrid attacks and strong infrastructure for preparedness, which covers the demand for redundancy in payment and cash handling. The counter-proposal's demand for further strengthened cyber defense thus follows directly from the plan.
Original (Swedish)
Planen slår uttryckligen fast att cyberförsvaret och underrättelseförmågan ska utvecklas och att förmågan att stå emot cyberangrepp ska stärkas. Den kräver också beredskap mot hybridattacker och en stark infrastruktur för beredskap, vilket täcker kravet på redundans i betalnings- och kontanthantering. Motförslagets krav på ytterligare stärkt cyberförsvar följer därmed direkt av planen.
- developed cyber defensedecisive»Vi vill fortsätta internationella samarbeten och utveckla cyberförsvaret och underrättelseförmågan.« (2022 manifesto ↗)“We want to continue international cooperation and develop cyber defense and intelligence capability.”
- strengthened resilience against cyberattacks»Arbetet för att stärka förmågan att stå emot cyberattacker och desinformation ska stärkas.« (2022 manifesto ↗)“Work to strengthen the capacity to withstand cyberattacks and disinformation shall be strengthened.”
- preparedness against hybrid threats»Beredskap mot hybridattacker.« (party programme ↗)“Preparedness against hybrid attacks.”
- robust societal infrastructure»Stark infrastruktur för stärkt beredskap.« (party programme ↗)“Strong infrastructure for strengthened preparedness.”
The plan has a broad security approach and requires that society secures control over critical infrastructure so that welfare, communication, water, energy production and power networks function in crisis.
Plan documents: party programme · 2022 manifesto
Reasoning and quotes
The plan has a broad security approach and requires that society secures control over critical infrastructure so that welfare, communication, water, energy production and power networks function in crisis. The counter-proposal's requirements for continued strengthened cyber defence and increased redundancy in payment systems is an application of the same commitment. The plan therefore supports the demand in substance, even if cyber threats are not mentioned explicitly.
Original (Swedish)
Planen har en bred säkerhetssyn och kräver att samhället säkrar kontroll över kritisk infrastruktur så att välfärd, kommunikation, vatten, energiproduktion och elnät fungerar i kris. Motförslagets krav på fortsatt stärkt cyberförsvar och ökad redundans i betalningssystemen är en tillämpning av samma åtagande. Planen stöder därmed kravet i sak, även om cyberhot inte nämns uttryckligen.
- protection of critical infrastructuredecisive»Samhället måste säkra kontroll över kritisk infrastruktur och att välfärd, kommunikation, vatten, energiproduktion och elnät fungerar i krissituationer.« (party programme ↗)“Society must secure control over critical infrastructure and that welfare, communication, water, energy production and power networks function in crisis situations.”
- strengthened crisis preparedness»Därför måste det civila försvaret stärkas, så att både Sveriges och EU:s krisberedskap är rustade för att kunna möta olika typer av hot.« (party programme ↗)“Therefore civil defence must be strengthened, so that both Sweden's and the EU's crisis preparedness are equipped to meet different types of threats.”
- increased appropriations for crisis preparedness»satsa en större andel av försvarets pengar på det civila försvaret, och öka anslagen till krisberedskap.« (2022 manifesto ↗)“allocate a larger share of the defence budget to civil defence, and increase appropriations for crisis preparedness.”
- broad security approach»Miljöpartiet har en bred syn på säkerhet och trygghet.« (party programme ↗)“The Green Party has a broad view of security and safety.”
The plan takes no explicit position on what the committee actually decided — often because the committee's reason was procedural. The stance is derived and fully cited, but it does not show the party broke a commitment.
The election manifesto makes upgrading civil defence and society's preparedness for war and crisis an explicit commitment, and the party programme requires that defence capability be adapted after new threats that don't come only from states.
Plan documents: 2022 manifesto · party programme
Reasoning and quotes
The election manifesto makes upgrading civil defence and society's preparedness for war and crisis an explicit commitment, and the party programme requires that defence capability be adapted after new threats that don't come only from states. Cyberattacks against electricity supply, payment systems and healthcare are precisely such a threat to society-critical functions. The counter-proposal's demands for strengthened cyber defence and redundancy in payment systems therefore follow from the plan.
Original (Swedish)
Valmanifestet gör upprustningen av civilförsvaret och samhällets beredskap inför kris och krig till ett uttryckligt åtagande, och partiprogrammet kräver att försvarsförmågan anpassas efter nya hot som inte kommer från stater enbart. Cyberangrepp mot elförsörjning, betalningssystem och sjukvård är just ett sådant hot mot samhällsviktiga funktioner. Motförslagets krav på stärkt cyberförsvar och redundans i betalningssystemen följer därför av planen.
- strengthen civil preparednessdecisive»Även det civila försvaret är livsviktigt. Vi måste rusta civilförsvaret och samhällets beredskap inför krig och kris.« (2022 manifesto ↗)“Civil defence is also vital. We must strengthen civil defence and society's preparedness for war and crisis.”
- defence against new threats»Därför måste vi också anpassa vår försvarsförmåga efter nya hot mot landet.« (party programme ↗)“Therefore we must also adapt our defence capability after new threats to the country.”
- protection of democracy against external threats»Sverige måste rustas snabbt och fokuserat; ingen ska kunna ta vårt demokratiska samhälle ifrån oss.« (2022 manifesto ↗)“Sweden must be armed quickly and in a focused way; no one shall be able to take our democratic society from us.”
- legal society in digital sphere»Samtidigt måste rättssamhället finnas även i den digitala sfären.« (party programme ↗)“At the same time, the legal society must also exist in the digital sphere.”
The plan takes no explicit position on what the committee actually decided — often because the committee's reason was procedural. The stance is derived and fully cited, but it does not show the party broke a commitment.
The plan requires that total defence is strongly strengthened and that civil defence is built up at the same pace as military defence, while cross-border criminality should be met with cross-border policing.
Plan documents: party programme · 2022 manifesto
Reasoning and quotes
The plan requires that total defence is strongly strengthened and that civil defence is built up at the same pace as military defence, while cross-border criminality should be met with cross-border policing. Continued expanded cyber defence and strengthened redundancy in societally critical functions is an application of these commitments. The plan thus argues for the counter-proposal's requirements.
Original (Swedish)
Planen kräver att totalförsvaret stärks kraftigt och att det civila försvaret byggs ut i samma takt som det militära, samtidigt som gränsöverskridande brottslighet ska mötas med gränsöverskridande polisarbete. Ett fortsatt utbyggt cyberförsvar och stärkt redundans i samhällsviktiga funktioner är en tillämpning av dessa åtaganden. Planen talar därför för motförslagets krav.
- strongly strengthened total defencedecisive»I ett säkerhetspolitiskt läge som är det svåraste sedan andra världskrigets slut behöver Sveriges totalförsvar stärkas kraftigt.« (party programme ↗)“In a security policy situation that is the most serious since the end of World War II, Sweden's total defence needs to be strongly strengthened.”
- civil defence at the same pace»det civila försvaret stärkas i samma takt som det militära« (2022 manifesto ↗)“civil defence is strengthened at the same pace as military defence”
- cross-border crime prevention»Gränsöverskridande brottslighet måste mötas med en gränsöverskridande polis.« (2022 manifesto ↗)“Cross-border criminality must be met with cross-border policing.”
- protection of societally critical infrastructure»Den utveckling där odemokratiska eller rentav totalitära stater förvärvar strategiska tillgångar i demokratiska länder, till exempel hamnar, elnät eller liknande, måste ses i ett säkerhetspolitiskt perspektiv.« (party programme ↗)“The development where undemocratic or even totalitarian states acquire strategic assets in democratic countries, such as ports, power grids or similar, must be seen from a security policy perspective.”
The plan takes no explicit position on what the committee actually decided — often because the committee's reason was procedural. The stance is derived and fully cited, but it does not show the party broke a commitment.
The plan establishes that new types of threats create an expanded security concept and that Sweden must be able to meet attacks including cyber warfare, and that the country in principle must be able to provide for the population's food and energy supply.
Plan documents: party programme
Reasoning and quotes
The plan establishes that new types of threats create an expanded security concept and that Sweden must be able to meet attacks including cyber warfare, and that the country in principle must be able to provide for the population's food and energy supply. The counter-proposal's requirement for strengthened cyber defence and redundancy in vital social functions is precisely this commitment. The plan also requires that total defence has sufficient resources.
Original (Swedish)
Planen slår fast att nya typer av hot ger ett vidgat säkerhetsbegrepp och att Sverige måste kunna möta angrepp i form av bland annat cyberkrigföring, samt att landet i princip ska kunna svara för befolkningens livsmedels- och energiförsörjning. Motförslagets krav på stärkt cyberförsvar och redundans i samhällsviktiga funktioner är just detta åtagande. Planen kräver också att totalförsvaret har tillräckliga resurser.
- meet cyber attacksdecisive»Sverige måste kunna möta angrepp från internationell kriminalitet, terrorism,« (party programme ↗)“Sweden must be able to meet attacks from international crime, terrorism,”
- expanded security concept»Nya typer av konflikter och hot leder till ett vidgat säkerhetsbegrepp.« (party programme ↗)“New types of conflicts and threats lead to an expanded security concept.”
- supply chain resilience»kunna svara för befolkningens livsmedels och energiförsörjning samt hålla en god beredskap« (party programme ↗)“be able to provide for the population's food and energy supply and maintain good resilience”
- resources for total defence»Det samlade totalförsvaret måste ha tillräckliga resurser för att kunna garantera« (party programme ↗)“The overall total defence must have sufficient resources to guarantee”
The stance rests on the quoted commitment in the party's own documents; the actual vote deviated. Click the quote to verify it in the document.
The plan explicitly promises to develop cyber defence and to introduce an action plan with concrete measures against hybrid threats and cyber attacks.
Plan documents: 2022 manifesto
Reasoning and quotes
The plan explicitly promises to develop cyber defence and to introduce an action plan with concrete measures against hybrid threats and cyber attacks. It also establishes that the military defence cannot solve its tasks if civil defence does not work, which is precisely the counter-proposal's point about functions vital to society. The demand for continued development of cyber policy is therefore in line with the plan.
Original (Swedish)
Planen lovar uttryckligen att utveckla cyberförsvaret och att införa en handlingsplan med konkreta åtgärder mot hybridhot och cyberattacker. Den slår också fast att det militära försvaret inte kan lösa sina uppgifter om det civila försvaret inte fungerar, vilket är precis motförslagets poäng om samhällsviktiga funktioner. Kravet på fortsatt utveckling av cyberpolitiken ligger därför i linje med planen.
- strengthened cyber defencedecisive»Utveckla cyberförsvaret« (2022 manifesto ↗)“Develop cyber defence”
- action plan against cyber attacks»Införa en handlingsplan med konkreta åtgärder mot hybridhot och cyberattacker« (2022 manifesto ↗)“Introduce an action plan with concrete measures against hybrid threats and cyber attacks”
- civil defence crucial»Fungerar inte det civila försvaret så kan inte heller det militära försvaret lösa sina uppgifter.« (2022 manifesto ↗)“If civil defence does not work, neither can military defence solve its tasks.”
- support against cyber attacks»Ge företag som är engagerade i säkerhetskänslig verksamhet bättre stöd från staten att kunna möta cyberattacker, spionage och stöldförsök från främmande makt« (2022 manifesto ↗)“Give companies engaged in security-sensitive activities better support from the state to meet cyber attacks, espionage and theft attempts from foreign powers”
The stance rests on the quoted commitment in the party's own documents; the actual vote deviated. Click the quote to verify it in the document.
The plan wants to strengthen society's preparedness for all types of crises and particularly points out disruptions in electronic systems and payment services as a serious vulnerability threat, while the position of cash should be defended.
Plan documents: 2022 manifesto
Reasoning and quotes
The plan wants to strengthen society's preparedness for all types of crises and particularly points out disruptions in electronic systems and payment services as a serious vulnerability threat, while the position of cash should be defended. The counter-proposal's demands for strengthened cyber defence and increased redundancy in payment and cash handling systems respond directly to these commitments. The plan does not mention cyber defence as its own area, so the conclusion is derived.
Original (Swedish)
Planen vill stärka samhällets beredskap för alla typer av kriser och pekar särskilt ut störningar i elektroniska system och betaltjänster som ett allvarligt sårbarhetshot, samtidigt som kontanternas ställning ska försvaras. Motförslagets krav på stärkt cyberförsvar och ökad redundans i betalnings- och kontanthanteringssystemen svarar direkt mot dessa åtaganden. Planen nämner inte cyberförsvaret som eget område, varför slutsatsen är härledd.
- vulnerability in critical systemsdecisive»Störningar i elektroniska system, betaltjänster eller elnät kan uppstå på grund av naturfenomen, angrepp eller fel och skulle kunna få oöverskådliga följder relativt snabbt.« (2022 manifesto ↗)“Disruptions in electronic systems, payment services or electricity networks can occur due to natural phenomena, attacks or errors and could have incalculable consequences relatively quickly.”
- cash as payment method»Försvara kontanternas ställning som betalmedel i Sverige« (2022 manifesto ↗)“Defend cash's position as a payment method in Sweden”
- broad crisis preparedness»Sverigedemokraterna vill stärka samhällets beredskap för alla typer av kriser som kan uppstå.« (2022 manifesto ↗)“Sweden Democrats want to strengthen society's preparedness for all types of crises that can occur.”
- strengthened central crisis management»Förbättra den centrala krisledningsförmågan« (2022 manifesto ↗)“Improve central crisis management capability”
The plan takes no explicit position on what the committee actually decided — often because the committee's reason was procedural. The stance is derived and fully cited, but it does not show the party broke a commitment.
Share and embed
Sources and documents
- The committee report on riksdagen.se (2025/26:FöU2)
- Committee report full text (HD01FöU2)
- Per-MP voting data (API)
- Case status (API)
Documents under consideration
- Motion 2025/26:3405 — Ökad civil försvarsförmåga och stärkt krisberedskap av Emma Berginger m.fl. (MP)
- Motion 2025/26:3556 — Totalförsvarets beredskap av Peter Hultqvist m.fl. (S)
- Motion 2025/26:3652 — En digital politik som bygger jämlikhet och tillväxt av Aylin Nouri m.fl. (S)
- Motion 2025/26:3834 — med anledning av prop. 2025/26:28 Ett starkt skydd för nätverks- och informationssystem - en ny cybersäkerhetslag av Ulf Holm m.fl. (MP)
- Motion 2025/26:3838 — med anledning av prop. 2025/26:28 Ett starkt skydd för nätverks- och informationssystem - en ny cybersäkerhetslag av Mikael Larsson och Niels Paarup-Petersen (båda C)
- Proposition 2025/26:28 — Ett starkt skydd för nätverks- och informationssystem - en ny cybersäkerhetslag
Source: The Swedish Parliament